๐ฉ๐ช
Hazzard
2026-08-28 13:33:54
(3 hours ago)
(mod_security) mod_security triggered on hostname [redacted]): (CF_ENABLE)
SQL Injection
๐ณ๐ฑ
Savvii
2026-08-28 12:26:27
(4 hours ago)
20 attempts against mh-misbehave-ban on onion
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
debestelapp
2026-08-28 08:55:06
(7 hours ago)
Web App Attack
๐ณ๐ฑ
Mangelot Hosting
2026-08-28 07:51:36
(8 hours ago)
(modsecurity) srv101 ModSecurity 34.178.210.167 (NL/The Netherlands/167.210.178.34.bc.googleusercont ...
show more
(modsecurity) srv101 ModSecurity 34.178.210.167 (NL/The Netherlands/167.210.178.34.bc.googleusercontent.com): 30 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs:
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 07:23:44
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.178.210.167 (167.210.178.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.178.210.167 (167.210.178.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 03:23:37.350298 2026] [security2:error] [pid 4678:tid 4678] [client 34.178.210.167:27790] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.ryszardwycisk.com"] [uri "/@fs/.env"] [unique_id "apE3eedJchobeYXfSU5R8AAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob
2026-08-28 06:45:46
(10 hours ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /@fs/../../.env (+9 more) | 2026-08-28 06:45 UTC
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 04:43:04
(12 hours ago)
(mod_security) mod_security (id:949110) triggered by 34.178.210.167 (167.210.178.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:949110) triggered by 34.178.210.167 (167.210.178.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 00:42:57.722720 2026] [security2:error] [pid 15411:tid 15411] [client 34.178.210.167:32834] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "www.experimentalscene.com"] [uri "/@fs/.env.development"] [unique_id "apER0efrfGJJjAVTlz1OHgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-08-28 04:10:17
(12 hours ago)
Excessive multi-domain requests
Brute-Force
๐ฌ๐ง
consul.to
2026-08-28 04:08:32
(12 hours ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 02:24:16
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.178.210.167 (167.210.178.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.178.210.167 (167.210.178.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 22:24:12.496840 2026] [security2:error] [pid 18528:tid 18528] [client 34.178.210.167:26212] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.naghmehfarahmand.com"] [uri "/@fs/root/.env"] [unique_id "apDxTBKM9ORQenOyz66m6AAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 01:05:06
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.178.210.167 (167.210.178.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.178.210.167 (167.210.178.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 21:04:58.976326 2026] [security2:error] [pid 29135:tid 29135] [client 34.178.210.167:29918] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.lubbockknights.com"] [uri "/@fs/app/.env"] [unique_id "apDeuh3ebc2USMdhMjcV4gAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
gamabe
2026-08-28 00:12:31
(16 hours ago)
Detected crowdsecurity/http-dos-swithcing-ua attack pattern. Reported by CrowdSec IDS.
Hacking
๐ซ๐ท
dynamix
2026-08-28 00:08:45
(16 hours ago)
Multiple WAF Violations
Web App Attack
๐ช๐ธ
alferez
2026-08-27 23:47:39
(17 hours ago)
Searching .(env|sql|zip|tar|rar) files
Hacking
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 23:23:20
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.178.210.167 (167.210.178.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.178.210.167 (167.210.178.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 19:23:14.695388 2026] [security2:error] [pid 6098:tid 6098] [client 34.178.210.167:27030] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mosherpit.com"] [uri "/@fs/root/.env"] [unique_id "apDG4iIegbxHiPmygchTAQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack