๐ณ๐ฑ
oisecnet
2026-10-02 21:02:08
(1 day ago)
Automated report: Unauthorized vulnerability scanning detected on 2026-10-02. 690 requests from this ...
show more
Automated report: Unauthorized vulnerability scanning detected on 2026-10-02. 690 requests from this IP.
show less
Port Scan
Hacking
Web App Attack
๐ณ๐ฑ
Alt255
2026-10-02 15:02:58
(1 day ago)
[ti-01al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-01al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 34.26.174.83 - - [02/Oct/2026:17:02:47 +0200] "GET /static../.env HTTP/2.0" 404 1855 "-" "Mozilla/5.0 (compatible; Google-Extended; +http://www.google.com/bot.html)"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 14:55:15
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.26.174.83 (83.174.26.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.26.174.83 (83.174.26.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 10:55:10.965371 2026] [security2:error] [pid 16073:tid 16073] [client 34.26.174.83:58024] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.scothorn.net"] [uri "/images../.env"] [unique_id "ar_FzrvvbNJdeQeYrtHmFAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 14:27:35
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.26.174.83 (83.174.26.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.26.174.83 (83.174.26.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 10:27:28.282051 2026] [security2:error] [pid 18969:tid 18969] [client 34.26.174.83:43964] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.beckerbrokerage.net"] [uri "/images../.env"] [unique_id "ar-_UB4sdAVOUrRqoITBJQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 14:08:03
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.26.174.83 (83.174.26.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.26.174.83 (83.174.26.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 10:07:57.788268 2026] [security2:error] [pid 19166:tid 19166] [client 34.26.174.83:37328] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "handankoc.net"] [uri "/.env.js"] [unique_id "ar-6vVPAt_6cleF-K6nQMgAAACk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 13:50:16
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.26.174.83 (83.174.26.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.26.174.83 (83.174.26.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 09:50:04.944772 2026] [security2:error] [pid 4899:tid 4899] [client 34.26.174.83:40298] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "fonzies.net"] [uri "/media../.env"] [unique_id "ar-2jG2VJFAbL23QOLJNxwAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
pscriptos
2026-10-02 13:15:52
(1 day ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
๐ฉ๐ช
mzaiser12
2026-10-02 13:05:47
(1 day ago)
Web application probing: 140 requests to typical attack paths (/api/templates/preview, /api/designer ...
show more
Web application probing: 140 requests to typical attack paths (/api/templates/preview, /api/designer/v1/file-content, /api/datasources, /actuator/gateway/routes) within 5 min. Reported automatically by a SIEM; contact via abuse mailbox of the reporting network.
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
mzaiser12
2026-10-02 13:04:26
(1 day ago)
Web application probing: 123 requests to typical attack paths (/.git/config, /.github/.env, /assets/ ...
show more
Web application probing: 123 requests to typical attack paths (/.git/config, /.github/.env, /assets/.env, /.aws/config) within 5 min. Reported automatically by a SIEM; contact via abuse mailbox of the reporting network.
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
valornode
2026-10-02 12:55:48
(1 day ago)
Detected by CrowdSec on www.iambrayden.net-47d88224: CrowdSec: crowdsecurity/grafana-cve-2021-43798 ...
show more
Detected by CrowdSec on www.iambrayden.net-47d88224: CrowdSec: crowdsecurity/grafana-cve-2021-43798 | ASN: 396982 (GOOGLE-CLOUD-PLATFORM) | Country: US | Range: 34.16.0.0/12
show less
Brute-Force
SSH
๐ฉ๐ช
LRob
2026-10-02 12:29:46
(1 day ago)
Vulnerability scanning | method: GET, POST | path: /webpack-stats.json, /dist/manifest.json, /model/ ...
show more
Vulnerability scanning | method: GET, POST | path: /webpack-stats.json, /dist/manifest.json, /model/info (+15 more) | ua: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36, Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; GPTBot/1.4; +https://openai.com/gptbot, Mozilla/5.0 (compatible; Qwenbot/1.0; +https://qwen.alibaba.com/) (+2 more)
show less
Port Scan
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 12:24:05
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.26.174.83 (83.174.26.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.26.174.83 (83.174.26.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 08:23:56.609129 2026] [security2:error] [pid 30176:tid 30176] [client 34.26.174.83:40220] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.techsuite7.net"] [uri "/uploads../.env"] [unique_id "ar-iXK7eU_se4mlOdUryfQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
nyt
2026-10-02 12:15:21
(1 day ago)
GraphQL Probe
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 11:42:32
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.26.174.83 (83.174.26.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.26.174.83 (83.174.26.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 07:42:28.741615 2026] [security2:error] [pid 17792:tid 17792] [client 34.26.174.83:37132] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "coast22.net"] [uri "/media../.env"] [unique_id "ar-YpLbcUdItZD-5gaFA6QAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 10:30:50
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.26.174.83 (83.174.26.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.26.174.83 (83.174.26.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 06:30:45.730926 2026] [security2:error] [pid 10082:tid 10082] [client 34.26.174.83:57216] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "reneehill.net"] [uri "/.env.js"] [unique_id "ar-H1WuCZFbhNhsXLChisgAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack