๐จ๐ญ
TheCoon
2026-06-04 01:15:01
(5 days ago)
Automated: Credential theft attempt - JSON bomb served
Web App Attack
Hacking
๐ณ๐ฑ
homeshowdomain.nl
2026-05-29 21:59:04
(1 week ago)
Auto-ban: >3000 req/min op 2026-05-29
Web App Attack
SSH
Hacking
๐ซ๐ท
Little Iguana
2026-05-29 04:52:48
(1 week ago)
Attempt to hack Wordpress Login, XMLRPC or other login
Hacking
๐ช๐ธ
alferez
2026-05-29 01:32:04
(1 week ago)
Searching .env files
Hacking
Exploited Host
Web App Attack
Anonymous
2026-05-29 00:07:57
(1 week ago)
45.13.214.53 - - [29/May/2026:00:07:56 +0000] "GET /.vault.env HTTP/1.1" 302 578 "-" "Mozilla/5.0 (M ...
show more
45.13.214.53 - - [29/May/2026:00:07:56 +0000] "GET /.vault.env HTTP/1.1" 302 578 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/130.0.0.0 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
Sling
2026-05-28 20:36:21
(1 week ago)
Automated detection: IP accessed 16 sensitive endpoints within 30s on slingexe.me. Paths: /.aws/cred ...
show more
Automated detection: IP accessed 16 sensitive endpoints within 30s on slingexe.me. Paths: /.aws/credentials, /.npmrc, /.env.bak, /application.properties, /.env.backup, /secrets.json, /credentials.json, /secrets.yml, /.env, /application.yml. UA: Mozilla/5.0 (iPhone; CPU iPhone OS 17_7 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.7 Mobile/15E148 Safari/604.1.
show less
Web App Attack
Bad Web Bot
Hacking
๐ฌ๐ง
Apache
2026-05-28 18:24:21
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 45.13.214.53 (US/United States/-): 5 in the las ...
show more
(mod_security) mod_security (id:210730) triggered by 45.13.214.53 (US/United States/-): 5 in the last 300 secs (CF_ENABLE)
show less
Brute-Force
Web App Attack
๐ท๐บ
DZBOT
2026-05-28 17:59:42
(1 week ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-28 14:50:55
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 45.13.214.53 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 45.13.214.53 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 28 10:50:51.797353 2026] [security2:error] [pid 2248:tid 2248] [client 45.13.214.53:41228] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "skipspsaexchange.com"] [uri "/.env.development"] [unique_id "ahhWSyQqFD1kNpSUYljfQQAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-05-28 14:27:11
(1 week ago)
Bot / seems abusive / Apache connections: 21
DDoS Attack
Web Spam
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob.fr
2026-05-28 14:15:08
(1 week ago)
Repeated 404 errors, blocked by Fail2ban in custom-404 jail
Bad Web Bot
๐บ๐ธ
kosada.com
2026-05-28 14:01:09
(1 week ago)
Web vulnerability probing: /secrets.yml (bogus vhost/SNI)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-28 13:52:26
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 45.13.214.53 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 45.13.214.53 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 28 09:52:20.914458 2026] [security2:error] [pid 3843:tid 3843] [client 45.13.214.53:57728] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "wplusw.com"] [uri "/.git/config"] [unique_id "ahhIlIM1g9tqgjr_Njf0OgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
ConsulHosting
2026-05-28 10:31:36
(1 week ago)
Excessive failed CAPTCHA attempts (CAPTCHA DoS)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-28 10:17:24
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 45.13.214.53 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 45.13.214.53 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 28 06:17:20.528536 2026] [security2:error] [pid 31490:tid 31490] [client 45.13.214.53:37130] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "lightedpath.com"] [uri "/.git/config"] [unique_id "ahgWMG7V7Sz87Mf_g9PzjwAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack