๐ฉ๐ช
LRob
2026-09-01 05:25:21
(10 hours ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /wp-config.php.swp (+12 more) | 2026-09-01 05:25 UTC
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 05:07:35
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.199.120.21 (21.120.199.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.199.120.21 (21.120.199.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 01:07:29.770355 2026] [security2:error] [pid 31873:tid 31873] [client 35.199.120.21:42066] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.djcommodore.com"] [uri "/.env.old"] [unique_id "apZdkW2zJi0PBANuv_JqSQAAAEU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-09-01 05:06:11
(10 hours ago)
Scanning/Probing (20)
Brute-Force
Web App Attack
๐ฉ๐ช
dbmwebdesign
2026-09-01 04:45:02
(11 hours ago)
WAF repeated trigger detected by Fail2Ban in plesk-modsecurity jail
Web App Attack
Anonymous
2026-09-01 03:30:44
(12 hours ago)
Web application attack detected.
Web App Attack
๐ฉ๐ช
joharikop
2026-09-01 03:17:40
(12 hours ago)
Nginx: credential/secret file probe (/.env, /.git, /.aws etc). Automated ban via fail2ban nginx-cred ...
show more
Nginx: credential/secret file probe (/.env, /.git, /.aws etc). Automated ban via fail2ban nginx-credential-probes jail.
show less
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-09-01 02:50:34
(13 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 02:34:28
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.199.120.21 (21.120.199.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.199.120.21 (21.120.199.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 22:34:21.037577 2026] [security2:error] [pid 21293:tid 21293] [client 35.199.120.21:47452] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.dc406.net"] [uri "/wp-config.php.swp"] [unique_id "apY5rY7456O551m3U-cSUgAAACA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
consul.to
2026-09-01 02:14:42
(13 hours ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 02:14:39
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.199.120.21 (21.120.199.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.199.120.21 (21.120.199.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 22:14:35.333307 2026] [security2:error] [pid 22859:tid 22859] [client 35.199.120.21:55782] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "havenlaneministries.com"] [uri "/.env.old"] [unique_id "apY1C_PnvdFV8AohPTDvuAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
4server
2026-09-01 00:27:35
(15 hours ago)
[TueSep0102:27:33.7293412026][security2:error][pid3407155:tid3407224][client35.199.120.21:0]ModSecur ...
show more
[TueSep0102:27:33.7293412026][security2:error][pid3407155:tid3407224][client35.199.120.21:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Patternmatch\"\(\?i\)\(\?:/\(\?:\^\|/\)\\\\\\\\.\(env\|git\|svn\|hg\|DS_Store\)\|/\(\?:wp-config\|\\\\\\\\.htaccess\|\\\\\\\\.htpasswd\)\|\\\\\\\\.\(\?:sql\|bak\|old\|log\)\$\)\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"156\"][id\"960720\"][msg\"Forbiddenfileaccessattempt\"][severity\"CRITICAL\"][hostname\"cpcontacts.gmint.ch\"][uri\"/.env.old\"][unique_id\"apYb9eXtJC9DG1CdFCM12QAAAMU\"]
show less
Port Scan
Brute-Force
Web App Attack
๐ฟ๐ฆ
conure.sh
2026-09-01 00:22:45
(15 hours ago)
csagent: score 20.0: secrets grab x2; 1 domain(s) in 0s
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 00:14:53
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.199.120.21 (21.120.199.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.199.120.21 (21.120.199.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 20:14:48.123413 2026] [security2:error] [pid 925:tid 925] [client 35.199.120.21:41234] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.braunfamily.info"] [uri "/wp-config.php.swp"] [unique_id "apYY-JIgTL41U7bOqSAKFgAAAFQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-08-31 22:53:31
(17 hours ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-31 22:46:34
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.199.120.21 (21.120.199.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.199.120.21 (21.120.199.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 18:46:30.216819 2026] [security2:error] [pid 1223:tid 1223] [client 35.199.120.21:41630] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "blanchebb.com"] [uri "/.env.old"] [unique_id "apYERoA03e5urAByylgVywAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack