๐ซ๐ท
dynamix
2026-06-15 14:32:49
(10 hours ago)
Multiple WAF Violations
Web App Attack
๐ฉ๐ช
tuxiano
2026-06-15 14:23:11
(11 hours ago)
34.101.217.180 - - [15/Jun/2026:14:23:11 +0000] "GET /mail.zip HTTP/1.1" 404 4839 "-" "Mozilla/5.0 ( ...
show more
34.101.217.180 - - [15/Jun/2026:14:23:11 +0000] "GET /mail.zip HTTP/1.1" 404 4839 "-" "Mozilla/5.0 (Linux; Android 8.1.0; SM-T580) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/76.0.3809.111 Safari/537.36" "-"
show less
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Savvii
2026-06-15 13:55:30
(11 hours ago)
20 attempts against mh-misbehave-ban on eris
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-15 08:34:49
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.101.217.180 (180.217.101.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.101.217.180 (180.217.101.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 15 04:34:45.980962 2026] [security2:error] [pid 2598:tid 2608] [client 34.101.217.180:53492] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.wwobb2.wwwhst.com"] [uri "/src/.env.production"] [unique_id "ai-5JSyyuxIrnUhX8e9svwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
venus.launch.bz
2026-06-15 05:47:25
(19 hours ago)
(mod_security) mod_security triggered on hostname [redacted] 34.101.217.180 (ID/Indonesia/180.217.10 ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.101.217.180 (ID/Indonesia/180.217.101.34.bc.googleusercontent.com)
show less
SQL Injection
๐บ๐ธ
TPI-Abuse
2026-06-15 05:42:36
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.101.217.180 (180.217.101.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.101.217.180 (180.217.101.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 15 01:42:30.945709 2026] [security2:error] [pid 11692:tid 11707] [client 34.101.217.180:57916] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.knoinvestments.oconnorpest.biz"] [uri "/backend/.env.production"] [unique_id "ai-QxhnntfI0eOF6-sTJkAAAAU0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
consul.to
2026-06-15 04:25:11
(21 hours ago)
Web attack/malicious scanning detected
Web App Attack
๐ณ๐ฑ
Cloud86 B.V.
2026-06-15 03:26:02
(22 hours ago)
categories: DDoS Attack
DDoS Attack
๐บ๐ธ
TPI-Abuse
2026-06-15 02:40:30
(22 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.101.217.180 (180.217.101.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.101.217.180 (180.217.101.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 22:40:24.294711 2026] [security2:error] [pid 3434:tid 3434] [client 34.101.217.180:60754] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "voidpope.com"] [uri "/.env.pre-production"] [unique_id "ai9mGPplg5dOweHs2Id9gQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Octopuce
2026-06-15 01:05:01
(1 day ago)
Aggressive web search of vulnerable pages: /services/api/.env /apps/frontend/.env /.env.local /packa ...
show more
Aggressive web search of vulnerable pages: /services/api/.env /apps/frontend/.env /.env.local /packages/api/.env /services/backend/.env ...
show less
Web App Attack
Anonymous
2026-06-14 23:05:13
(1 day ago)
CrowdSec ban: crowdsecurity/http-sensitive-files
Port Scan
๐บ๐ธ
TPI-Abuse
2026-06-14 21:10:40
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.101.217.180 (180.217.101.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.101.217.180 (180.217.101.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 17:10:36.318702 2026] [security2:error] [pid 16109:tid 16109] [client 34.101.217.180:51092] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "rasmisdigital.com"] [uri "/.env.qa"] [unique_id "ai8YzAU8WiQ5sENWXMKX8AAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-06-14 04:10:03
(1 day ago)
Scanning/Probing (89)
Brute-Force
Web App Attack
๐ฎ๐น
VHosting
2026-06-14 02:45:04
(1 day ago)
Detected WordPress attack from 4 different servers
Brute-Force
Web App Attack
๐บ๐ธ
kosada.com
2026-06-13 22:10:10
(2 days ago)
Web vulnerability probing: /env
Web App Attack