๐ฉ๐ช
LRob
2026-09-02 04:30:24
(33 minutes ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /.env (+1 more) | 2026-09-02 04:30 UTC
show less
Hacking
Web App Attack
๐ซ๐ท
dynamix
2026-09-02 04:04:43
(58 minutes ago)
Multiple WAF Violations
Web App Attack
๐ฉ๐ช
4server
2026-09-02 03:33:50
(1 hour ago)
[WedSep0205:33:48.3745302026][security2:error][pid887158:tid887234][client35.221.63.123:0]ModSecurit ...
show more
[WedSep0205:33:48.3745302026][security2:error][pid887158:tid887234][client35.221.63.123:0]ModSecurity:Accessdeniedwithcode403\(phase2\).Patternmatch\"\(\?:\\\\\\\\\$\(\?:\\\\\\\\\(\(\?:\\\\\\\\\(.\*\\\\\\\\\)\|.\*\)\\\\\\\\\)\|\\\\\\\\{.\*\\\\\\\\}\)\|[\<\>]\\\\\\\\\(.\*\\\\\\\\\)\)\"atARGS:0.[file\"/etc/apache2/conf.d/modsec_rules/10_asl_rules.conf\"][line\"396\"][id\"393655\"][rev\"17\"][msg\"Atomicorp.comWAFRules:PossibleRemoteCommandExecution:UnixShellExpressionFound\"][data\"MatchedData:\$\(\(41\*271\)\)foundwithinARGS:0:{then:\$1:__proto__:thenstatus:resolved_modelreason:-1value:{then:\$b1337}_response:{_prefix:varres=process.mainmodule.require\(child_process\).execsync\(echo\$\(\(41\*271\)\)\|base64-w0\).tostring\(\).trim\(\)throwobject.assign\(newerror\(next_redirect\){digest:\`next_redirectpush/login\?a=\${res}307\`}\)_chunks:\$q2_formdata:{get:\$1:constructor:constructor}}}\"][tag\"attack-rce\"][hostname\"www.ldrtrade.eu.136-243-54-122.cpanel.site\"][uri\"/\"][unique_id\"apeZHJtbAy-y30kFatXHqQAAAIw\
show less
Port Scan
Brute-Force
Web App Attack
๐ซ๐ท
Octopuce
2026-09-02 01:52:51
(3 hours ago)
Aggressive web search of vulnerable pages: /.env /.env.local /app/.env /apps/.env /api/.env ...
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-02 01:49:21
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.221.63.123 (123.63.221.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.221.63.123 (123.63.221.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 21:49:12.550073 2026] [security2:error] [pid 32377:tid 32377] [client 35.221.63.123:34802] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.lct.lbee.com"] [uri "/.git/config"] [unique_id "apeAmNYIsrbepFZuY4VBzgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 22:16:46
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.221.63.123 (123.63.221.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.221.63.123 (123.63.221.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 18:16:39.101595 2026] [security2:error] [pid 13553:tid 13553] [client 35.221.63.123:41180] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.lbgeeks.com"] [uri "/.git/config"] [unique_id "apdOx6xDIYCcYS4w6ylQsAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-09-01 21:43:12
(7 hours ago)
Excessive 404/403 errors
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-09-01 21:07:43
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.221.63.123 (123.63.221.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.221.63.123 (123.63.221.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 17:07:38.724892 2026] [security2:error] [pid 29696:tid 29696] [client 35.221.63.123:43642] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.lazymanvegan.com.trafficstopper.com"] [uri "/.git/config"] [unique_id "apc-mrvuhmNRyYL1fY1O1gAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-01 19:40:03
(9 hours ago)
suspicious request in access.log
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 19:35:40
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.221.63.123 (123.63.221.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.221.63.123 (123.63.221.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 15:35:35.046899 2026] [security2:error] [pid 1361:tid 1361] [client 35.221.63.123:57190] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.layoverinamsterdam.thinkingepic.com"] [uri "/.git/config"] [unique_id "apcpBxfokKZkMzL5Goi19wAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
VHosting
2026-09-01 18:50:03
(10 hours ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 18:36:58
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.221.63.123 (123.63.221.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.221.63.123 (123.63.221.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 14:36:54.067422 2026] [security2:error] [pid 10581:tid 10581] [client 35.221.63.123:53480] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.laydox.com"] [uri "/.git/config"] [unique_id "apcbRoQoTFnoXcCqEJzTwwAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 17:26:15
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.221.63.123 (123.63.221.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.221.63.123 (123.63.221.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 13:26:07.819627 2026] [security2:error] [pid 4944:tid 4957] [client 35.221.63.123:58978] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.lawyercalifornia.net.aafm.us"] [uri "/.git/config"] [unique_id "apcKr59eFmZnnxHsI4ZQAwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack