๐บ๐ธ
SYSMarshal
2025-12-15 16:44:42
(9 months ago)
SysMarshal detection : RDP Brute-Force
DDoS Attack
Brute-Force
๐ท๐ด
RsH
2025-12-11 04:47:02
(9 months ago)
2025/12/11 04:47:01 [error] 2423#2423: *74892 access forbidden by rule, client: 35.88.178.210, serve ...
show more
2025/12/11 04:47:01 [error] 2423#2423: *74892 access forbidden by rule, client: 35.88.178.210, server: rares-andrei.me, request: "GET /.env HTTP/2.0", host: "rares-andrei.me", referrer: "http://rares-andrei.me/.env"
2025/12/11 04:47:01 [error] 2423#2423: *74892 access forbidden by rule, client: 35.88.178.210, server: rares-andrei.me, request: "GET /app/.env HTTP/2.0", host: "rares-andrei.me", referrer: "http://rares-andrei.me/app/.env"
2025/12/11 04:47:01 [error] 2423#2423: *74892 access forbidden by rule, client: 35.88.178.210, server: rares-andrei.me, request: "GET /config/.env HTTP/2.0", host: "rares-andrei.me", referrer: "http://rares-andrei.me/config/.env"
2025/12/11 04:47:01 [error] 2423#2423: *74892 access forbidden by rule, client: 35.88.178.210, server: rares-andrei.me, request: "GET /api/.env HTTP/2.0", host: "rares-andrei.me", referrer: "http://rares-andrei.me/api/.env"
2025/12/11 04:47:01 [error] 2423#2423: *74892 access forbidden by rule, client: 35.88.178.210, server: rar
...
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob
2025-12-11 03:32:23
(9 months ago)
WAF repeated trigger detected by Fail2Ban in plesk-modsecurity jail
Web App Attack
๐ณ๐ฑ
Jordy
2025-12-11 03:07:21
(9 months ago)
11/Dec/2025:04:07:20.144754 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client ...
show more
11/Dec/2025:04:07:20.144754 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client 35.88.178.210] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "125"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "ramongames.nl"] [uri "/.env"] [unique_id "aTo1aFfleYUiYE2fAkNp0gAAAAU"]
11/Dec/2025:04:07:20.144754 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client 35.88.178.210] ModSecurity: Warning. Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "In
...
show less
Web App Attack
๐ซ๐ท
Quarks Solutions
2025-12-11 02:58:10
(9 months ago)
crowdsecurity/http-sensitive-files
Hacking
Web App Attack
๐ฎ๐ฉ
Burayot
2025-12-11 02:57:31
(9 months ago)
LF_MODSEC: (mod_security) mod_security (id:949110) triggered by 35.88.178.210 (US/United States/ec2- ...
show more
LF_MODSEC: (mod_security) mod_security (id:949110) triggered by 35.88.178.210 (US/United States/ec2-35-88-178-210.us-west-2.compute.amazonaws.com): 1 in the last 3600 secs
show less
Web App Attack
๐ฉ๐ช
big-cloud.nl
2025-12-11 02:17:57
(9 months ago)
Try to access /.env
Web App Attack
๐บ๐ธ
myagent.site
2025-12-11 02:15:08
(9 months ago)
Blocking for trying to access an exploit file: /.env
Hacking
๐บ๐ธ
octageeks.com
2025-12-10 05:07:44
(9 months ago)
Wordpress malicious attack:[octablocked]
Web App Attack
๐ฆ๐บ
2000cn.com.au
2025-12-10 03:29:42
(9 months ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Hacking
Web App Attack
๐ฉ๐ช
lumbermatt_de
2025-12-10 03:07:44
(9 months ago)
Vulnerability exploit attack detected
Web App Attack
๐ณ๐ฑ
Jordy
2025-12-10 02:39:40
(9 months ago)
10/Dec/2025:03:39:39.952719 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client ...
show more
10/Dec/2025:03:39:39.952719 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client 35.88.178.210] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "125"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "ramongames.nl"] [uri "/.env"] [unique_id "aTjda1gTEvX1N3ZwJbc80gAAAAs"]
10/Dec/2025:03:39:39.952719 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client 35.88.178.210] ModSecurity: Warning. Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "In
...
show less
Web App Attack
๐ซ๐ฎ
as211431.net
2025-12-10 02:16:18
(9 months ago)
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET metho ...
show more
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET method)
Endpoint: /.env
UA: Mozilla/5.0 (X11; Linux x86_64)
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐ฉ๐ช
neckaralb-admin.de
2025-12-10 02:04:46
(9 months ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
๐บ๐ธ
myagent.site
2025-12-10 01:56:29
(9 months ago)
Blocking for trying to access an exploit file: /.env
Hacking