Anonymous
2026-09-16 05:25:02
(6 hours ago)
suspicious request in access.log
Web App Attack
π¬π§
openstrike.co.uk
2026-09-16 05:14:57
(6 hours ago)
161 attacks on env grabbing URLs, VC URLs, PHP URLs:
GET /bulk/.env HTTP/1.1
GET /.git/config HTTP/1 ...
show more
161 attacks on env grabbing URLs, VC URLs, PHP URLs:
GET /bulk/.env HTTP/1.1
GET /.git/config HTTP/1.1
GET /smtp/phpinfo.php HTTP/1.1
show less
Hacking
Web App Attack
π³π±
Savvii
2026-09-16 04:47:58
(7 hours ago)
20 attempts against mh-misbehave-ban on ozone
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-16 04:21:18
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.13.47.49 (49.47.13.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.13.47.49 (49.47.13.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 00:21:10.704584 2026] [security2:error] [pid 3905:tid 3905] [client 34.13.47.49:43470] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "paihianz.com"] [uri "/.git/config"] [unique_id "aqoZNrHWAq3foGOcPlRGhwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π²π½
octageeks.com
2026-09-16 04:10:47
(7 hours ago)
Wordpress malicious attack:[octablocked]
Web App Attack
π«π·
Octopuce
2026-09-16 04:00:27
(8 hours ago)
Aggressive web search of vulnerable pages: / /.env /.env.local /app/.env /apps/.env ...
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-16 01:58:02
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.13.47.49 (49.47.13.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.13.47.49 (49.47.13.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 21:57:57.050759 2026] [security2:error] [pid 23439:tid 23439] [client 34.13.47.49:43492] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "paguilar.com"] [uri "/.git/config"] [unique_id "aqn3pYkqRcKcEqBrZec90AAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π΅π±
Budyn
2026-09-15 22:12:44
(13 hours ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scan ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scanner. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: staging.goblinpot.online | URI: /.git/config | UA: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36 | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-15 18:24:20
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.13.47.49 (49.47.13.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.13.47.49 (49.47.13.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 14:24:16.126563 2026] [security2:error] [pid 16820:tid 16820] [client 34.13.47.49:35752] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "staging.eta-mct.com"] [uri "/.git/config"] [unique_id "aqmNUNSXBLfMraeHXgjUoAAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-15 16:17:38
(19 hours ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack
π΅π±
Budyn
2026-09-15 16:08:08
(20 hours ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scan ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scanner. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: staging.dont-eat-the-pudding.xyz | URI: /.git/config | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36 | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
π©πͺ
cloudmax
2026-09-15 15:52:05
(20 hours ago)
Cloudmax Protect [WEB BLOCK] - Too many 400/500 requests. Possible attack or hacking attempt
Hacking
Web App Attack
π³π±
Savvii
2026-09-15 13:09:42
(23 hours ago)
20 attempts against mh_ha-misbehave-ban on eris
Brute-Force
Bad Web Bot
Web App Attack
π«π·
masterguru
2026-09-15 09:44:22
(1 day ago)
Remote Command Execution: Unix Command Injection (command without evasion). Pattern match "(?i)(?:b ...
show more
Remote Command Execution: Unix Command Injection (command without evasion). Pattern match "(?i)(?:b (932235-195)
show less
Hacking
πΊπΈ
kosada.com
2026-09-15 08:53:35
(1 day ago)
Repeated exploit attempts, for example: /.env.staging /.env (HTTP/1.1 port 443, user agent: "Mozilla ...
show more
Repeated exploit attempts, for example: /.env.staging /.env (HTTP/1.1 port 443, user agent: "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36")
show less
Web App Attack