๐ฉ๐ช
FeG Deutschland
2026-09-15 09:05:01
(3 days ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 1247
Exploited Host
Web App Attack
Anonymous
2026-09-15 08:55:01
(3 days ago)
suspicious request in access.log
Web App Attack
๐ต๐ฑ
wielorzeczownik
2026-09-15 08:39:32
(3 days ago)
5 failed attempts
2026-09-15 10:39:21 GET /.git/config -> 404
2026-09-15 10:39:22 GET /.env -> ...
show more
5 failed attempts
2026-09-15 10:39:21 GET /.git/config -> 404
2026-09-15 10:39:22 GET /.env -> 404
2026-09-15 10:39:22 GET /.env.local -> 404
2026-09-15 10:39:23 GET /.env.production -> 404
2026-09-15 10:39:23 GET /.env.staging -> 404
show less
Web App Attack
Hacking
๐ฉ๐ช
4server
2026-09-15 05:42:40
(3 days ago)
[TueSep1507:42:37.6452622026][security2:error][pid2828274:tid2828334][client34.175.207.43:0]ModSecur ...
show more
[TueSep1507:42:37.6452622026][security2:error][pid2828274:tid2828334][client34.175.207.43:0]ModSecurity:Accessdeniedwithcode403\(phase2\).Patternmatch\"\(\?:\\\\\\\\\$\(\?:\\\\\\\\\(\(\?:\\\\\\\\\(.\*\\\\\\\\\)\|.\*\)\\\\\\\\\)\|\\\\\\\\{.\*\\\\\\\\}\)\|[\<\>]\\\\\\\\\(.\*\\\\\\\\\)\)\"atARGS:0.[file\"/etc/apache2/conf.d/modsec_rules/10_asl_rules.conf\"][line\"396\"][id\"393655\"][rev\"17\"][msg\"Atomicorp.comWAFRules:PossibleRemoteCommandExecution:UnixShellExpressionFound\"][data\"MatchedData:\$\(\(41\*271\)\)foundwithinARGS:0:{then:\$1:__proto__:thenstatus:resolved_modelreason:-1value:{then:\$b1337}_response:{_prefix:varres=process.mainmodule.require\(child_process\).execsync\(echo\$\(\(41\*271\)\)\|base64-w0\).tostring\(\).trim\(\)throwobject.assign\(newerror\(next_redirect\){digest:\`next_redirectpush/login\?a=\${res}307\`}\)_chunks:\$q2_formdata:{get:\$1:constructor:constructor}}}\"][tag\"attack-rce\"][hostname\"furgonianoleggio.ch\"][uri\"/\"][unique_id\"aqjazcskZFEsKJKYCINxpAAAAFE\"]
show less
Port Scan
Brute-Force
Web App Attack
Anonymous
2026-09-15 05:17:31
(3 days ago)
GET /.git/config HTTP/1.1
...
Web App Attack
๐ซ๐ฎ
mnazibo
2026-09-15 04:00:06
(3 days ago)
Date: 15/Sep/2026 06:30:25 | Reported IP: 34.175.207.43 mod_security | id: 930130 932130 932235 9322 ...
show more
Date: 15/Sep/2026 06:30:25 | Reported IP: 34.175.207.43 mod_security | id: 930130 932130 932235 932260 933135 934100 934130 942151 942550 | ES/group.my_domain/- | Connections: 248 | Blocked: Permanent Block: [LF_MODSEC] | URIs: /; /actions/.env; /admin/.env; /administrator/.env; /administrator/phpinfo.php; /admin-panel/.env; /admin/phpinfo.php; /angular/.env; /ansible/.env; /api/dev/.env; /api/.env; /api/staging/.env; /api/v1/.env; /api/v2/.env; /api/v3/.env; /app/.env; /application_default_credentials.json; /application/.env; /apps/.env; /aws/.env; /azure/.env; /backend/.env; /backup/.env; /backups/.env; /beta/.env; /beta/phpinfo.php; /bin/.env; /bootstrap/.env; /brevo/.env; /build/.env; /buildkite/.env; /bulk/.env; /cache/.env; /cakephp/.env; /campaign/.env; /cd/.env; /ci/.env; /circleci/.env; /client/.env; /cloud/.env; /cms/.env; /codeigniter/.env; /config/app/.env; /config/.env; /.config/gcloud/application_default_credentials.json;
show less
SQL Injection
Brute-Force
Bad Web Bot
๐ฌ๐ง
consul.to
2026-09-15 02:25:07
(3 days ago)
Web attack/malicious scanning detected
Web App Attack
๐ช๐ธ
elcruzado.es
2026-09-14 21:09:15
(4 days ago)
(mod_security) mod_security triggered on hostname [redacted] 34.175.207.43 (ES/Spain/43.207.175.34.b ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.175.207.43 (ES/Spain/43.207.175.34.bc.googleusercontent.com)
show less
SQL Injection
๐ณ๐ฑ
Site.eu
2026-09-14 20:59:27
(4 days ago)
Excessive multi-domain requests
Brute-Force
Anonymous
2026-09-14 19:21:02
(4 days ago)
Bot / scanning and/or hacking attempts: POST / HTTP/1.1, GET /.git/config HTTP/1.1
Hacking
Web App Attack
๐ช๐ธ
robotstxt
2026-09-14 16:55:14
(4 days ago)
34.175.207.43 - - [14/Sep/2026:16:54:35 +0000] "POST / HTTP/1.1" 403 126755 "-" "Mozilla/5.0 (X11; L ...
show more
34.175.207.43 - - [14/Sep/2026:16:54:35 +0000] "POST / HTTP/1.1" 403 126755 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "-" edge="34.175.207.43"
34.175.207.43 - - [14/Sep/2026:16:54:35 +0000] "POST / HTTP/1.1" 403 126796 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "-" edge="34.175.207.43"
34.175.207.43 - - [14/Sep/2026:16:54:35 +0000] "GET /.git/config HTTP/1.1" 403 48836 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "-" edge="34.175.207.43"
34.175.207.43 - - [14/Sep/2026:16:54:36 +0000] "GET /.env HTTP/1.1" 403 48835 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "-" edge="34.175.207.43"
34.175.207.43 - - [14/Sep/2026:16:54:36 +0000] "GET /.env.local HTTP/1.1" 403 48835 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like
...
show less
Web App Attack
Anonymous
2026-09-14 16:29:56
(4 days ago)
Banned by Fail2Ban on server
Web App Attack
๐ซ๐ฎ
pixiekat
2026-09-14 14:38:48
(4 days ago)
[Mon Sep 14 15:38:47.323110 2026] [security2:error] [pid 1348603:tid 1348636] [client 34.175.207.43: ...
show more
[Mon Sep 14 15:38:47.323110 2026] [security2:error] [pid 1348603:tid 1348636] [client 34.175.207.43:60356] ModSecurity: Access denied with code 403 (phase 1). Pattern match ".+" at REQUEST_HEADERS:Next-Action. [file "/mnt/HC_Volume_105148208/crs/crs-custom.conf"] [line "166"] [id "9000100"] [msg "Next.js Server Action probe blocked (no Next.js apps on this server)"] [tag "custom/next-action-recon"] [hostname "funcoland.spacecadetgrrl.me"] [uri "/"] [unique_id "aqgG90Xq2sSo_-dsIBuB4AAAAIU"]
[Mon Sep 14 15:38:47.609902 2026] [security2:error] [pid 1296247:tid 1296296] [client 34.175.207.43:60372] ModSecurity: Access denied with code 403 (phase 1). Pattern match ".+" at REQUEST_HEADERS:Next-Action. [file "/mnt/HC_Volume_105148208/crs/crs-custom.conf"] [line "166"] [id "9000100"] [msg "Next.js Server Action probe blocked (no Next.js apps on this server)"] [tag "custom/next-action-recon"] [hostname "funcoland.spacecadetgrrl.me"] [uri "/"] [unique_id "aqgG97YqNPWF-JRq7JFf7gAAAFU"]
[Mon Sep 1
...
show less
Web App Attack
๐ธ๐ช
vaia.cloud
2026-09-14 14:30:02
(4 days ago)
crowdsecurity/http-admin-interface-probing
Brute-Force
Web App Attack
๐ฉ๐ช
Gwyneth Llewelyn
2026-09-13 14:48:38
(5 days ago)
2026/09/13 15:48:25 [error] 1459171#1459171: *621127 access forbidden by rule, client: 34.175.207.43 ...
show more
2026/09/13 15:48:25 [error] 1459171#1459171: *621127 access forbidden by rule, client: 34.175.207.43, server: feminina.eu, request: "GET /.env HTTP/2.0", host: "feminina.eu"
34.175.207.43 - - [13/Sep/2026:15:48:25 +0100] "GET /.env HTTP/2.0" 403 138 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
2026/09/13 15:48:37 [error] 1459171#1459171: *621176 access forbidden by rule, client: 34.175.207.43, server: feminina.eu, request: "GET /app/.env HTTP/2.0", host: "feminina.eu"
show less
Brute-Force
Web App Attack