๐บ๐ธ
OceanTreasure
2026-09-16 08:21:00
(1 day ago)
tcp/80; PHPUnit RCE vulnerability exploitation: "POST //admin/vendor/phpunit/phpunit/src/Util/PHP/ev ...
show more
tcp/80; PHPUnit RCE vulnerability exploitation: "POST //admin/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" @ 2026-09-16T08:21:00Z [proxy]
show less
Web App Attack
๐ฉ๐ช
joharikop
2026-09-16 08:09:59
(1 day ago)
Nginx: credential/secret file probe (/.env, /.git, /.aws etc). Automated ban via fail2ban nginx-cred ...
show more
Nginx: credential/secret file probe (/.env, /.git, /.aws etc). Automated ban via fail2ban nginx-credential-probes jail.
show less
Web App Attack
๐บ๐ธ
[email protected]
2026-09-16 07:49:52
(1 day ago)
CrowdSec ban: crowdsecurity/http-wordpress-scan (duration: 71h59m50s)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 00:25:33
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.200.5.159 (159.5.200.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.200.5.159 (159.5.200.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 20:25:25.898645 2026] [security2:error] [pid 25119:tid 25119] [client 35.200.5.159:41100] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "lucypower.com"] [uri "/.env"] [unique_id "aqnh9VqDka731b-7asVU9gAAACU"], referer: https://www.google.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
consul.to
2026-09-15 19:51:03
(2 days ago)
Web attack/malicious scanning detected
Web App Attack
๐ซ๐ท
dynamix
2026-09-15 19:29:18
(2 days ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 19:13:00
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 35.200.5.159 (159.5.200.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.200.5.159 (159.5.200.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 15:12:55.281302 2026] [security2:error] [pid 31800:tid 31800] [client 35.200.5.159:41058] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "frenchla.com"] [uri "/.env"] [unique_id "aqmYt8xjkGQr-jWznDniuQAAABU"], referer: https://www.google.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 16:48:56
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 35.200.5.159 (159.5.200.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.200.5.159 (159.5.200.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 12:48:51.252933 2026] [security2:error] [pid 3699:tid 3750] [client 35.200.5.159:34460] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "eceinal.com"] [uri "/.env"] [unique_id "aql282oPXOvU9i2gw4T5YwAAAZE"], referer: https://www.google.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 15:27:11
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 35.200.5.159 (159.5.200.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.200.5.159 (159.5.200.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 11:27:07.569026 2026] [security2:error] [pid 5374:tid 5374] [client 35.200.5.159:59066] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cowetaappliance.com"] [uri "/.env"] [unique_id "aqljyzerQLi8o-TBBRYrSAAAAAs"], referer: https://www.google.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
Lee Daniel
2026-09-15 13:55:00
(2 days ago)
35.200.5.159 - - [15/Sep/2026:09:54:59 -0400] "GET /.env HTTP/1.1" 403 6302 "https://www.google.com/ ...
show more
35.200.5.159 - - [15/Sep/2026:09:54:59 -0400] "GET /.env HTTP/1.1" 403 6302 "https://www.google.com/" "Mozilla/5.0 (Windows; U; MSIE 7.0b; Linux x86_64; Trident/5.0; X11)"
...
show less
DDoS Attack
Web Spam
Email Spam
Port Scan
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
IndigoRidge
2026-09-15 13:50:55
(2 days ago)
35.200.5.159 - - [15/Sep/2026:09:50:53 -0400] "GET /.env HTTP/1.1" 500 5325 "https://www.google.com/ ...
show more
35.200.5.159 - - [15/Sep/2026:09:50:53 -0400] "GET /.env HTTP/1.1" 500 5325 "https://www.google.com/" "Mozilla/5.0 (Linux i386; X11) AppleWebKit/535.9 (KHTML, like Gecko) Version/6.0.4 Safari/535.31"
35.200.5.159 - - [15/Sep/2026:09:50:55 -0400] "GET //vendor/.env HTTP/1.1" 404 5741 "https://www.google.com/" "Mozilla/5.0 (Linux i386; X11) AppleWebKit/535.9 (KHTML, like Gecko) Version/6.0.4 Safari/535.31"
35.200.5.159 - - [15/Sep/2026:09:50:55 -0400] "GET //lib/.env HTTP/1.1" 404 5741 "https://www.google.com/" "Mozilla/5.0 (Linux i386; X11) AppleWebKit/535.9 (KHTML, like Gecko) Version/6.0.4 Safari/535.31"
...
show less
Web App Attack
๐ฉ๐ช
arnisolutions
2026-09-15 08:46:34
(2 days ago)
Vulnerability scanning (requests for admin panels, shells, backup files etc.) against a production s ...
show more
Vulnerability scanning (requests for admin panels, shells, backup files etc.) against a production server. Observed on 1 day(s) between 2026-09-15 and 2026-09-15 (UTC). Sample request: GET //vendor/.env HTTP/1.1
show less
Web App Attack
Hacking
๐ฉ๐ช
Hazzard
2026-09-15 07:16:10
(2 days ago)
(mod_security) mod_security triggered on hostname [redacted]): (CF_ENABLE)
SQL Injection
๐ฉ๐ช
FD-IX
2026-09-15 07:15:05
(2 days ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack