๐ณ๐ฑ
homeshowdomain.nl
2026-06-14 22:03:59
(5 days ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-06-13.
show less
Web App Attack
SSH
Hacking
๐บ๐ธ
TPI-Abuse
2026-06-13 16:18:40
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 34.84.172.116 (116.172.84.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.84.172.116 (116.172.84.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 13 12:18:34.430697 2026] [security2:error] [pid 19918:tid 19918] [client 34.84.172.116:58026] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jpastorphotographics.com"] [uri "/.env.copy"] [unique_id "ai2C2hMANEUypVqClB9ulgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-06-13 15:33:31
(6 days ago)
Excessive multi-domain requests
Brute-Force
๐ง๐ช
Saec
2026-06-13 14:15:06
(6 days ago)
Jarvis auto-ban: CF top attacker on saec.ovh (151 hits, JP)
Port Scan
Web App Attack
Anonymous
2026-06-13 13:28:22
(6 days ago)
Bot / seems abusive / Apache connections: 104
DDoS Attack
Web Spam
Bad Web Bot
Web App Attack
Anonymous
2026-06-13 13:07:37
(6 days ago)
[server.tmg.gr] httpd-suspicious-path: sites=dunantcongress2022.gr; logs=/var/log/httpd/domains/duna ...
show more
[server.tmg.gr] httpd-suspicious-path: sites=dunantcongress2022.gr; logs=/var/log/httpd/domains/dunantcongress2022.gr.log; samples=/backend/.env.backup | /frontend/.env.backup | /frontend/.env.staging
show less
Hacking
Web App Attack
๐ฌ๐ง
consul.to
2026-06-13 12:02:22
(6 days ago)
Web attack/malicious scanning detected
Web App Attack
Anonymous
2026-06-13 10:28:47
(6 days ago)
Multiple web server 400 error codes from same source ip
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-13 09:27:53
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 34.84.172.116 (116.172.84.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.84.172.116 (116.172.84.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 13 05:27:45.556210 2026] [security2:error] [pid 4417:tid 4417] [client 34.84.172.116:42296] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jafgcreates.com"] [uri "/.env.backup"] [unique_id "ai0ikTknH3uirRHFXuAb5wAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
rubixstudios
2026-06-13 08:40:03
(6 days ago)
Excessive HTTP requests consistent with automated attack behaviour detected by Imunify360
DDoS Attack
Brute-Force
Web App Attack
๐ซ๐ท
dynamix
2026-06-13 07:26:13
(6 days ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
mnsf
2026-06-13 07:07:01
(6 days ago)
Scanning/Probing (98)
Request Overload (103)
Brute-Force
Web App Attack
๐ฉ๐ช
updown.io
2026-06-13 06:26:03
(6 days ago)
{"level":"info","ts":1781331961.6287787,"logger":"http.log.access.log1","msg":"handled request","req ...
show more
{"level":"info","ts":1781331961.6287787,"logger":"http.log.access.log1","msg":"handled request","request":{"remote_ip":"34.84.172.116","remote_port":"47126","client_ip":"34.84.172.116","proto":"HTTP/1.1","method":"GET","host":"hgfeupdate.update.vutsrqpormlkjihgfedcbwwwc7402a95-6fc9-4756-b4e6-fa6c7eeb29c6.random.159.89.98.98.nip.io","uri":"/.env.test","headers":{"User-Agent":["Mozilla/5.0 (Android; Mobile; rv:35.0) Gecko/35.0 Firefox/35.0"],"Accept-Charset":["utf-8"],"Accept-Encoding":["gzip"],"Connection":["close"]}},"bytes_read":0,"user_id":"","duration":0.000107936,"size":0,"status":308,"resp_headers":{"Server":["Caddy"],"Connection":["close"],"Location":["https://hgfeupdate.update.vutsrqpormlkjihgfedcbwwwc7402a95-6fc9-4756-b4e6-fa6c7eeb29c6.random.159.89.98.98.nip.io/.env.test"],"Content-Type":[]}}
{"level":"info","ts":1781331961.6333184,"logger":"http.log.access.log1","msg":"handled request","request":{"remote_ip":"34.84.172.116","remote_port":"47112","client_ip":"34.84.172.116","p
...
show less
DDoS Attack
Web App Attack
๐ซ๐ท
Octopuce
2026-06-13 06:21:20
(6 days ago)
Aggressive web search of vulnerable pages: /frontend/.env.local /frontend/.env /src/.env.local /serv ...
show more
Aggressive web search of vulnerable pages: /frontend/.env.local /frontend/.env /src/.env.local /server/.env /server/.env.local ...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-13 05:22:47
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 34.84.172.116 (116.172.84.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.84.172.116 (116.172.84.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 13 01:22:41.967684 2026] [security2:error] [pid 25238:tid 25238] [client 34.84.172.116:39796] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "whoownsmyhome.com"] [uri "/.env.old"] [unique_id "aizpIWPk0-mXjW_5pBJGIwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack