๐ณ๐ฑ
homeshowdomain.nl
2026-08-28 22:02:27
(4 days ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-08-27.
show less
Web App Attack
SSH
Hacking
๐ง๐ท
SOC-BR
2026-08-28 07:18:05
(5 days ago)
Attack detected by Fortinet - applications3: Spring.Boot.Actuator.Unauthorized.Access - 2026-08-27 1 ...
show more
Attack detected by Fortinet - applications3: Spring.Boot.Actuator.Unauthorized.Access - 2026-08-27 19:12:52 - Source Port 56192
show less
Port Scan
Hacking
Anonymous
2026-08-27 22:19:31
(5 days ago)
WordPress Enforcement Protection.
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 22:17:44
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 34.173.234.89 (89.234.173.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.173.234.89 (89.234.173.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 18:17:37.997451 2026] [security2:error] [pid 28168:tid 28168] [client 34.173.234.89:36078] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "lazymanvegan.com"] [uri "/wp-config.php.swp"] [unique_id "apC3gWa2FxmRAyabMun8KwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-27 22:10:10
(5 days ago)
| Suspicious URL access.
Web App Attack
Hacking
SQL Injection
๐ง๐ช
sid3windr
2026-08-27 22:01:34
(5 days ago)
GET /.env (Tarpitted for 4m18s, wasted 15.23kB)
Web App Attack
๐ณ๐ฑ
0xffffffff
2026-08-27 21:58:58
(5 days ago)
[2026-08-28 00:58:56.407972] [authz_core:error] [pid 2325289:tid 127817622746816] [client 34.173.234 ...
show more
[2026-08-28 00:58:56.407972] [authz_core:error] [pid 2325289:tid 127817622746816] [client 34.173.234.89:46204] AH01630: client denied by server configuration: /var/www/*/.env.local , error_notes:config-files , URI:'/.env.local'
[2026-08-28 00:58:56.409365] [authz_core:error] [pid 2325236:tid 127818262423232] [client 34.173.234.89:46252] AH01630: client denied by server configuration: /var/www/*/env , error_notes:wrong-host , URI:'/env'
[2026-08-28 00:58:56.412272] [authz_core:error] [pid 2325289:tid 127817840826048] [client 34.173.234.89:46280] AH01630: client denied by server configuration: /var/www/*/wp-config.php~ , error_notes:wp:root-files , URI:'/wp-config.php~'
[2026-08-28 00:58:56.412640] [authz_core:error] [pid 2325236:tid 127818254030528] [client 34.173.234.89:46194] AH01630: client denied by server configuration: /var/www/*/_ignition , error_notes:non-dirs , URI:'/_ignition/health-check'
[2026-08-28 00:58:56.421709] [authz_core:error] [pid 2325236:tid 127818245637824] [client 34.173.234.89:46258] A
show less
Web App Attack
Bad Web Bot
๐ธ๐ช
vaia.cloud
2026-08-27 19:00:03
(5 days ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 18:56:51
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 34.173.234.89 (89.234.173.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.173.234.89 (89.234.173.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 14:56:44.794464 2026] [security2:error] [pid 30321:tid 30321] [client 34.173.234.89:57524] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "geno-med.com"] [uri "/wp-config.php.swp"] [unique_id "apCIbGY1Ut3azHjI4hKiTwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
craudiovizai
2026-08-27 18:31:09
(5 days ago)
Automated honeypot detection. honeypot against a Next.js application. Paths: /actuator/configprops, ...
show more
Automated honeypot detection. honeypot against a Next.js application. Paths: /actuator/configprops, /.env.local, /.env.production. Blocked at the edge.
show less
Web App Attack
Bad Web Bot
๐ฉ๐ช
wpadm4
2026-08-27 18:24:21
(5 days ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
๐ท๐บ
DZBOT
2026-08-27 18:09:46
(5 days ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 17:56:22
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 34.173.234.89 (89.234.173.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.173.234.89 (89.234.173.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 13:56:16.352529 2026] [security2:error] [pid 22122:tid 22122] [client 34.173.234.89:36196] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.payrrip.com.thelowensteinfamily.com"] [uri "/wp-config.php.swp"] [unique_id "apB6QPH6TdAGePv8kvZuWQAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐ฉ
Burayot
2026-08-27 17:38:51
(5 days ago)
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 34.173.234.89 (US/United States/89. ...
show more
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 34.173.234.89 (US/United States/89.234.173.34.bc.googleusercontent.com): 1 in the last 3600 secs
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 17:03:07
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 34.173.234.89 (89.234.173.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.173.234.89 (89.234.173.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 13:03:03.182334 2026] [security2:error] [pid 2731:tid 2731] [client 34.173.234.89:53970] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "james.ahlstrom.name"] [uri "/.env.production"] [unique_id "apBtx7L-u7HQK9AFGvB3RQAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack