๐บ๐ธ
mnsf
2026-09-01 20:05:11
(12 hours ago)
Scanning/Probing (20)
Brute-Force
Web App Attack
๐ซ๐ท
masterguru
2026-09-01 09:58:57
(22 hours ago)
URL file extension is restricted by policy. String match within ".ani/ .asa/ .asax/ .ascx/ .backup/ ...
show more
URL file extension is restricted by policy. String match within ".ani/ .asa/ .asax/ .ascx/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .compositefont/ .config/ .conf/ .crt/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dist/ .dll/ .dos/ .dpkg-dist/ .drv/ .gadget/ .hta/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .inf/ .ini/ .jse/ .key/ .licx/ .lnk/ .log/ .mdb/ .msc/ .ocx/ .old/ .pass/ .pdb/ .pfx/ .pif/ .pem/ .pol/ .prf/ .printer/ .pwd/ .rdb/ .rdp/ .reg/ .resources/ .resx/ .scr/ .sct/ .shs/ .sql/ .swp/ .sys/ .tlb/ .tmp/ .url/ .vb/ .vbe/ .vbs/ .vbproj/ .vsdisco/ .vxd/ .webinfo/ .ws/ .wsc/ .wsf/ .wsh/ .xsd/ .xsx/" at TX:extension. (920440-195)
show less
Hacking
๐จ๐ฆ
Anytech
2026-09-01 09:36:18
(23 hours ago)
Blocked by ConnMonitor
Web App Attack
๐ซ๐ท
masterguru
2026-09-01 09:29:07
(23 hours ago)
Restricted File Access Attempt. Matched phrase ".env" at REQUEST_FILENAME. (930130-196)
Hacking
Web App Attack
๐ฎ๐ฉ
Burayot
2026-09-01 08:34:47
(1 day ago)
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 34.72.212.121 (US/United States/121 ...
show more
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 34.72.212.121 (US/United States/121.212.72.34.bc.googleusercontent.com): 1 in the last 3600 secs
show less
Web App Attack
Anonymous
2026-09-01 08:18:36
(1 day ago)
Web application attack detected.
Web App Attack
Anonymous
2026-09-01 08:00:42
(1 day ago)
IncogNET WAF local CrowdSec decision. Scenario=crowdsecurity/http-sensitive-files; Action=ban; Event ...
show more
IncogNET WAF local CrowdSec decision. Scenario=crowdsecurity/http-sensitive-files; Action=ban; Events=5; Hosts=gate.isp.llc; Paths=/.env,/.env.bak,/.env.dev,/.env.local,/.env.prod; Country=US; ASN=396982 GOOGLE-CLOUD-PLATFORM
show less
Hacking
Web App Attack
๐ธ๐ช
vaia.cloud
2026-09-01 07:40:03
(1 day ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 06:39:32
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.72.212.121 (121.212.72.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.72.212.121 (121.212.72.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 02:39:24.061468 2026] [security2:error] [pid 30460:tid 30460] [client 34.72.212.121:52578] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "tech-support.biz"] [uri "/.env"] [unique_id "apZzHCzo-X2eakGuSx8NhAAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 05:12:40
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.72.212.121 (121.212.72.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.72.212.121 (121.212.72.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 01:12:32.688416 2026] [security2:error] [pid 18156:tid 18156] [client 34.72.212.121:58370] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "elimer.com.ve"] [uri "/.env.prod"] [unique_id "apZewMRuyI1MxdAFX8bugQAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-01 04:04:12
(1 day ago)
Bot / seems abusive / Apache connections: 25
DDoS Attack
Web Spam
Bad Web Bot
Web App Attack
๐ฉ๐ช
Ano_Nym
2026-09-01 03:38:47
(1 day ago)
CrowdSec IDS alert on VPS 85.215.198.123 (DE). Scenario: crowdsecurity/http-sensitive-files
Web App Attack
๐บ๐ธ
CBJ
2026-09-01 03:11:24
(1 day ago)
fail2ban: apache-filepath-recon
...
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 03:01:43
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.72.212.121 (121.212.72.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.72.212.121 (121.212.72.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 23:01:35.468355 2026] [security2:error] [pid 21004:tid 21004] [client 34.72.212.121:44330] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kentweakley.com"] [uri "/.env.save"] [unique_id "apZAD9Tz3hid8VZxBh2DCgAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FD-IX
2026-09-01 02:48:59
(1 day ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack