๐ณ๐ฑ
ItsJustStan
2026-08-31 22:12:32
(3 weeks ago)
Web app attack - scanning for vulnerabilities
Web App Attack
๐ธ๐ช
vaia.cloud
2026-08-27 12:35:02
(1 month ago)
crowdsecurity/http-admin-interface-probing
Brute-Force
Web App Attack
๐ณ๐ฑ
Site.eu
2026-08-27 10:59:08
(1 month ago)
Excessive multi-domain requests
Brute-Force
๐ต๐ฑ
sledzik1984
2026-08-27 07:11:41
(1 month ago)
2026/08/27 09:11:40 [error] 1772#1772: *122321 directory index of "/home/cmapl/sql_backups/" is forb ...
show more
2026/08/27 09:11:40 [error] 1772#1772: *122321 directory index of "/home/cmapl/sql_backups/" is forbidden, client: 34.140.171.200, server: cma.pl, request: "GET /sql_backups/ HTTP/1.1", host: "www.cma.pl"
34.140.171.200 - - [27/Aug/2026:09:11:40 +0200] "GET /wp-*.php HTTP/1.1" 404 47 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
2026/08/27 09:11:41 [error] 1772#1772: *122321 directory index of "/home/cmapl/sql_backups/" is forbidden, client: 34.140.171.200, server: cma.pl, request: "GET /sql_backups/ HTTP/1.1", host: "www.cma.pl"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 06:21:48
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 34.140.171.200 (200.171.140.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.140.171.200 (200.171.140.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 02:21:41.139167 2026] [security2:error] [pid 32734:tid 32734] [client 34.140.171.200:54976] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.fresnogymnastics.com"] [uri "/.env"] [unique_id "ao_XdU1WNgfjI-ORxUfLCQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 03:33:52
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 34.140.171.200 (200.171.140.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.140.171.200 (200.171.140.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 23:33:47.100187 2026] [security2:error] [pid 26343:tid 26343] [client 34.140.171.200:34876] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.3beeze.bridgital.com"] [uri "/.git/HEAD"] [unique_id "ao-wGw85muavIVzhlMweJwAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
Starburst SysOp Team
2026-08-27 03:11:28
(1 month ago)
Restricted File Access Attempt. Matched phrase ".env" at REQUEST_FILENAME. (930130-stl2-14)
Hacking
Web App Attack
๐ฉ๐ช
todix
2026-08-27 02:50:01
(1 month ago)
Web App Attack Exploid from 34.140.171.200
Web App Attack
๐ฉ๐ช
andorin
2026-08-27 01:10:01
(1 month ago)
Automated report from halo.habith.eu (NGINX access log).
Detected 80 suspicious requests in last 20 ...
show more
Automated report from halo.habith.eu (NGINX access log).
Detected 80 suspicious requests in last 20000 lines.
Sample log lines:
34.140.171.200 - - [26/Aug/2026:03:50:19 +0200] "GET /.env HTTP/1.1" 403 195 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Geck\n34.140.171.200 - - [26/Aug/2026:03:50:19 +0200] "GET /.env.local HTTP/1.1" 404 3452 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, li\n34.140.171.200 - - [26/Aug/2026:03:50:19 +0200] "GET /api/.env.prod HTTP/1.1" 404 3452 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML,\n34.140.171.200 - - [26/Aug/2026:03:50:19 +0200] "GET /backend/.env.production HTTP/1.1" 404 3452 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.\n34.140.171.200 - - [26/Aug/2026:03:50:19 +0200] "GET /services/.env HTTP/1.1" 403 195 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, \n34.140.171.200 - - [26/Aug/2026:03:50:19 +0200] "GET /curr
show less
DDoS Attack
Ping of Death
Hacking
๐ซ๐ฎ
kumiko
2026-08-26 23:37:10
(1 month ago)
[2026-08-27 02:37:10] Probing for dotfiles
"GET /.env HTTP/1.1" 403
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-26 18:38:25
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 34.140.171.200 (200.171.140.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.140.171.200 (200.171.140.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 14:38:21.077327 2026] [security2:error] [pid 23337:tid 23337] [client 34.140.171.200:50470] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "4115thewestford.com"] [uri "/.env"] [unique_id "ao8ynb4E7Pl7X_8Lbf3cYAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-26 17:18:37
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 34.140.171.200 (200.171.140.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.140.171.200 (200.171.140.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 13:18:30.127762 2026] [security2:error] [pid 1008:tid 1008] [client 34.140.171.200:41032] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "40svocaltrio.com.flashbackmusicmemories.com"] [uri "/.env"] [unique_id "ao8f5n6j2p--l6PnK8IcPQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-26 14:04:25
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 34.140.171.200 (200.171.140.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.140.171.200 (200.171.140.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 10:04:19.787100 2026] [security2:error] [pid 51452:tid 51490] [client 34.140.171.200:57448] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "1shot.us"] [uri "/.env"] [unique_id "ao7yYxJHY9jCM-meRWIJZgAAAQQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
4server
2026-08-26 13:57:22
(1 month ago)
[WedAug2615:57:19.7000242026][security2:error][pid4007840:tid4007967][client34.140.171.200:0]ModSecu ...
show more
[WedAug2615:57:19.7000242026][security2:error][pid4007840:tid4007967][client34.140.171.200:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:5\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.10\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"viveretrentino.it\"][uri\"/.git/HEAD\"][unique_id\"ao7wvyORSKux-fYWcib1ewAAARA\"]
show less
Port Scan
Brute-Force
Web App Attack
๐บ๐ธ
ambor
2026-08-26 09:04:24
(1 month ago)
L0ss Honeypot: Environment file access attempt. Path: /.env
Web App Attack