๐บ๐ธ
TPI-Abuse
2026-07-25 14:36:09
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 223.122.135.114 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 223.122.135.114 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 25 10:36:00.942540 2026] [security2:error] [pid 186800:tid 186800] [client 223.122.135.114:45910] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kerbros.com"] [uri "/.env.bak"] [unique_id "amTJ0GaPOIgXrwkdnLqisgAAACU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-25 13:59:04
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 223.122.135.114 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 223.122.135.114 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 25 09:58:59.316176 2026] [security2:error] [pid 2889148:tid 2889148] [client 223.122.135.114:33852] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kerrywood.com"] [uri "/.env.bak"] [unique_id "amTBIyjzw2s1V5LVioO2xQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-25 11:21:22
(2 days ago)
Multiple web server 400 error codes from same source ip
Web App Attack
๐ฎ๐ฉ
sockominfo
2026-07-25 10:00:53
(2 days ago)
Access to sensitive files detected w/ specific boundary.. Threat Score: 4.9/10 (MEDIUM). Confidence: ...
show more
Access to sensitive files detected w/ specific boundary.. Threat Score: 4.9/10 (MEDIUM). Confidence: 40%. CVSS v3.1: 2.9/10 (Low). CVSS Vector: CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N. Bayesian Probability: 40%. MITRE ATT&CK: T1016 (System Network Configuration Discovery). Tactic: TA0001. Freshness: Fresh. Source Reputation: UNKNOWN. Methodology: CVSS 3.1 + Bayesian + Temporal + Environmental + MITRE ATT&CK + OWASP. Standards: ISO/IEC 27065:2022, NIST SP 800-30, IEEE S&P 2020. Reported by TangerangKota-CSIRT. Status: MALICIOUS
show less
Hacking
Web App Attack
๐ฎ๐ฉ
sockominfo
2026-07-25 09:00:54
(2 days ago)
Access to sensitive files detected w/ specific boundary.. Threat Score: 5/10 (MEDIUM). Confidence: 4 ...
show more
Access to sensitive files detected w/ specific boundary.. Threat Score: 5/10 (MEDIUM). Confidence: 40%. CVSS v3.1: 2.9/10 (Low). CVSS Vector: CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N. Bayesian Probability: 40%. MITRE ATT&CK: T1016 (System Network Configuration Discovery). Tactic: TA0001. Freshness: Fresh. Source Reputation: UNKNOWN. Methodology: CVSS 3.1 + Bayesian + Temporal + Environmental + MITRE ATT&CK + OWASP. Standards: ISO/IEC 27065:2022, NIST SP 800-30, IEEE S&P 2020. Reported by TangerangKota-CSIRT. Status: MALICIOUS
show less
Hacking
Web App Attack
Anonymous
2026-07-25 08:12:23
(2 days ago)
GET phpinfo | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) C ...
show more
GET phpinfo | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/42.0.2311.135 Safari/537.36 Edge/12.246 | Time: 2026-07-25 08:12:23 UTC
show less
Web App Attack
๐ฎ๐ฉ
sockominfo
2026-07-25 08:00:10
(2 days ago)
Access to sensitive files detected w/ specific boundary.. Threat Score: 7.1/10 (HIGH). Reported by T ...
show more
Access to sensitive files detected w/ specific boundary.. Threat Score: 7.1/10 (HIGH). Reported by TangerangKota-CSIRT. Status: MALICIOUS
show less
Hacking
Web App Attack
๐ฎ๐ฉ
sockominfo
2026-07-25 07:00:09
(2 days ago)
Access to sensitive files detected w/ specific boundary.. Threat Score: 7.2/10 (HIGH). Reported by T ...
show more
Access to sensitive files detected w/ specific boundary.. Threat Score: 7.2/10 (HIGH). Reported by TangerangKota-CSIRT. Status: MALICIOUS
show less
Hacking
Web App Attack
Anonymous
2026-07-25 04:47:46
(2 days ago)
Aggressive web scan
Web App Attack
Anonymous
2026-07-25 04:32:53
(2 days ago)
[25/Jul/2026:14:32:53 +1000] "GET /.env.bak HTTP/1.1" 404 236 "Mozilla/5.0 (Windows NT 10.0; Win64; ...
show more
[25/Jul/2026:14:32:53 +1000] "GET /.env.bak HTTP/1.1" 404 236 "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/42.0.2311.135 Safari/537.36 Edge/12.246"
show less
Hacking
Web App Attack
๐ฎ๐น
VHosting
2026-07-25 04:00:06
(2 days ago)
Detected WordPress attack from 4 different servers
Brute-Force
Web App Attack
๐ฎ๐ฉ
penjaga BRIN
2026-07-25 02:48:48
(2 days ago)
Suspicious malicious activity
Hacking
๐บ๐ธ
TPI-Abuse
2026-07-25 02:32:44
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 223.122.135.114 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 223.122.135.114 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 22:32:36.966264 2026] [security2:error] [pid 7501:tid 7501] [client 223.122.135.114:46862] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "keithbowles.com"] [uri "/.env.bak"] [unique_id "amQgRP3bXb3ybihpkQjecgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
melroy89
2026-07-25 01:55:31
(3 days ago)
223.122.135.114 - - [25/Jul/2026:03:54:30 +0200] "GET /.env.bak HTTP/1.1" 403 205 "-" "Mozilla/5.0 ...
show more
223.122.135.114 - - [25/Jul/2026:03:54:30 +0200] "GET /.env.bak HTTP/1.1" 403 205 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/42.0.2311.135 Safari/537.36 Edge/12.246" "kbin.melroy.org" 0.000
223.122.135.114 - - [25/Jul/2026:03:54:30 +0200] "GET /.env.local HTTP/1.1" 403 205 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/42.0.2311.135 Safari/537.36 Edge/12.246" "kbin.melroy.org" 0.000
223.122.135.114 - - [25/Jul/2026:03:54:31 +0200] "GET /.env.production HTTP/1.1" 403 205 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/42.0.2311.135 Safari/537.36 Edge/12.246" "kbin.melroy.org" 0.000
223.122.135.114 - - [25/Jul/2026:03:54:31 +0200] "GET /.env.staging HTTP/1.1" 403 205 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/42.0.2311.135 Safari/537.36 Edge/12.246" "kbin.melroy.org" 0.000
223.122.135.114 - - [25
...
show less
Web App Attack