Anonymous
2026-06-19 08:00:36
(1 day ago)
Unauthorized access attempt to administration interfaces (wp-admin, phpMyAdmin, panel, etc). Automat ...
show more
Unauthorized access attempt to administration interfaces (wp-admin, phpMyAdmin, panel, etc). Automated scanning blocked by fail2ban.
show less
Web App Attack
๐บ๐ธ
NXTwoThou
2026-06-18 05:03:17
(3 days ago)
/___proxy_subdomain_whm/login/%3Flogin_only=1
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-18 04:53:20
(3 days ago)
(mod_security) mod_security (id:949110) triggered by 3.253.69.28 (ec2-3-253-69-28.eu-west-1.compute. ...
show more
(mod_security) mod_security (id:949110) triggered by 3.253.69.28 (ec2-3-253-69-28.eu-west-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 18 00:53:16.098953 2026] [security2:error] [pid 24402:tid 24402] [client 3.253.69.28:44374] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "192.64.150.239"] [uri "/.git/HEAD"] [unique_id "ajN5vBF_jlLH9y9m6d3B8wAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
poundawebsiteltd
2026-06-18 04:19:09
(3 days ago)
Web App Attack (ModSecurity Block). Evidence: [REDACTED_DOMAIN]:80 3.253.69.28 - - [18/Jun/2026:05:1 ...
show more
Web App Attack (ModSecurity Block). Evidence: [REDACTED_DOMAIN]:80 3.253.69.28 - - [18/Jun/2026:05:19:06 +0100] GET /data/dump.sql HTTP/1.1 403 177 - Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.0.0 Safari/537.36
show less
Web App Attack
๐ง๐ท
SOC PR
2026-06-18 03:49:10
(3 days ago)
IPS: Web Server Enforcement Violation.
Hacking
๐ฉ๐ช
NewGastroline
2026-06-18 03:33:54
(3 days ago)
Malicious request blocked by CrowdSec on gastro-prod1.boreus.de
Bad Web Bot
Web App Attack
๐ฎ๐ช
AutosOnShow
2026-06-18 03:31:04
(3 days ago)
blocked for webapp attack | path requested: /.env | seen at 2026-06-18 03:30:03.304 |
Web App Attack
๐ง๐ท
SOC Blue Team
2026-06-18 03:25:56
(3 days ago)
IPs get by Hunting on SIEM
Phishing
Web Spam
Port Scan
Hacking
๐บ๐ธ
TPI-Abuse
2026-06-18 03:25:02
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 3.253.69.28 (ec2-3-253-69-28.eu-west-1.compute. ...
show more
(mod_security) mod_security (id:210492) triggered by 3.253.69.28 (ec2-3-253-69-28.eu-west-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 17 23:24:55.481614 2026] [security2:error] [pid 9621:tid 9621] [client 3.253.69.28:44680] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.70"] [uri "/.git/HEAD"] [unique_id "ajNlBzgsvrzI2s02oDxTKQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-18 03:10:16
(3 days ago)
Repeated unauthorized connection attempts to restricted service observed.
Port Scan
Hacking
Bad Web Bot
๐ฌ๐ง
djboddington
2026-06-18 03:10:08
(3 days ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
Anonymous
2026-06-18 03:08:46
(3 days ago)
Automated report from Fail2Ban firewall ban
Brute-Force
SSH
IoT Targeted
๐บ๐ธ
TPI-Abuse
2026-06-18 02:55:51
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 3.253.69.28 (ec2-3-253-69-28.eu-west-1.compute. ...
show more
(mod_security) mod_security (id:210492) triggered by 3.253.69.28 (ec2-3-253-69-28.eu-west-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 17 22:55:46.048892 2026] [security2:error] [pid 15747:tid 15747] [client 3.253.69.28:37444] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.71"] [uri "/.git/HEAD"] [unique_id "ajNeMm8bIQbc6lqP8_5sNgAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
pipeline.es
2026-06-18 02:53:19
(3 days ago)
Web scanning / probing for vulnerable paths | URL: /terraform.tfstate | Evidence: landingow.aavv.com ...
show more
Web scanning / probing for vulnerable paths | URL: /terraform.tfstate | Evidence: landingow.aavv.com 3.253.69.28 - - [18/Jun/2026:04:52:55 +0200] \"GET /terraform.tfstate HTTP/1.1\" 404 215 \"-\" \"Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.0.0 Safari/537.36\" GEOIP_COUNTRY_CODE=IE | ASN: AMAZON-02 | Country: IE
show less
Port Scan
Web App Attack
Anonymous
2026-06-18 02:30:42
(3 days ago)
Web App Attack