๐ซ๐ท
Stara
2026-09-04 15:40:55
(1 week ago)
ModSecurity detected web attack - .env/config probing or SQLi/Code injection (Rule 949110)
Brute-Force
SSH
Web App Attack
Anonymous
2026-09-04 15:35:02
(1 week ago)
Bot / scanning and/or hacking attempts: GET /.gcloud/credentials HTTP/1.1, GET /.github/.env HTTP/1. ...
show more
Bot / scanning and/or hacking attempts: GET /.gcloud/credentials HTTP/1.1, GET /.github/.env HTTP/1.1, GET /.git/HEAD HTTP/1.1, GET /config/.env HTTP/1.1, GET /.git-credentials HTTP/1.1, GET /root/.aws/credentials HTTP/1.1, GET /src/.env HTTP/1.1, GET /.git/config HTTP/1.1, GET /.aws/config HTTP/1.1, GET /root/.aws/config HTTP/1.1, GET /.env.development HTTP/1.1, GET /laravel/.env HTTP/1.1, GET /public/.env HTTP/1.1, GET /.aws/credentials HTTP/1.1
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-04 15:16:14
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 34.148.64.113 (113.64.148.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.148.64.113 (113.64.148.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 11:16:06.608780 2026] [security2:error] [pid 22484:tid 22484] [client 34.148.64.113:46078] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.fredlandia.com"] [uri "/@fs/.env"] [unique_id "aprgti1RXTa5uUm6pyxITgAAAHs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
leo1305
2026-09-04 15:09:47
(2 weeks ago)
CrowdSec detection | scenario: http-path-traversal-probing
Web App Attack
Exploited Host
๐บ๐ธ
TPI-Abuse
2026-09-04 13:58:30
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 34.148.64.113 (113.64.148.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.148.64.113 (113.64.148.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 09:58:26.561686 2026] [security2:error] [pid 30645:tid 30645] [client 34.148.64.113:65050] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "urban-tails.com"] [uri "/@fs/src/.env"] [unique_id "aprOgqrNpDPQNePaYAzxTgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-04 13:22:28
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 34.148.64.113 (113.64.148.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.148.64.113 (113.64.148.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 09:22:24.285016 2026] [security2:error] [pid 14947:tid 14947] [client 34.148.64.113:52842] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.pamfilyataban.com"] [uri "/@fs/.env"] [unique_id "aprGEIZzEMy1EvAXhj5jjAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
YF
2026-09-04 13:00:14
(2 weeks ago)
Distributed subnet attack โ coordinated scanning from multiple IPs in the same /24
DDoS Attack
Web App Attack
๐ณ๐ฑ
middelkoopcc
2026-09-04 12:13:00
(2 weeks ago)
2026-09-04 14:11:28 GET /@fs/home/www-data/.aws/credentials?raw?? [404] && 2026-09-04 14:11:28 GET / ...
show more
2026-09-04 14:11:28 GET /@fs/home/www-data/.aws/credentials?raw?? [404] && 2026-09-04 14:11:28 GET /@fs/home/node/.aws/credentials?raw?? [404] && 2026-09-04 14:11:28 GET /@fs/src/.env?raw?? [404] && 113 more within 20 minutes
show less
Web App Attack
๐บ๐ธ
mnsf
2026-09-04 12:05:13
(2 weeks ago)
Abuse Detected (9)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-04 11:06:38
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 34.148.64.113 (113.64.148.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.148.64.113 (113.64.148.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 07:06:30.451461 2026] [security2:error] [pid 11145:tid 11165] [client 34.148.64.113:56798] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "dailysavershbg.com"] [uri "/@fs/.env"] [unique_id "apqmNnrzwxXVEFl6VeBaGQAAARI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-04 09:15:58
(2 weeks ago)
Blocked by ModSec and CSF
Port Scan
Anonymous
2026-09-04 09:03:38
(2 weeks ago)
34.148.64.113 - - [04/Sep/2026:11:01:26 +0200] "GET /.env?raw?? HTTP/1.1" 403 1856 "Mozilla/5.0 App ...
show more
34.148.64.113 - - [04/Sep/2026:11:01:26 +0200] "GET /.env?raw?? HTTP/1.1" 403 1856 "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ChatGPT-User/1.0; +https://openai.com/bot"
show less
Web Spam
Blog Spam
Brute-Force
Web App Attack
๐ณ๐ฑ
ConsulHosting
2026-09-04 08:59:03
(2 weeks ago)
Excessive failed CAPTCHA attempts (CAPTCHA DoS)
Web App Attack
๐ฆ๐บ
rubixstudios
2026-09-04 08:47:02
(2 weeks ago)
Excessive HTTP requests consistent with automated attack behaviour detected by Imunify360
DDoS Attack
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-04 08:05:06
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 34.148.64.113 (113.64.148.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.148.64.113 (113.64.148.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 04:05:00.884071 2026] [security2:error] [pid 23062:tid 23062] [client 34.148.64.113:13540] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.performingartsguild.com"] [uri "/@fs/.env"] [unique_id "app7rFsPQKOfsI7RrmXzAwAAAHU"]
show less
Brute-Force
Bad Web Bot
Web App Attack