๐ฟ๐ฆ
conure.sh
2026-08-02 12:05:29
(4 weeks ago)
csagent: score 20.5: secrets grab x2, 404 noise floor x2; 1 domain(s) in 0s
Web App Attack
๐ฉ๐ช
enchiriadis
2026-08-01 17:24:01
(4 weeks ago)
Fail2Ban caddy-wp-404scan on Tuxi
Port Scan
๐บ๐ธ
TPI-Abuse
2026-08-01 17:15:03
(4 weeks ago)
(mod_security) mod_security (id:210492) triggered by 34.101.81.20 (20.81.101.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.101.81.20 (20.81.101.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 13:14:54.835481 2026] [security2:error] [pid 1380323:tid 1380323] [client 34.101.81.20:40274] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "zaaniebowen.dev"] [uri "/.env.bak"] [unique_id "am4pjtc_nnwP35CNVe98ZQAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
zynex
2026-08-01 16:47:12
(4 weeks ago)
URL Probing: /.env
Web App Attack
๐ฉ๐ช
4server
2026-08-01 16:34:08
(4 weeks ago)
[SatAug0118:34:06.6899682026][security2:error][pid1730179:tid1730256][client34.101.81.20:0]ModSecuri ...
show more
[SatAug0118:34:06.6899682026][security2:error][pid1730179:tid1730256][client34.101.81.20:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:5\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.10\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"www.archi-box.ch.136-243-54-122.cpanel.site\"][uri\"/.env.dev\"][unique_id\"am4f_h43Osv8TwtWFOdpIAAAAJA\"]
show less
Port Scan
Brute-Force
Web App Attack
๐ซ๐ฎ
paissangroup
2026-08-01 16:29:43
(4 weeks ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-01 16:20:12
(4 weeks ago)
(mod_security) mod_security (id:210492) triggered by 34.101.81.20 (20.81.101.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.101.81.20 (20.81.101.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 12:20:06.002618 2026] [security2:error] [pid 971303:tid 971303] [client 34.101.81.20:57078] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.sircain.cain2016.org"] [uri "/.env.backup"] [unique_id "am4ctguf3pYV9Jf1VeVoiAAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
juutis
2026-08-01 15:47:36
(4 weeks ago)
Multiple WAF abuses - IP blocked
Hacking
Brute-Force
Web App Attack
Anonymous
2026-08-01 15:43:36
(4 weeks ago)
[ns65.kdns.gr] httpd-config-scan: sites=www.example.com; logs=/var/log/httpd/access_log; samples=/.e ...
show more
[ns65.kdns.gr] httpd-config-scan: sites=www.example.com; logs=/var/log/httpd/access_log; samples=/.env.save | /.env.prod | /.env.backup
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-01 15:42:31
(4 weeks ago)
(mod_security) mod_security (id:210492) triggered by 34.101.81.20 (20.81.101.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.101.81.20 (20.81.101.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 11:42:26.500335 2026] [security2:error] [pid 177942:tid 177942] [client 34.101.81.20:47968] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "neh-media.com.abraxasstudio.com"] [uri "/.env.dev"] [unique_id "am4T4nXpGTIRaf1yYk1_7AAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-08-01 15:11:36
(4 weeks ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-08-01 15:05:20
(4 weeks ago)
Scanning/Probing (20)
Brute-Force
Web App Attack
๐ฟ๐ฆ
conure.sh
2026-08-01 15:03:01
(4 weeks ago)
csagent: score 20.2: secrets grab x2, 404 noise floor x1; 1 domain(s) in 0s
Web App Attack
๐ธ๐ช
vaia.cloud
2026-08-01 14:55:03
(4 weeks ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
๐ซ๐ท
masterguru
2026-08-01 14:16:12
(4 weeks ago)
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 34.101.81.20 (ID/Indonesia/20.81.101. ...
show more
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 34.101.81.20 (ID/Indonesia/20.81.101.34.bc.googleusercontent.com): 1 in the last 3600 secs (0-195)
show less
Hacking