๐ฎ๐ณ
evicky2002
2026-08-31 00:01:03
(1 day ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
๐ฟ๐ฆ
conure.sh
2026-08-29 12:01:43
(2 days ago)
csagent: score 20.0: secrets grab x2; 1 domain(s) in 0s
Web App Attack
๐ฌ๐ง
consul.to
2026-08-29 03:01:15
(2 days ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-29 02:45:53
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.181.163.67 (67.163.181.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.181.163.67 (67.163.181.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 22:45:49.248152 2026] [security2:error] [pid 28727:tid 28727] [client 34.181.163.67:56886] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.blog.taxgroupsd.com"] [uri "/.env.old"] [unique_id "apJH3V47rMTbGJXd4aenbgAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
voormedia
2026-08-29 02:41:49
(3 days ago)
Accessed trap at '/.env'
Web App Attack
๐ซ๐ฎ
paissangroup
2026-08-29 02:28:17
(3 days ago)
Multiple WAF Violations
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-08-29 02:10:26
(3 days ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-29 02:07:14
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.181.163.67 (67.163.181.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.181.163.67 (67.163.181.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 22:07:09.557380 2026] [security2:error] [pid 30190:tid 30190] [client 34.181.163.67:35650] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.usashooters.gemexpressions.com"] [uri "/.env.prod"] [unique_id "apI-zUgSmPksyf_qiTNe9gAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
MatCat
2026-08-29 01:05:10
(3 days ago)
Banned by fail2ban: apache-webprobe
Port Scan
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-08-29 00:42:29
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.181.163.67 (67.163.181.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.181.163.67 (67.163.181.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 20:42:24.887606 2026] [security2:error] [pid 20501:tid 20501] [client 34.181.163.67:38424] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "monmouthcountydanceclasses.com.leonardodecaprio.com"] [uri "/.env.old"] [unique_id "apIq8NRK0M_85i9FnjTTzQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฟ๐ฆ
conure.sh
2026-08-29 00:24:49
(3 days ago)
csagent: score 20.5: 404 noise floor x2, wp-config backup grab x1, secrets grab x1; 1 domain(s) in 0 ...
show more
csagent: score 20.5: 404 noise floor x2, wp-config backup grab x1, secrets grab x1; 1 domain(s) in 0s
show less
Web App Attack
๐บ๐ธ
mnsf
2026-08-29 00:08:58
(3 days ago)
Abuse Detected (9)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 23:49:39
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.181.163.67 (67.163.181.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.181.163.67 (67.163.181.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 19:49:35.288049 2026] [security2:error] [pid 3363342:tid 3363352] [client 34.181.163.67:56626] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.jpdesign.us.jean-paullederer.com"] [uri "/.env.dev"] [unique_id "apIej2-f09rsyFsPsuSmYwAAAUA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 23:07:52
(3 days ago)
(mod_security) mod_security (id:949110) triggered by 34.181.163.67 (67.163.181.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:949110) triggered by 34.181.163.67 (67.163.181.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 19:07:46.857950 2026] [security2:error] [pid 4319:tid 4319] [client 34.181.163.67:44382] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "letahaabooking.com"] [uri "/.env.backup"] [unique_id "apIUwmGp4QBxp9aqeg2klwAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
Celtic
2026-08-28 22:55:22
(3 days ago)
Blocked by Fail2Ban with Jail (plesk-modsecurity)
Brute-Force
SSH