๐ณ๐ฑ
Savvii
2026-09-13 01:13:01
(5 days ago)
20 attempts against mh-misbehave-ban on bud
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
โจ
2026-09-13 00:36:20
(5 days ago)
Rule : WEB
2026-09-12 21:24:35 34.90.160.42 59296 10.10.0.16 80 - - - - 400 - Verb -
Port Scan
Anonymous
2026-09-12 23:54:37
(5 days ago)
Aggressive web scan
Web App Attack
๐ฏ๐ต
VXG-NET
2026-09-12 19:10:11
(5 days ago)
port=80, indicator_type=info-leak
Hacking
Anonymous
2026-09-12 13:44:14
(5 days ago)
Malicious IP Addresses.
Hacking
๐ฌ๐ง
bensmithurst
2026-09-12 10:49:00
(6 days ago)
34.90.160.42 - - [12/Sep/2026:10:48:34 +0000] "GET /assets../../../etc/passwd HTTP/1.1" 400 150 "-" ...
show more
34.90.160.42 - - [12/Sep/2026:10:48:34 +0000] "GET /assets../../../etc/passwd HTTP/1.1" 400 150 "-" "-"
34.90.160.42 - - [12/Sep/2026:10:48:38 +0000] "GET /assets../../../.env HTTP/1.1" 400 150 "-" "-"
34.90.160.42 - - [12/Sep/2026:10:48:43 +0000] "GET ////../.env HTTP/1.1" 400 150 "-" "-"
34.90.160.42 - - [12/Sep/2026:10:48:43 +0000] "GET /%2e%2e/%2e%2e/.env HTTP/1.1" 400 150 "-" "-"
34.90.160.42 - - [12/Sep/2026:10:48:59 +0000] "GET /assets../../../etc/passwd HTTP/1.1" 400 150 "-" "-"
... [host=LAN***]
show less
Web App Attack
๐ง๐พ
lns.bz
2026-09-12 05:57:55
(6 days ago)
.env scanning [BY]
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-12 05:09:14
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 34.90.160.42 (42.160.90.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.90.160.42 (42.160.90.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 01:09:05.143090 2026] [security2:error] [pid 3410:tid 3410] [client 34.90.160.42:62102] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.19"] [uri "/static../.env"] [unique_id "aqTecTIqRfRuoKmH7LHmUgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
fabrice
2026-09-11 23:50:25
(6 days ago)
Repeated Trusted domain errors : 34.90.160.42 - - [12/Sep/2026:01:50:25 +0200] "GET /wp-content/debu ...
show more
Repeated Trusted domain errors : 34.90.160.42 - - [12/Sep/2026:01:50:25 +0200] "GET /wp-content/debug.log HTTP/1.1" 403 1958 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko; compatible; GPTBot/1.4; +https://openai.com/gptbot) Chrome/130.0.2629.202 Safari/537.36 Edg/130.0.2629.202"
...
show less
Web App Attack
Anonymous
2026-09-11 20:00:04
(6 days ago)
| Common web attack.
Web App Attack
Hacking
SQL Injection
๐ณ๐ฑ
Savvii
2026-09-11 19:53:55
(6 days ago)
10 attempts against mh_ha-misc-ban on automation
Brute-Force
Web App Attack
๐ฉ๐ช
Lennart Kramer
2026-09-11 19:02:41
(6 days ago)
Restricted File Access Attempt | Matched phrase "*env*" at /@fs/proc/self/environ | Mozilla/5.0 Appl ...
show more
Restricted File Access Attempt | Matched phrase "*env*" at /@fs/proc/self/environ | Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; GPTBot/1.2; +https://openai.com/gptbot)
show less
Hacking
Web App Attack
๐บ๐ธ
kosada.com
2026-09-11 17:20:21
(6 days ago)
Repeated requests for suspicious nonexistent URLs, for example: /.env.local (HTTP/1.1 port 80, bogus ...
show more
Repeated requests for suspicious nonexistent URLs, for example: /.env.local (HTTP/1.1 port 80, bogus vhost, user agent: "Mozilla/5.0 (compatible; GPTBot/1.2; +https://openai.com/gptbot)")
show less
Web App Attack
Anonymous
2026-09-11 16:39:33
(6 days ago)
denied traffic to a honeypot network. destination port 8443.
Port Scan
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-11 16:38:56
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 34.90.160.42 (42.160.90.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.90.160.42 (42.160.90.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 12:38:49.450917 2026] [security2:error] [pid 25822:tid 25822] [client 34.90.160.42:63474] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.115"] [uri "/static../.env"] [unique_id "aqQumaIL1QvJAnsDvY0KmwAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack