๐ซ๐ท
dynamix
2026-07-25 01:21:16
(3 hours ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-25 01:05:55
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 27.21.31.84 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 27.21.31.84 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 21:05:48.260815 2026] [security2:error] [pid 3649526:tid 3649526] [client 27.21.31.84:38478] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.landon.hookedupfishing.net"] [uri "/.env"] [unique_id "amQL7GkoEwwM5VOj_wStRgAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-25 00:44:45
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 27.21.31.84 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 27.21.31.84 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 20:44:41.700419 2026] [security2:error] [pid 775620:tid 775620] [client 27.21.31.84:49522] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.lajoyadelmar.net"] [uri "/.env"] [unique_id "amQG-fRjGxgz8bHFXl2drQAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-25 00:07:40
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 27.21.31.84 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 27.21.31.84 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 20:07:32.536540 2026] [security2:error] [pid 27392:tid 27392] [client 27.21.31.84:57956] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.kylight.net"] [uri "/.env"] [unique_id "amP-RNasisklgpqWvcaVLgAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-24 23:24:28
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 27.21.31.84 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 27.21.31.84 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 19:24:24.221022 2026] [security2:error] [pid 29706:tid 29706] [client 27.21.31.84:49036] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.krugmans.net"] [uri "/.env"] [unique_id "amP0KHe51Rd3tX1evQVcDwAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
lns.bz
2026-07-24 21:00:04
(8 hours ago)
.env scanning [DOPP]
Web App Attack
๐ฟ๐ฆ
conure
2026-07-24 14:28:43
(14 hours ago)
csagent: score 20.8: 404 noise floor x11, secrets grab x2, php 404 x1; 2 domain(s) in 3m20s
Web App Attack
๐ฟ๐ฆ
hostsec_za
2026-07-24 11:40:00
(17 hours ago)
WHM Auth Attack. 10 failed logins in 10 minutes.
Brute-Force
๐ง๐ช
voormedia
2026-07-24 09:07:15
(19 hours ago)
Accessed trap at '/.env'
Web App Attack
๐ฟ๐ฆ
conure
2026-07-24 08:44:44
(20 hours ago)
csagent: score 15.2: 404 noise floor x32, secrets grab x3, php 404 x3; 3 domain(s) in 16m1s
Web App Attack
๐ง๐พ
lns.bz
2026-07-23 21:29:00
(1 day ago)
.env scanning [BY]
Web App Attack
๐ต๐ฑ
lns.bz
2026-07-23 20:25:53
(1 day ago)
Web app attack [PL.Lu]
Exploited Host
Web App Attack
๐ง๐พ
sashan
2026-06-25 02:06:51
(1 month ago)
2026-06-25T05:06:51.313902+03:00 gate kernel: nftables: JAIL-TELNET IN=wan OUT= MAC= SRC=27.21.31.84 ...
show more
2026-06-25T05:06:51.313902+03:00 gate kernel: nftables: JAIL-TELNET IN=wan OUT= MAC= SRC=27.21.31.84 DST=xxx.xxx.xxx.xxx LEN=60 TOS=0x00 PREC=0x00 TTL=51 ID=17550 DF PROTO=TCP SPT=39841 DPT=23 WINDOW=29040 RES=0x00 SYN URGP=0
...
show less
Port Scan