๐ฆ๐บ
ozisp.com.au
2024-06-08 02:19:12
(2 years ago)
US_Charter_<33>1717813151 [1:2031502:4] ET INFO Request to Hidden Environment File - Inbound [Classi ...
show more
US_Charter_<33>1717813151 [1:2031502:4] ET INFO Request to Hidden Environment File - Inbound [Classification: Misc activity] [Priority: 3] {TCP} 24.164.171.218:54171
show less
Hacking
๐ฆ๐บ
FEWA
2024-06-07 23:19:24
(2 years ago)
Fail2Ban Ban Triggered
Hacking
Bad Web Bot
Web App Attack
Anonymous
2024-06-07 04:16:11
(2 years ago)
Fuzzing/Looking for credentials files.
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-06-07 01:25:56
(2 years ago)
(mod_security) mod_security (id:210492) triggered by 24.164.171.218 (syn-024-164-171-218.res.spectru ...
show more
(mod_security) mod_security (id:210492) triggered by 24.164.171.218 (syn-024-164-171-218.res.spectrum.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 06 21:25:53.513275 2024] [security2:error] [pid 20643] [client 24.164.171.218:50897] [client 24.164.171.218] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.19"] [uri "/.env"] [unique_id "ZmJhoR9kRY3w79W0qZ5dgQAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
MogBox
2024-06-06 18:06:20
(2 years ago)
(mod_security) mod_security (id:210492) triggered by 24.164.171.218 (US/United States/syn-024-164-17 ...
show more
(mod_security) mod_security (id:210492) triggered by 24.164.171.218 (US/United States/syn-024-164-171-218.res.spectrum.com): 1 in the last 3600 secs (CF_ENABLE); Ports: *; Direction: inout; Trigger: LF_MODSEC; Logs: [Thu Jun 06 14:06:18.708444 2024] [security2:error] [pid 32443:tid 47434768070400] [client 24.164.171.218:57378] [client 24.164.171.218] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "67.225.186.60"] [uri "/.env"] [unique_id "ZmH6mhnqPdIIu1sTSEUF_AAAAEI"]
show less
Hacking
๐ฆ๐บ
FEWA
2024-06-06 08:47:47
(2 years ago)
Fail2Ban Ban Triggered
Hacking
Bad Web Bot
Web App Attack
๐บ๐ธ
BSG Webmaster
2024-06-06 07:35:19
(2 years ago)
Port scanning (Port 80)
Port Scan
Hacking
๐บ๐ธ
MogBox
2024-06-06 00:18:10
(2 years ago)
(mod_security) mod_security (id:210492) triggered by 24.164.171.218 (US/United States/syn-024-164-17 ...
show more
(mod_security) mod_security (id:210492) triggered by 24.164.171.218 (US/United States/syn-024-164-171-218.res.spectrum.com): 1 in the last 3600 secs (CF_ENABLE); Ports: *; Direction: inout; Trigger: LF_MODSEC; Logs: [Wed Jun 05 20:18:06.795133 2024] [security2:error] [pid 81760:tid 47434778576640] [client 24.164.171.218:57574] [client 24.164.171.218] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "67.225.186.60"] [uri "/.env"] [unique_id "ZmEAPlNLqgE0s801oXP9tAAAAAc"]
show less
Hacking
๐บ๐ธ
TPI-Abuse
2024-06-05 23:19:16
(2 years ago)
(mod_security) mod_security (id:210492) triggered by 24.164.171.218 (syn-024-164-171-218.res.spectru ...
show more
(mod_security) mod_security (id:210492) triggered by 24.164.171.218 (syn-024-164-171-218.res.spectrum.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 05 19:19:12.023792 2024] [security2:error] [pid 27939] [client 24.164.171.218:65292] [client 24.164.171.218] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.151.10"] [uri "/.env"] [unique_id "ZmDycMmo4T2pSAVT6iJxRgAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ต๐ฑ
Marek Krolikowski
2024-06-05 04:43:16
(2 years ago)
GET /.env HTTP/1.1
Web App Attack
๐ฉ๐ช
Mr-Money
2024-06-04 15:51:51
(2 years ago)
24.164.171.218 - - [04/Jun/2024:17:51:50 +0200] "GET /.env HTTP/1.1" 404 492 "-" "Mozilla/5.0 (X11; ...
show more
24.164.171.218 - - [04/Jun/2024:17:51:50 +0200] "GET /.env HTTP/1.1" 404 492 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36"
...
show less
Hacking
SQL Injection
Bad Web Bot
Exploited Host
Web App Attack
Anonymous
2024-06-04 14:15:33
(2 years ago)
Bot / scanning and/or hacking attempts: idle, streams: 0/34/34/0/0 (open/recv/resp/push/rst), GET /. ...
show more
Bot / scanning and/or hacking attempts: idle, streams: 0/34/34/0/0 (open/recv/resp/push/rst), GET /.env HTTP/1.1, POST / HTTP/1.1, done, streams: 0/1/1/0/0 (open/recv/resp/push/rst), idle, streams: 0/29/29/12/0 (open/recv/resp/push/rst), idle, streams: 0/12/12/12/0 (open/recv/resp/push/rst)
show less
Hacking
Web App Attack
Anonymous
2024-06-04 10:38:19
(2 years ago)
Infostealer, stealing credentials: /.env
Hacking
Bad Web Bot
Anonymous
2024-06-04 10:21:30
(2 years ago)
Malicious activity detected
Hacking
Web App Attack
๐ช๐ธ
10dencehispahard SL
2024-06-04 09:00:15
(2 years ago)
Suspicious activity detected by Modsecurity [Suspicious IP found on 88 endpoints 103 hits. Reinciden ...
show more
Suspicious activity detected by Modsecurity [Suspicious IP found on 88 endpoints 103 hits. Reincident by 0. Rules:]
show less
Web App Attack