Anonymous
2026-04-29 03:11:15
(1 month ago)
(mod_security) mod_security triggered on hostname [redacted] 23.95.128.184 (US/United States/23-95-1 ...
show more
(mod_security) mod_security triggered on hostname [redacted] 23.95.128.184 (US/United States/23-95-128-184-host.colocrossing.com)
show less
SQL Injection
๐บ๐ธ
TPI-Abuse
2026-04-29 02:53:11
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 23.95.128.184 (23-95-128-184-host.colocrossing. ...
show more
(mod_security) mod_security (id:210492) triggered by 23.95.128.184 (23-95-128-184-host.colocrossing.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Apr 28 22:53:08.048980 2026] [security2:error] [pid 12923:tid 12923] [client 23.95.128.184:38438] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "chrismonty.com"] [uri "/.env.old"] [unique_id "afFylB-QjB1zncPWBwb8cwAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ท๐ด
StarTech Team
2026-04-29 02:39:56
(1 month ago)
Web App Atack
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-29 02:34:03
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 23.95.128.184 (23-95-128-184-host.colocrossing. ...
show more
(mod_security) mod_security (id:210492) triggered by 23.95.128.184 (23-95-128-184-host.colocrossing.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Apr 28 22:33:58.993511 2026] [security2:error] [pid 31730:tid 31730] [client 23.95.128.184:43380] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "carjinn.net"] [uri "/.env"] [unique_id "afFuFgmDOpMsaiv2z7yInwAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-04-29 02:20:17
(1 month ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐ณ๐ฟ
Antinson
2026-04-29 02:17:46
(1 month ago)
High error rate and elevated request volume targeting cPanel servers
Bad Web Bot
๐ณ๐ฑ
Mangelot Hosting
2026-04-29 01:34:12
(1 month ago)
(modsecurity) srv102 ModSecurity 23.95.128.184 (US/United States/23-95-128-184-host.colocrossing.com ...
show more
(modsecurity) srv102 ModSecurity 23.95.128.184 (US/United States/23-95-128-184-host.colocrossing.com): 10 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs:
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-29 01:07:46
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 23.95.128.184 (23-95-128-184-host.colocrossing. ...
show more
(mod_security) mod_security (id:210492) triggered by 23.95.128.184 (23-95-128-184-host.colocrossing.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Apr 28 21:07:42.300230 2026] [security2:error] [pid 6609:tid 6609] [client 23.95.128.184:40366] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "justinrudd.com"] [uri "/.env"] [unique_id "afFZ3v8bjZslouixLN9LBAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
YF
2026-04-29 01:05:06
(1 month ago)
Config JSON probe
Web App Attack
๐ซ๐ท
โจ
2026-04-29 01:04:13
(1 month ago)
Domain : nfstimpson.co.uk
Rule : hack
2026-04-29 00:50:59 ***hidden-privacy*** GET /.env.bak - 443 - ...
show more
Domain : nfstimpson.co.uk
Rule : hack
2026-04-29 00:50:59 ***hidden-privacy*** GET /.env.bak - 443 - 23.95.128.184 HTTP/1.1 Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:132.0) Gecko/20100101 Firefox/132.0 - nfstimpson.co.uk 404 0 2 12866 419 397 - -
show less
Hacking
SQL Injection
Brute-Force
๐ฉ๐ช
Gwyneth Llewelyn
2026-04-29 00:40:26
(1 month ago)
2026/04/29 01:40:23 [error] 4134979#4134979: *3338906 access forbidden by rule, client: 23.95.128.18 ...
show more
2026/04/29 01:40:23 [error] 4134979#4134979: *3338906 access forbidden by rule, client: 23.95.128.184, server: apcoelho.pt, request: "GET /.env HTTP/2.0", host: "apcoelho.pt"
23.95.128.184 - - [29/Apr/2026:01:40:23 +0100] "GET /.env HTTP/2.0" 403 1045 "-" "Mozilla/5.0 (iPad; CPU OS 18_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.1 Mobile/15E148 Safari/604.1"
2026/04/29 01:40:24 [error] 4134979#4134979: *3338923 access forbidden by rule, client: 23.95.128.184, server: apcoelho.pt, request: "GET /app/.env HTTP/2.0", host: "apcoelho.pt"
show less
Brute-Force
Web App Attack
๐ซ๐ฎ
Shaik Sai Meera
2026-04-29 00:05:09
(1 month ago)
IM360 WAF: Hidden file access
Brute-Force
๐ฉ๐ช
big-cloud.nl
2026-04-28 23:47:11
(1 month ago)
Try to access /.aws/config
Web App Attack
๐ฉ๐ช
paissangroup
2026-04-28 23:19:25
(1 month ago)
Multiple WAF Violations
Web App Attack
๐ฌ๐ง
thetomtaylor.co.uk
2026-04-28 23:08:02
(1 month ago)
Fail2Ban - [WEB]Custom exploit pattern detected on customexploits ... [ice02]
Hacking
Brute-Force
Bad Web Bot
Web App Attack