ππΊ
miszterx.hu
2026-09-02 05:06:44
(3 hours ago)
XORP (haproxy): 3x HTTP 404/403/500 or handshake failure in 24h. Automated report from log_check_ipt ...
show more
XORP (haproxy): 3x HTTP 404/403/500 or handshake failure in 24h. Automated report from log_check_iptables_generator.sh (xorp.hu)
show less
Web App Attack
π«π·
masterguru
2026-09-01 10:17:58
(22 hours ago)
Restricted File Access Attempt. Matched phrase ".env" at REQUEST_FILENAME. (930130-197)
Hacking
Web App Attack
π©πͺ
MBombeck
2026-09-01 09:54:48
(22 hours ago)
Fail2Ban/traefik-botsearch on apps-01: banned after 5 failures
Web App Attack
πΏπ¦
conure.sh
2026-09-01 09:35:44
(23 hours ago)
csagent: score 20.5: secrets grab x2, 404 noise floor x2; 1 domain(s) in 0s
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-01 09:19:07
(23 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.19.226.160 (160.226.19.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.19.226.160 (160.226.19.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 05:19:00.386608 2026] [security2:error] [pid 30925:tid 30925] [client 34.19.226.160:48002] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "stepiz62.com"] [uri "/.env.old"] [unique_id "apaYhO0rijIiLt_4Q-FslAAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-01 08:47:38
(23 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.19.226.160 (160.226.19.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.19.226.160 (160.226.19.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 04:47:34.435943 2026] [security2:error] [pid 24082:tid 24082] [client 34.19.226.160:54274] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sentinel-sg.com.springmeadowventures.com"] [uri "/.env.example"] [unique_id "apaRJgUTQXmIe_y-UtPkMQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π¬π§
consul.to
2026-09-01 07:10:48
(1 day ago)
Web attack/malicious scanning detected
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-01 07:04:25
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.19.226.160 (160.226.19.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.19.226.160 (160.226.19.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 03:04:20.900566 2026] [security2:error] [pid 23464:tid 23464] [client 34.19.226.160:55586] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "faeriespringsfarm.com"] [uri "/.env.dev"] [unique_id "apZ49OIkxSgVcpNH4qjf0wAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π«π·
Stara
2026-09-01 06:10:42
(1 day ago)
ModSecurity detected web attack - .env/config probing or SQLi/Code injection (Rule 949110)
Brute-Force
SSH
Web App Attack
π¬π§
thetomtaylor.co.uk
2026-09-01 06:08:01
(1 day ago)
Fail2Ban - [WEB]Custom exploit pattern detected on customexploits ... [ice01,ice02,wa01,wa02]
Hacking
Brute-Force
Bad Web Bot
Web App Attack
ππΊ
miszterx.hu
2026-09-01 05:39:12
(1 day ago)
XORP (haproxy): 19x HTTP 404/403/500 or handshake failure in 24h. Automated report from log_check_ip ...
show more
XORP (haproxy): 19x HTTP 404/403/500 or handshake failure in 24h. Automated report from log_check_iptables_generator.sh (xorp.hu)
show less
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-01 05:33:09
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.19.226.160 (160.226.19.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.19.226.160 (160.226.19.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 01:33:01.007702 2026] [security2:error] [pid 11039:tid 11039] [client 34.19.226.160:46624] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "thorndikestudio.com"] [uri "/.env"] [unique_id "apZjjUkC2CND6pDF1FG3EwAAADA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-01 05:09:55
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.19.226.160 (160.226.19.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.19.226.160 (160.226.19.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 01:09:50.052730 2026] [security2:error] [pid 9718:tid 9718] [client 34.19.226.160:36754] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "editor.flyingdodostudio.com"] [uri "/.env"] [unique_id "apZeHgY53vtFrGOg0gk2VQAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-01 04:27:15
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 34.19.226.160 (160.226.19.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.19.226.160 (160.226.19.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 00:27:07.713871 2026] [security2:error] [pid 13583:tid 13583] [client 34.19.226.160:36164] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||bitcoincasting.usaangelinvestors.com|F|2"] [data ".env.backup"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "bitcoincasting.usaangelinvestors.com"] [uri "/.env.backup"] [unique_id "apZUG_DUdkCDZfUIbO6C-AAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π¬π§
Apache
2026-09-01 04:26:45
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.19.226.160 (CA/Canada/160.226.19.34.bc.googl ...
show more
(mod_security) mod_security (id:210492) triggered by 34.19.226.160 (CA/Canada/160.226.19.34.bc.googleusercontent.com): 5 in the last 300 secs (CF_ENABLE)
show less
Brute-Force
Web App Attack