๐จ๐ฟ
ddw
2026-08-31 07:44:36
(10 hours ago)
ModSecurity detection - Rules: 930130(Restricted File Access Attempt)
Web App Attack
๐ฉ๐ช
ut-addicted.com
2026-08-31 04:52:20
(12 hours ago)
\[Mon Aug 31 06:52:18.580634 2026\] \[:error\] \[pid 15489:tid 140352388241152\] \[client 34.180.80. ...
show more
\[Mon Aug 31 06:52:18.580634 2026\] \[:error\] \[pid 15489:tid 140352388241152\] \[client 34.180.80.154:60140\] \[client 34.180.80.154\] ModSecurity: Access denied with code 403 \(phase 2\). Operator GE matched 5 at TX:anomaly_score. \[file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-949-BLOCKING-EVALUATION.conf"\] \[line "57"\] \[id "949110"\] \[msg "Inbound Anomaly Score Exceeded \(Total Score: 18\)"\] \[severity "CRITICAL"\] \[tag "application-multi"\] \[tag "language-multi"\] \[tag "platform-multi"\] \[tag "attack-generic"\] \[hostname "78.46.187.162"\] \[uri "/static../.env"\] \[unique_id "apUIglsJy5jS1ikHH@pQVwAAANc"\]
show less
Brute-Force
Web App Attack
๐ต๐ฑ
webadmin
2026-08-31 04:12:36
(13 hours ago)
2026-08-31T06:12:34.996602+02:00 tytan mobile-sai-api[4129]: [error] client: 34.180.80.154 server: 2 ...
show more
2026-08-31T06:12:34.996602+02:00 tytan mobile-sai-api[4129]: [error] client: 34.180.80.154 server: 213.25.105.152, request: "GET", url: http://213.25.105.152/__aws_leak_probe_a5c96290__ [404]: Not Found
2026-08-31T06:12:35.806762+02:00 tytan mobile-sai-api[4129]: [error] client: 34.180.80.154 server: 213.25.105.152, request: "GET", url: http://213.25.105.152/static../.env [404]: Not Found
2026-08-31T06:12:35.806762+02:00 tytan mobile-sai-api[4129]: [error] client: 34.180.80.154 server: 213.25.105.152, request: "GET", url: http://213.25.105.152/.env.local [404]: Not Found
2026-08-31T06:12:35.806762+02:00 tytan mobile-sai-api[4129]: [error] client: 34.180.80.154 server: 213.25.105.152, request: "GET", url: http://213.25.105.152/files../etc/passwd [404]: Not Found
show less
Web App Attack
๐ง๐พ
lns.bz
2026-08-31 02:30:22
(15 hours ago)
.env scanning [BY]
Web App Attack
๐ฉ๐ช
Viveronese
2026-08-31 01:46:18
(16 hours ago)
HTTP vulnerability scanning
Web App Attack
๐ณ๐ฟ
Antinson
2026-08-30 12:39:08
(1 day ago)
Scraping with a high error ratio and request rate
Bad Web Bot
๐ง๐พ
lns.bz
2026-08-30 03:43:51
(1 day ago)
Too many 404 requests [BY]
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-30 01:35:52
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.180.80.154 (154.80.180.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.180.80.154 (154.80.180.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 21:35:43.513123 2026] [security2:error] [pid 5235:tid 5235] [client 34.180.80.154:57734] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.7"] [uri "/static../.env"] [unique_id "apOI71jIOZmFdgT31ZicMQAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-30 00:34:08
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.180.80.154 (154.80.180.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.180.80.154 (154.80.180.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 20:34:04.087369 2026] [security2:error] [pid 2809:tid 2809] [client 34.180.80.154:3866] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.39"] [uri "/static../.env"] [unique_id "apN6fNveGc2Zfd1Q41GF1gAAACo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
Axel
2026-08-30 00:32:09
(1 day ago)
Blocked by UFW on LAXHH [443/tcp] | SPT: 59706 | TTL: 55 | LEN: 60 | TOS: 0x00 โข Reported by: github ...
show more
Blocked by UFW on LAXHH [443/tcp] | SPT: 59706 | TTL: 55 | LEN: 60 | TOS: 0x00 โข Reported by: github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
๐ณ๐ฑ
knock
2026-08-29 19:28:49
(1 day ago)
Knock-Knock honeypot brute-force: HTTP (398 total hits)
Web App Attack
๐ซ๐ท
omartin
2026-08-29 13:07:13
(2 days ago)
Critical Vulnerability Scan detected
Hacking
Brute-Force
Exploited Host
Web App Attack
๐ช๐ธ
librebit
2026-08-29 12:15:12
(2 days ago)
Bad guys doing bad things, bad crawling
Bad Web Bot
๐ณ๐ฟ
Antinson
2026-08-29 10:22:11
(2 days ago)
Scraping with a high error ratio and request rate
Bad Web Bot
Anonymous
2026-08-29 07:24:45
(2 days ago)
denied traffic to a honeypot network. destination port 80.
Port Scan
Hacking