๐ฆ๐บ
sel
2026-10-08 13:12:57
(34 minutes ago)
Web scanner/attack: 3 requests.
2026/10/08 13:12:23 [error] 95019#95019: *45507 connect() failed (11 ...
show more
Web scanner/attack: 3 requests.
2026/10/08 13:12:23 [error] 95019#95019: *45507 connect() failed (111: Connection refused) while connecting to upstream, client: 34.62.68.97, server: msfs.forum, request: "GET / HTTP/1.1", upstream: "
2026/10/08 13:12:24 [error] 95019#95019: *45507 connect() failed (111: Connection refused) while connecting to upstream, client: 34.62.68.97, server: msfs.forum, request: "GET / HTTP/1.1", upstream: "
2026/10/08 13:12:27 [error] 95019#95019: *45507 connect() failed (111: Connection refused) while connecting to upstream, client: 34.62.68.97, server: msfs.forum, request: "GET / HTTP/1.1", upstream: "
show less
Web App Attack
Bad Web Bot
๐ฉ๐ช
LRob
2026-10-08 11:09:19
(2 hours ago)
Secret file probe | method: GET | path: /.env | ua: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleW ...
show more
Secret file probe | method: GET | path: /.env | ua: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36
show less
Hacking
Web App Attack
๐ฆ๐บ
paulshipley.com.au
2026-10-07 19:08:42
(18 hours ago)
[Thu Oct 08 06:08:41.077747 2026] [security2:error] [pid 409951] [client 34.62.68.97:20916] [client ...
show more
[Thu Oct 08 06:08:41.077747 2026] [security2:error] [pid 409951] [client 34.62.68.97:20916] [client 34.62.68.97] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/modsecurity/crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "support.paulshipley.com.au"] [uri "/.env"] [unique_id "asaYudPVIaXKWe5l_NR3uQAAAAg"]
...
show less
Web App Attack
Anonymous
2026-10-07 17:08:20
(20 hours ago)
T: f2b 404 5x
Web App Attack
๐ฆ๐บ
2000cn.com.au
2026-10-07 16:42:03
(21 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐ฉ๐ช
altenglaner
2026-10-07 16:40:17
(21 hours ago)
Web scanner probing for sensitive files (.env, .git, backups) or path traversal. Reported by fail2ba ...
show more
Web scanner probing for sensitive files (.env, .git, backups) or path traversal. Reported by fail2ban.
show less
Hacking
Web App Attack
๐ฌ๐ท
setupgr
2026-10-07 16:05:58
(21 hours ago)
(mod_security) mod_security (id:11000011) triggered by 34.62.68.97 (BE/Belgium/Brussels Capital/Brus ...
show more
(mod_security) mod_security (id:11000011) triggered by 34.62.68.97 (BE/Belgium/Brussels Capital/Brussels/-/[AS396982 Google LLC]): 1 in the last 86400 secs (CF_ENABLE); Ports: *; Direction: inout; Trigger: LF_MODSEC; Logs: [Wed Oct 07 19:05:56.393222 2026] [security2:error] [pid 1055004:tid 1055119] [client 34.62.68.97:25240] ModSecurity: Access denied with code 406 (phase 1). Matched phrase "googleusercontent.com" at REMOTE_HOST. [file "/etc/apache2/conf.d/modsec/modsec2.user.conf"] [line "141"] [id "11000011"] [msg "BLOCKED BAD DOMAIN: 97.68.62.34.bc.googleusercontent.com"] [severity "CRITICAL"] [hostname "setworldup.com"] [uri "/"] [unique_id "asZt43xw_0nyqM_49OscggAAAkA"]
show less
Port Scan
๐ซ๐ท
Kraften
2026-10-07 06:56:19
(1 day ago)
GET Web noscript attack
...
Web Spam
Web App Attack
๐ต๐ฑ
Budyn
2026-10-07 03:16:26
(1 day ago)
Budyn SOC Canary Trap: AWS Key Compromised! | Memo: AWS_Token_2 | Action: AWS API Call | Token: tu8j ...
show more
Budyn SOC Canary Trap: AWS Key Compromised! | Memo: AWS_Token_2 | Action: AWS API Call | Token: tu8jkpvo92f821qykacxbbvok | Client Tool: aws-sdk-go-v2/1.45.1 ua/2.1 os/linux lang/go#1.25.14 md/GOOS#linux md/GOARCH#amd64 api/sts#1.46.0 m/e
show less
Hacking
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Alt255
2026-10-06 06:42:48
(2 days ago)
[cb-15al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[cb-15al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 34.62.68.97 - - [06/Oct/2026:08:42:27 +0200] "GET /.env HTTP/2.0" 301 139 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 06:23:27
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.62.68.97 (97.68.62.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.62.68.97 (97.68.62.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 02:23:19.135172 2026] [security2:error] [pid 6941:tid 6941] [client 34.62.68.97:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.sahinozalit.com"] [uri "/.env"] [unique_id "asST1-4uMa44u7svoT4ryQAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
blinx
2026-10-06 03:36:52
(2 days ago)
Suspicious activity detected by Modsecurity
Web Spam
Port Scan
Hacking
Bad Web Bot
Web App Attack
๐ต๐ฑ
Budyn
2026-10-05 23:01:32
(2 days ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scan ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scanner. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: elastic.definitelynotahoneypot.online | URI: /.git/HEAD | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36 | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
Anonymous
2026-10-05 18:11:46
(2 days ago)
(mod_security) mod_security triggered on hostname [redacted])
SQL Injection
๐ณ๐ฑ
e.fierstra
2026-10-05 16:49:02
(2 days ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack