๐ฉ๐ช
LRob
2026-08-18 20:31:47
(22 minutes ago)
Credential and secrets file probing | req: /.git-credentials | UA: Mozilla/5.0 (compatible; Amazonbo ...
show more
Credential and secrets file probing | req: /.git-credentials | UA: Mozilla/5.0 (compatible; Amazonbot/0.1; +https://developer.amazon.com/support/amazonbot)
show less
Hacking
Web App Attack
Anonymous
2026-08-18 20:01:41
(52 minutes ago)
(mod_security) mod_security triggered on hostname [redacted])
SQL Injection
๐ซ๐ท
Octopuce
2026-08-18 19:57:51
(56 minutes ago)
Aggressive web search of vulnerable pages: /.env /media../.env /.env.local /app/.env /files../.env ...
show more
Aggressive web search of vulnerable pages: /.env /media../.env /.env.local /app/.env /files../.env ...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-18 19:53:13
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.124.183.11 (11.183.124.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.124.183.11 (11.183.124.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 18 15:53:07.424539 2026] [security2:error] [pid 8991:tid 8991] [client 34.124.183.11:59726] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jaragoodrich.com"] [uri "/@fs/../.env"] [unique_id "aoS4IyOej7bFsZ2rvhAGYQAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-18 18:40:15
(2 hours ago)
(mod_security) mod_security (id:211190) triggered by 34.124.183.11 (11.183.124.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:211190) triggered by 34.124.183.11 (11.183.124.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 18 14:40:12.331490 2026] [security2:error] [pid 13626:tid 13626] [client 34.124.183.11:3760] ModSecurity: Access denied with code 403 (phase 2). Match of "contains cpanel" against "REQUEST_URI" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "55"] [id "211190"] [rev "9"] [msg "COMODO WAF: Remote File Access Attempt||zztp.ws|F|2"] [data "Matched Data: /etc/ found within REQUEST_URI: /download?file=../../../../etc/passwd"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "zztp.ws"] [uri "/download"] [unique_id "aoSnDMdzOG2DVtX5DF3q7wAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฒ๐พ
Rizzy
2026-08-18 18:35:20
(2 hours ago)
Multiple WAF Violations
Brute-Force
Web App Attack
Anonymous
2026-08-18 18:24:41
(2 hours ago)
2026/08/18 18:24:35 [error] 539#539: *39021 [client 34.124.183.11] ModSecurity: Access denied with c ...
show more
2026/08/18 18:24:35 [error] 539#539: *39021 [client 34.124.183.11] ModSecurity: Access denied with code 403 (phase 2). Matched "Operator `Ge' with parameter `16' against variable `TX:BLOCKING_INBOUND_ANOMALY_SCORE' (Value: `30' ) [file "/etc/modsecurity.d/owasp-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "222"] [id "949110"] [rev ""] [msg "Inbound Anomaly Score Exceeded (Total Score: 30)"] [data ""] [severity "0"] [ver "OWASP_CRS/4.16.0"] [maturity "0"] [accuracy "0"] [tag "modsecurity"] [tag "anomaly-evaluation"] [tag "OWASP_CRS"] [hostname "homesex.casa"] [uri "/download"] [unique_id "178707747535.831657"] [ref ""], client: 34.124.183.11, server: homesex.casa, request: "GET /download?file=../../../../etc/passwd HTTP/1.1", host: "homesex.casa"
2026/08/18 18:24:35 [error] 539#539: *39016 [client 34.124.183.11] ModSecurity: Access denied with code 403 (phase 2). Matched "Operator `Ge' with parameter `16' against variable `TX:BLOCKING_INBOUND_ANOMALY_SCORE' (Value: `30' ) [fil
...
show less
Hacking
Web App Attack
๐ธ๐ช
vaia.cloud
2026-08-18 17:40:01
(3 hours ago)
crowdsecurity/http-admin-interface-probing
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-18 16:36:59
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.124.183.11 (11.183.124.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.124.183.11 (11.183.124.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 18 12:36:53.566684 2026] [security2:error] [pid 21986:tid 21986] [client 34.124.183.11:24000] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.support.tbvfc.com"] [uri "/@fs/../.env"] [unique_id "aoSKJbks4eDcZ-d0kBN3SAAAAB8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-18 16:17:14
(4 hours ago)
RdpGuard detected brute-force attempt on HTTP
Brute-Force
๐ณ๐ฟ
Antinson
2026-08-18 15:43:44
(5 hours ago)
Scraping with a high error ratio and request rate
Bad Web Bot
๐ฉ๐ช
Hazzard
2026-08-18 15:24:27
(5 hours ago)
*Port Scan* detected from 34.124.183.11 (SG/Singapore/-/Singapore/11.183.124.34.bc.googleusercontent ...
show more
*Port Scan* detected from 34.124.183.11 (SG/Singapore/-/Singapore/11.183.124.34.bc.googleusercontent.com/[redacted]).
show less
Port Scan
๐บ๐ธ
NXTwoThou
2026-08-18 15:12:32
(5 hours ago)
/assets../../../etc/passwd
Web App Attack
๐ณ๐ฑ
Site.eu
2026-08-18 14:54:43
(5 hours ago)
Excessive multi-domain requests
Brute-Force
๐ณ๐ฑ
ConsulHosting
2026-08-18 07:41:10
(13 hours ago)
Excessive failed CAPTCHA attempts (CAPTCHA DoS)
Web App Attack