Anonymous
2026-08-28 07:47:00
(2 days ago)
Various attempts to fetch passwd file
Web App Attack
Hacking
Anonymous
2026-08-26 17:00:04
(3 days ago)
Bot / scanning and/or hacking attempts: GET /bitbucket-pipelines.yml HTTP/1.1, GET /.github/workflow ...
show more
Bot / scanning and/or hacking attempts: GET /bitbucket-pipelines.yml HTTP/1.1, GET /.github/workflows/docker.yml HTTP/1.1, GET /.env.ci HTTP/1.1, GET /api/v1/fetch?url=http%3A%2F%2F169.254.169.254%2Flatest%2Fm, GET /.env.json HTTP/1.1, GET /.env.production.local HTTP/1.1, GET /.env.openai HTTP/1.1, GET /.github/workflows/main.yml HTTP/1.1, GET /.travis.yml HTTP/1.1, GET /aws.env HTTP/1.1, GET /.github/workflows/test.yml HTTP/1.1, GET /.github/workflows/release.yml HTTP/1.1, GET /.jenkins/config.xml HTTP/1.1, GET /config/jenkins.conf HTTP/1.1, GET /var/www/.env HTTP/1.1, GET /.github/secrets.env HTTP/1.1, GET /.github/workflows/publish.yml HTTP/1.1, GET /job/.env HTTP/1.1, GET /.github/workflows/build.yml HTTP/1.1, GET /jenkins/Jenkinsfile HTTP/1.1
show less
Hacking
Web App Attack
🇬🇧
consul.to
2026-08-26 16:37:04
(3 days ago)
Web attack/malicious scanning detected
Web App Attack
🇮🇹
CoreTech srl
2026-08-26 16:28:57
(3 days ago)
cloudlinux2 fail2ban: 2026-08-26 18:24:25,626 fail2ban.filter [1775]: INFO [plesk-modsecu ...
show more
cloudlinux2 fail2ban: 2026-08-26 18:24:25,626 fail2ban.filter [1775]: INFO [plesk-modsecurity] Found 35.194.162.14 - 2026-08-26 18:24:25cloudlinux2 fail2ban: 2026-08-26 18:25:02,481 fail2ban.filter [1775]: INFO [plesk-modsecurity] Found 165.22.107.47 - 2026-08-26 18:25:02cloudlinux2 fail2ban: 2026-08-26 18:25:05,194 fail2ban.filter [1775]: INFO [plesk-modsecurity] Found 165.22.107.47 - 2026-08-26 18:25:05cloudlinux2 fail2ban: 2026-08-26 18:25:43,319 fail2ban.filter [1775]: INFO [plesk-modsecurity] Found 34.124.147.134 - 2026-08-26 18:25:43cloudlinux2 fail2ban: 2026-08-26 18:25:43,354 fail2ban.filter [1775]: INFO [plesk-modsecurity] Found 34.124.147.134 - 2026-08-26 18:25:43cloudlinux2 fail2ban: 2026-08-26 18:25:43,403 fail2ban.filter [1775]: INFO [plesk-modsecurity] Found 34.124.147.134 - 2026-08-26 18:25:43cloudlinux2 fail2ban: 2026-08-26 18:25:43,376 fail2ban.filter [1775]: INFO [plesk-modsecurity] Found 34.124.147.134 - 2026-08-26
show less
Brute-Force
🇺🇸
TPI-Abuse
2026-08-26 15:19:18
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 34.124.147.134 (134.147.124.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.124.147.134 (134.147.124.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 11:19:14.372642 2026] [security2:error] [pid 4884:tid 4884] [client 34.124.147.134:52158] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "tex-fun.com"] [uri "/static../.env"] [unique_id "ao8D8rk8p05irVeF3yOq5gAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇵🇱
Budyn
2026-08-26 15:10:23
(4 days ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: CRITICAL: ModSecurity WAF Exploit ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: CRITICAL: ModSecurity WAF Exploit Block. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: teddypot.online | URI: /.git-credentials | UA: Mozilla/5.0 (X11; Ubuntu; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko; compatible; facebookexternalhit/1.1; +http://www.facebook.com/externalhit_uatext.php) Chrome/148.0.8960.145 Safari/537.36 Edg/148.0.8960.145 | BODY: [Empty / GET Request]
show less
Hacking
Web App Attack
🇳🇱
Mangelot Hosting
2026-08-26 13:53:11
(4 days ago)
(modsecurity) srv103 ModSecurity 34.124.147.134 (SG/Singapore/134.147.124.34.bc.googleusercontent.co ...
show more
(modsecurity) srv103 ModSecurity 34.124.147.134 (SG/Singapore/134.147.124.34.bc.googleusercontent.com): 30 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs:
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-08-26 13:28:53
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 34.124.147.134 (134.147.124.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.124.147.134 (134.147.124.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 09:28:47.879957 2026] [security2:error] [pid 16561:tid 16561] [client 34.124.147.134:47730] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "tersch.com"] [uri "/.git/HEAD"] [unique_id "ao7qDy8KDMOcR1BX8RrdfQAAACA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
Octopuce
2026-08-26 13:08:56
(4 days ago)
Aggressive web search of vulnerable pages: /app/.env /.env.local /.env /media../.env /web/.env ...
Web App Attack
🇩🇪
LRob
2026-08-26 12:54:26
(4 days ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /@fs/proc/self/environ (+13 more) | 2026-08-26 12:54 UTC
show less
Hacking
Web App Attack
🇳🇱
WeCloudit-Anti-Abuse
2026-08-26 12:41:35
(4 days ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-path-traversal-probing
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-08-26 12:25:44
(4 days ago)
(mod_security) mod_security (id:211190) triggered by 34.124.147.134 (134.147.124.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:211190) triggered by 34.124.147.134 (134.147.124.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 08:25:40.156518 2026] [security2:error] [pid 23378:tid 23378] [client 34.124.147.134:36116] ModSecurity: Access denied with code 403 (phase 2). Match of "contains cpanel" against "REQUEST_URI" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "55"] [id "211190"] [rev "9"] [msg "COMODO WAF: Remote File Access Attempt||lusineweb.com|F|2"] [data "Matched Data: /etc/ found within REQUEST_URI: /?file=../../../../etc/passwd"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "lusineweb.com"] [uri "/"] [unique_id "ao7bRLiEq-rWVC_L5ypvrQAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
gigatech
2026-08-26 12:05:03
(4 days ago)
Webserver Probing
Web App Attack
🇺🇸
TPI-Abuse
2026-08-26 12:01:08
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 34.124.147.134 (134.147.124.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.124.147.134 (134.147.124.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 08:00:59.714600 2026] [security2:error] [pid 11269:tid 11269] [client 34.124.147.134:29274] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "monmouthcountydanceclasses.com"] [uri "/static../.env"] [unique_id "ao7Ve5a4mjuqxgTye05cEwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-26 11:14:17
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 34.124.147.134 (134.147.124.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.124.147.134 (134.147.124.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 07:14:10.985175 2026] [security2:error] [pid 16411:tid 16411] [client 34.124.147.134:33872] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.myhrer.info"] [uri "/app/.env"] [unique_id "ao7KgvTgOuf2PTJQDHQfjQAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack