๐บ๐ธ
mnsf
2026-08-26 12:05:14
(1 week ago)
Scanning/Probing (12)
Brute-Force
Web App Attack
Anonymous
2026-08-26 11:55:02
(1 week ago)
suspicious request in access.log
Web App Attack
๐ณ๐ฟ
Tripwire
2026-08-26 10:23:01
(1 week ago)
Scanning for exploits - /media../etc/passwd
Web App Attack
๐ฉ๐ช
Vegascosmetics
2026-08-26 10:18:23
(1 week ago)
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after sensitive config/credentials exposure ...
show more
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after sensitive config/credentials exposure probe. Evidence: AttackPattern: /\.env (Match: /.env)
show less
Hacking
Brute-Force
Web App Attack
Anonymous
2026-08-26 10:09:30
(1 week ago)
Aggressive web scan
Web App Attack
๐ณ๐ฑ
Savvii
2026-08-26 09:43:15
(1 week ago)
20 attempts against mh-misbehave-ban on redirect
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Octopuce
2026-08-26 09:04:29
(1 week ago)
Aggressive web search of vulnerable pages: /.env.local /media../.env /.env /app/.env /src/.env ...
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-26 08:59:35
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 35.187.65.167 (167.65.187.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.187.65.167 (167.65.187.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 04:59:29.153219 2026] [security2:error] [pid 9766:tid 9766] [client 35.187.65.167:21594] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "richsilver.com"] [uri "/static../.env"] [unique_id "ao6q8a_EpTUFPRqAuNEQ6wAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob
2026-08-26 08:58:28
(1 week ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /static../.env (+14 more) | 2026-08-26 08:58 UTC
show less
Hacking
Web App Attack
๐ฉ๐ช
schuerholz
2026-08-26 08:37:00
(1 week ago)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-26 08:26:30
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 35.187.65.167 (167.65.187.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.187.65.167 (167.65.187.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 04:26:25.520236 2026] [security2:error] [pid 26703:tid 26703] [client 35.187.65.167:27994] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jeffhinkley.com"] [uri "/static../.env"] [unique_id "ao6jMep8oQZTcJ6ut36Y9AAAADE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Baking333
2026-08-26 07:17:33
(1 week ago)
[redacted] 35.187.65.167 - - [26/Aug/2026:08:17:31 +0100] "GET /.[redacted] HTTP/1.1" 302 6773 0/136 ...
show more
[redacted] 35.187.65.167 - - [26/Aug/2026:08:17:31 +0100] "GET /.[redacted] HTTP/1.1" 302 6773 0/136314 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 14_5) AppleWebKit/537.36 (KHTML, like Gecko; compatible; Amazonbot/0.1; +https://[redacted]/support/amazonbot) Chrome/126.0.6367.12 Safari/537.36 Edg/126.0.6367.12" [redacted] 35.187.65.167 - - [26/Aug/2026:08:17:31 +0100] "GET /@fs/root/.aws/credentials?raw?? HTTP/1.1" 302 6773 0/151126 "-" "Mozilla/5.0 (Windows NT 11.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.6034.219 Safari/537.36; compatible; ClaudeBot/1.0; +claudebot@[redacted]"
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-26 06:45:52
(1 week ago)
(mod_security) mod_security (id:211190) triggered by 35.187.65.167 (167.65.187.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:211190) triggered by 35.187.65.167 (167.65.187.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 02:45:44.935772 2026] [security2:error] [pid 3516:tid 3516] [client 35.187.65.167:35568] ModSecurity: Access denied with code 403 (phase 2). Match of "contains cpanel" against "REQUEST_URI" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "55"] [id "211190"] [rev "9"] [msg "COMODO WAF: Remote File Access Attempt||mail.quincysheetmetal.com|F|2"] [data "Matched Data: /etc/ found within REQUEST_URI: /?file=../../../../etc/passwd"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.quincysheetmetal.com"] [uri "/"] [unique_id "ao6LmPW2gqvV4O3VqlHIogAAAGQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-08-26 06:27:15
(1 week ago)
Restricted File Access Attempt. Matched phrase "/@fs/" at REQUEST_FILENAME. (930130-201)
Hacking
Web App Attack
๐ธ๐ช
EmK530
2026-08-26 05:27:20
(1 week ago)
URL flagged by RegEx: /.git/HEAD
Web App Attack