๐ฉ๐ช
piticu iuli
2026-08-07 02:37:09
(1 month ago)
(mod_security) mod_security triggered on hostname [redacted] 45.194.27.110 (MY/Malaysia/-)
SQL Injection
Anonymous
2026-08-07 02:27:05
(1 month ago)
Web application attack detected.
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-07 02:22:00
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 45.194.27.110 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 45.194.27.110 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 06 22:21:56.287904 2026] [security2:error] [pid 3715284:tid 3715284] [client 45.194.27.110:39728] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "web.cruisingforsex.com"] [uri "/.git/config"] [unique_id "anVBRFD_f518BOc9VILe5wAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
Gabriel Camargo
2026-08-07 01:34:47
(1 month ago)
45.194.27.110 - - [06/Aug/2026:20:34:47 -0500] "GET /.env.prod HTTP/1.1" 301 178 "-" "Mozilla/5.0 (W ...
show more
45.194.27.110 - - [06/Aug/2026:20:34:47 -0500] "GET /.env.prod HTTP/1.1" 301 178 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
45.194.27.110 - - [06/Aug/2026:20:34:47 -0500] "GET /.git/config HTTP/1.1" 301 178 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
45.194.27.110 - - [06/Aug/2026:20:34:47 -0500] "GET /.env.backup HTTP/1.1" 301 178 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
...
show less
Brute-Force
SSH
๐ณ๐ด
jad-abuse
2026-08-06 23:58:08
(1 month ago)
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: env_probe ...
show more
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: env_probe, source_backup, git_exposure. Observed by 1 sensor(s); 7 hits.
show less
Web App Attack
Anonymous
2026-08-06 21:08:43
(1 month ago)
IncogNET WAF local CrowdSec decision. Scenario=crowdsecurity/appsec-vpatch; Action=ban; Events=2; Co ...
show more
IncogNET WAF local CrowdSec decision. Scenario=crowdsecurity/appsec-vpatch; Action=ban; Events=2; Country=MY; ASN=149440 Evoxt Enterprise
show less
Hacking
๐ธ๐ช
vaia.cloud
2026-08-06 20:45:02
(1 month ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
๐ฉ๐ช
33three
2026-08-06 16:47:27
(1 month ago)
Fail2Ban jail WebAttack triggered
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-08-06 15:50:01
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 45.194.27.110 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 45.194.27.110 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 06 11:49:54.818351 2026] [security2:error] [pid 3034267:tid 3034267] [client 45.194.27.110:58418] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kiinlog.com"] [uri "/.env"] [unique_id "anStIh8GcVb10tpUCilsnwAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-08-06 15:30:51
(1 month ago)
[06/Aug/2026:18:30:50 +0300] -- 45.194.27.110 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.env ...
show more
[06/Aug/2026:18:30:50 +0300] -- 45.194.27.110 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.env.backup HTTP/1.1
show less
Bad Web Bot
Web App Attack
๐ฎ๐น
CoreTech srl
2026-08-06 06:14:31
(1 month ago)
cloudlinux2 fail2ban: 2026-08-06 08:08:51,194 fail2ban.filter [1460]: INFO [plesk-wordpre ...
show more
cloudlinux2 fail2ban: 2026-08-06 08:08:51,194 fail2ban.filter [1460]: INFO [plesk-wordpress] Found 91.206.200.203 - 2026-08-06 08:08:50cloudlinux2 fail2ban: 2026-08-06 08:10:28,233 fail2ban.filter [1460]: INFO [plesk-modsecurity] Found 182.48.223.117 - 2026-08-06 08:10:27cloudlinux2 fail2ban: 2026-08-06 08:11:48,348 fail2ban.filter [1460]: INFO [recidive] Found 45.194.27.110 - 2026-08-06 08:11:48cloudlinux2 fail2ban: 2026-08-06 08:11:48,114 fail2ban.filter [1460]: INFO [plesk-modsecurity] Found 45.194.27.110 - 2026-08-06 08:11:48cloudlinux2 fail2ban: 2026-08-06 08:11:48,142 fail2ban.filter [1460]: INFO [plesk-modsecurity] Found 45.194.27.110 - 2026-08-06 08:11:48cloudlinux2 fail2ban: 2026-08-06 08:11:48,170 fail2ban.filter [1460]: INFO [plesk-modsecurity] Found 45.194.27.110 - 2026-08-06 08:11:48cloudlinux2 fail2ban: 2026-08-06 08:11:48,343 fail2ban.actions [1460]: NOTICE [plesk-modsecurity] Ban 45.194.27.110cloudlinux2 fail2ban: 2026-0
show less
Web App Attack
๐ง๐ช
voormedia
2026-08-06 05:55:21
(1 month ago)
Accessed trap at '/.env'
Web App Attack
Anonymous
2026-08-06 04:05:04
(1 month ago)
Web Server Exposed Git Repository Information Disclosure.
Hacking
๐บ๐ธ
TPI-Abuse
2026-08-06 04:02:03
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 45.194.27.110 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 45.194.27.110 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 06 00:01:58.316301 2026] [security2:error] [pid 527542:tid 527542] [client 45.194.27.110:49898] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "fundaciondamashcc.org.ec"] [uri "/.env.save"] [unique_id "anQHNiXmyfChCqr1UqVwygAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Skyrider
2026-08-06 03:51:16
(1 month ago)
crowdsecurity/http-sensitive-files
Web App Attack