🇺🇸
cwytech
2026-09-06 06:30:56
(19 hours ago)
Fleet-wide ban from the Ghostfleet 👻. Triggered by scenario: crowdsecurity/http-sensitive-files.
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 03:53:53
(21 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.106.149.134 (134.149.106.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.106.149.134 (134.149.106.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 23:53:50.187344 2026] [security2:error] [pid 32492:tid 32492] [client 34.106.149.134:57432] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.shelbysmoak.com"] [uri "/.env.dev"] [unique_id "apzjztOnIlUs6J1yKQ1NvwAAAHk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-06 03:33:48
(22 hours ago)
[server.tmg.gr] httpd-config-scan: sites=www.cardioathena2026.gr; logs=/var/log/httpd/domains/cardio ...
show more
[server.tmg.gr] httpd-config-scan: sites=www.cardioathena2026.gr; logs=/var/log/httpd/domains/cardioathena2026.gr.log; samples=/.env.bak | /actuator/configprops | /.env.backup
show less
Hacking
Web App Attack
🇩🇪
paissangroup
2026-09-06 03:25:12
(22 hours ago)
Multiple WAF Violations
Web App Attack
Anonymous
2026-09-06 03:22:02
(22 hours ago)
Bot / scanning and/or hacking attempts: GET /crusader-404-probe HTTP/1.1, GET /.env.local HTTP/1.1
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 03:05:38
(22 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.106.149.134 (134.149.106.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 34.106.149.134 (134.149.106.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 23:05:32.013894 2026] [security2:error] [pid 16605:tid 16605] [client 34.106.149.134:60982] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||puckerbackbikinis.puckerbikini.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "puckerbackbikinis.puckerbikini.com"] [uri "/dump.sql"] [unique_id "apzYfNpVLFuZfMTsxI2Z3QAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇹🇼
kk_it_man
2026-09-06 03:03:01
(22 hours ago)
ET INFO Request to Hidden Environment File - Inbound
ET WEB_SERVER Tilde in URI - potential .php~ ...
show more
ET INFO Request to Hidden Environment File - Inbound
ET WEB_SERVER Tilde in URI - potential .php~ source disclosure vulnerability
show less
Port Scan
Anonymous
2026-09-06 03:00:16
(22 hours ago)
(mod_security) mod_security triggered on hostname [redacted])
SQL Injection
🇬🇧
consul.to
2026-09-06 02:29:14
(23 hours ago)
Web attack/malicious scanning detected
Web App Attack
🇩🇪
ghostwarriors
2026-09-06 02:20:15
(23 hours ago)
Webpage scraping
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
thetomtaylor.co.uk
2026-09-06 02:08:00
(23 hours ago)
Fail2Ban - [WEB]Custom exploit pattern detected on customexploits ... [ice01,ice02]
Hacking
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
thetomtaylor.co.uk
2026-09-06 01:07:02
(1 day ago)
Fail2Ban - [WEB]Custom exploit pattern detected on customexploits ... [wa01,wa02]
Hacking
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 00:46:39
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.106.149.134 (134.149.106.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.106.149.134 (134.149.106.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 20:46:35.974388 2026] [security2:error] [pid 2281:tid 2281] [client 34.106.149.134:46944] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "aallred.com"] [uri "/.env.bak"] [unique_id "apy36-WEJa80u0K3Z9k0bgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
e.fierstra
2026-09-06 00:23:24
(1 day ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 00:18:46
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.106.149.134 (134.149.106.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.106.149.134 (134.149.106.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 20:18:41.913271 2026] [security2:error] [pid 15201:tid 15201] [client 34.106.149.134:50278] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "amybeam.com"] [uri "/wp-config.php~"] [unique_id "apyxYW7RPtTD4DcIIdc8YQAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack