๐ฉ๐ช
hidemail.app
2026-08-01 17:06:52
(17 minutes ago)
Automated scan for exposed config/secret files and known web exploits (e.g. /.env, RCE probes); auto ...
show more
Automated scan for exposed config/secret files and known web exploits (e.g. /.env, RCE probes); auto-banned by fail2ban.
show less
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-08-01 16:50:07
(34 minutes ago)
(mod_security) mod_security (id:210492) triggered by 34.101.79.129 (129.79.101.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.101.79.129 (129.79.101.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 12:49:59.449310 2026] [security2:error] [pid 4332:tid 4332] [client 34.101.79.129:42104] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.sipa.com.hk"] [uri "/.env.local"] [unique_id "am4jt3ossBim1aB12fqhhwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-08-01 16:06:35
(1 hour ago)
Multiple unauthorized connection attempts
Web App Attack
๐ซ๐ท
dynamix
2026-08-01 15:36:30
(1 hour ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-01 15:30:08
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.101.79.129 (129.79.101.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.101.79.129 (129.79.101.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 11:30:01.492705 2026] [security2:error] [pid 445424:tid 445424] [client 34.101.79.129:52654] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.drhasanunal.chevronparkett.com"] [uri "/.env"] [unique_id "am4Q-XKHVEAmTYUtibqEaQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-08-01 15:28:06
(1 hour ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
Anonymous
2026-08-01 15:14:44
(2 hours ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
๐จ๐ญ
4server
2026-08-01 15:08:48
(2 hours ago)
[SatAug0117:08:43.7936362026][security2:error][pid3976367:tid3976590][client34.101.79.129:0]ModSecur ...
show more
[SatAug0117:08:43.7936362026][security2:error][pid3976367:tid3976590][client34.101.79.129:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\".env\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"365\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"edomustech.ch\"][uri\"/.env.example\"][unique_id\"am4L-6ps-lhEGqWSuvuFGgAAAMc\"]
show less
Hacking
Web App Attack
Anonymous
2026-08-01 14:43:26
(2 hours ago)
Blocked by ModSec and CSF
Port Scan
๐บ๐ธ
TPI-Abuse
2026-08-01 14:32:15
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.101.79.129 (129.79.101.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.101.79.129 (129.79.101.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 10:32:08.724196 2026] [security2:error] [pid 4848:tid 4848] [client 34.101.79.129:38204] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.bernard.gonzalez.com"] [uri "/.env.backup"] [unique_id "am4DaJ03fWkt7zjKHnJVrAAAAC4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฟ๐ฆ
conure
2026-08-01 14:23:01
(3 hours ago)
csagent: score 20.0: secrets grab x2; 1 domain(s) in 0s
Web App Attack
๐ง๐พ
lns.bz
2026-08-01 14:18:37
(3 hours ago)
Too many 404 requests [BY]
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-01 14:02:29
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.101.79.129 (129.79.101.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.101.79.129 (129.79.101.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 10:02:22.065221 2026] [security2:error] [pid 2305295:tid 2305295] [client 34.101.79.129:36394] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.jacksbagels.jbaydeliveries.com"] [uri "/.env.backup"] [unique_id "am38bixljFlGFa21N-3jOwAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-08-01 13:55:38
(3 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐ฉ๐ช
iNetWorker
2026-08-01 13:53:05
(3 hours ago)
trolling for resource vulnerabilities
Web App Attack