๐ง๐ช
Savvii
2026-08-01 03:57:09
(32 minutes ago)
20 attempts against mh-misbehave-ban on escape
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-01 03:44:29
(45 minutes ago)
(mod_security) mod_security (id:210492) triggered by 34.125.169.50 (50.169.125.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.125.169.50 (50.169.125.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 31 23:44:22.452656 2026] [security2:error] [pid 1726103:tid 1726103] [client 34.125.169.50:53990] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.austli.com"] [uri "/docker/.env"] [unique_id "am1rlgvHBgciShALsgGfxAAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
ReyhZhao
2026-08-01 02:52:10
(1 hour ago)
Multiple ModSecurity blocks detected from a single source IP, including a restricted file access att ...
show more
Multiple ModSecurity blocks detected from a single source IP, including a restricted file access attempt and disallowed request content types.
show less
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-08-01 02:50:01
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.125.169.50 (50.169.125.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.125.169.50 (50.169.125.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 31 22:49:56.928675 2026] [security2:error] [pid 1088541:tid 1088541] [client 34.125.169.50:8732] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.sailsara.com"] [uri "/.env.local"] [unique_id "am1e1AwO6yPYOP0IoAcvRgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-08-01 02:37:37
(1 hour ago)
Restricted File Access Attempt. Matched phrase ".docker/" at REQUEST_FILENAME. (930130-131)
Hacking
Web App Attack
Anonymous
2026-08-01 02:35:11
(1 hour ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
๐ฎ๐ช
RoboSOC
2026-08-01 01:43:27
(2 hours ago)
React Server Components Remote Code Execution Vulnerability, PTR: 50.169.125.34.bc.googleusercontent ...
show more
React Server Components Remote Code Execution Vulnerability, PTR: 50.169.125.34.bc.googleusercontent.com.
show less
Hacking
๐ฉ๐ช
macrob
2026-08-01 01:26:34
(3 hours ago)
2026/08/01 01:26:32 [error] 3687372#3687372: *433439163 access forbidden by rule, client: 34.125.169 ...
show more
2026/08/01 01:26:32 [error] 3687372#3687372: *433439163 access forbidden by rule, client: 34.125.169.50, server: antzcapital.com, request: "GET /.env HTTP/1.1", host: "antzcapital.com"
2026/08/01 01:26:32 [error] 3687370#3687370: *433439166 access forbidden by rule, client: 34.125.169.50, server: antzcapital.com, request: "GET /.env.production HTTP/1.1", host: "antzcapital.com"
2026/08/01 01:26:32 [error] 3687372#3687372: *433439165 access forbidden by rule, client: 34.125.169.50, server: antzcapital.com, request: "GET /.env.local HTTP/1.1", host: "antzcapital.com"
...
show less
Web App Attack
๐บ๐ธ
WizardsToolkit
2026-08-01 01:00:20
(3 hours ago)
tried to access server backup files
Web App Attack
๐ฌ๐ง
consul.to
2026-08-01 00:23:42
(4 hours ago)
Web attack/malicious scanning detected
Web App Attack
๐ซ๐ฎ
YF
2026-08-01 00:00:41
(4 hours ago)
WordPress config file probe
Web App Attack
๐บ๐ธ
Victor Lรณpez
2026-07-31 23:54:59
(4 hours ago)
2026/07/31 18:54:59 [error] 1232094#1232094: *725479 limiting requests, excess: 53.300 by zone "gene ...
show more
2026/07/31 18:54:59 [error] 1232094#1232094: *725479 limiting requests, excess: 53.300 by zone "general", client: 34.125.169.50, server: vpardilalaw.com, request: "GET /.openclaw/openclaw.json HTTP/1.1", host: "vpardilalaw.com"
2026/07/31 18:54:59 [error] 1232091#1232091: *725522 limiting requests, excess: 53.300 by zone "general", client: 34.125.169.50, server: vpardilalaw.com, request: "GET /.azure/azureProfile.json HTTP/1.1", host: "vpardilalaw.com"
2026/07/31 18:54:59 [error] 1232094#1232094: *725481 limiting requests, excess: 53.300 by zone "general", client: 34.125.169.50, server: vpardilalaw.com, request: "GET /.cursor/mcp.json HTTP/1.1", host: "vpardilalaw.com"
2026/07/31 18:54:59 [error] 1232091#1232091: *725524 limiting requests, excess: 53.200 by zone "general", client: 34.125.169.50, server: vpardilalaw.com, request: "GET /.firebase/hosting.json HTTP/1.1", host: "vpardilalaw.com"
2026/07/31 18:54:59 [error] 1232093#1232093: *725457 limiting requests, excess: 53.300 by zone
...
show less
DDoS Attack
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-31 23:33:39
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.125.169.50 (50.169.125.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.125.169.50 (50.169.125.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 31 19:33:31.214187 2026] [security2:error] [pid 931:tid 931] [client 34.125.169.50:45820] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.berntson.org"] [uri "/.env.local"] [unique_id "am0wywP2jqnPEQ-X9ikyqAAAAC8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
BlueWire Hosting
2026-07-31 23:18:53
(5 hours ago)
Bad bot ignoring robot.txt
Bad Web Bot
๐ฒ๐พ
Rizzy
2026-07-31 23:17:44
(5 hours ago)
Multiple WAF Violations
Brute-Force
Web App Attack