๐ณ๐ฑ
oisecnet
2026-08-01 21:06:49
(18 minutes ago)
Automated report: Unauthorized vulnerability scanning detected on 2026-08-01. 205 requests from this ...
show more
Automated report: Unauthorized vulnerability scanning detected on 2026-08-01. 205 requests from this IP.
show less
Brute-Force
Web App Attack
SSH
๐บ๐ธ
TPI-Abuse
2026-08-01 17:03:28
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.82.194.166 (166.194.82.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.82.194.166 (166.194.82.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 13:03:24.039220 2026] [security2:error] [pid 1555579:tid 1555579] [client 34.82.194.166:45924] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "realclean.net"] [uri "/.env.example"] [unique_id "am4m3F4tMRCjKIq4CUhX6QAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob
2026-08-01 16:57:37
(4 hours ago)
CrowdSec: crowdsecurity/http-sensitive-files | req: /.env.backup | 5 distinct paths | UA: crusader-w ...
show more
CrowdSec: crowdsecurity/http-sensitive-files | req: /.env.backup | 5 distinct paths | UA: crusader-worker/1.0
show less
Hacking
๐ณ๐ฑ
debestelapp
2026-08-01 16:46:13
(4 hours ago)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-01 15:36:49
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.82.194.166 (166.194.82.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.82.194.166 (166.194.82.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 11:36:42.249121 2026] [security2:error] [pid 38135:tid 38135] [client 34.82.194.166:53488] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "wheelworks.my"] [uri "/.env.old"] [unique_id "am4SioIh0EHyGWN3GXab-gAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ธ๐ช
vaia.cloud
2026-08-01 15:30:04
(5 hours ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
๐ฌ๐ง
Oakley
2026-08-01 15:26:59
(5 hours ago)
(confirmed_bot_sig) Confirmed bot
Hacking
๐บ๐ธ
TPI-Abuse
2026-08-01 15:16:39
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.82.194.166 (166.194.82.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.82.194.166 (166.194.82.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 11:16:33.648662 2026] [security2:error] [pid 906986:tid 906986] [client 34.82.194.166:39982] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kleens-uk.com"] [uri "/.env.production"] [unique_id "am4N0SJUo_Tb-sB6nDoF3AAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-01 14:59:41
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.82.194.166 (166.194.82.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.82.194.166 (166.194.82.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 10:59:34.244341 2026] [security2:error] [pid 2301039:tid 2301039] [client 34.82.194.166:36414] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.southshorestreetrods.com.nashes.net"] [uri "/.env.production"] [unique_id "am4J1puGrOF196v2LKgedwAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
paissangroup
2026-08-01 14:53:14
(6 hours ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
cwytech
2026-08-01 14:29:36
(6 hours ago)
Fleet-wide ban from the Ghostfleet ๐ป. Triggered by scenario: cwy/tactical-rmm-lockdown-high.
Hacking
๐จ๐ญ
leo1305
2026-08-01 14:12:09
(7 hours ago)
CrowdSec detection | scenario: http-sensitive-files
Web App Attack
Exploited Host
๐ณ๐ฑ
e.fierstra
2026-08-01 14:08:23
(7 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐ฌ๐ง
consul.to
2026-08-01 13:14:43
(8 hours ago)
Web attack/malicious scanning detected
Web App Attack
๐ท๐บ
DZBOT
2026-08-01 12:25:00
(9 hours ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack