๐ณ๐ฑ
e.fierstra
2026-08-01 05:30:25
(18 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-07-31 22:21:33
(1 day ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-31 21:46:01
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 45.33.4.246 (45-33-4-246.ip.linodeusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 45.33.4.246 (45-33-4-246.ip.linodeusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 31 17:45:56.567856 2026] [security2:error] [pid 26562:tid 26562] [client 45.33.4.246:39786] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "yakaloco.tracybur.net"] [uri "/.env"] [unique_id "am0XlA8uM5mrJKpv9LcbOQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
MarkGGN
2026-07-31 13:01:34
(1 day ago)
Web attack. 45.33.4.246 - - [31/Jul/2026:15:01:33 +0200] "GET /.env HTTP/1.1" 404 178 "-" "Mozilla/5 ...
show more
Web attack. 45.33.4.246 - - [31/Jul/2026:15:01:33 +0200] "GET /.env HTTP/1.1" 404 178 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/138.0.0.0 Safari/537.36 Edg/138.0.0.0"
show less
Web App Attack
๐ฌ๐ง
openstrike.co.uk
2026-07-31 05:13:51
(1 day ago)
4 attacks on env grabbing URLs, PHP URLs:
GET /.env HTTP/1.1
GET /login/index.php HTTP/1.1
Hacking
Web App Attack
๐ฆ๐บ
paulshipley.com.au
2026-07-30 23:37:41
(2 days ago)
[Fri Jul 31 09:37:40.763880 2026] [security2:error] [pid 605525] [client 45.33.4.246:51790] [client ...
show more
[Fri Jul 31 09:37:40.763880 2026] [security2:error] [pid 605525] [client 45.33.4.246:51790] [client 45.33.4.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/modsecurity/crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "winesbydesign.com.au"] [uri "/.env"] [unique_id "amvgRJ2_6sQSpKKuDf_nVAAAAAY"]
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-30 20:59:54
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 45.33.4.246 (45-33-4-246.ip.linodeusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 45.33.4.246 (45-33-4-246.ip.linodeusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 30 16:59:47.656270 2026] [security2:error] [pid 476424:tid 476424] [client 45.33.4.246:45454] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "whm.powersystemprotection.co.uk"] [uri "/.env"] [unique_id "amu7Q8xl4wcnqvHX6XPZUgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฒ๐ฆ
Bazoras
2026-07-30 13:36:00
(2 days ago)
Exploited Host
Hacking
๐บ๐ธ
anon333
2026-07-30 13:33:58
(2 days ago)
Hacker syslog review 1785418438
Hacking
๐บ๐ธ
anon333
2026-07-30 12:06:25
(2 days ago)
Invalid probes to web server T0806
Hacking
Exploited Host
๐ฉ๐ช
MarkGGN
2026-07-30 11:22:03
(2 days ago)
Web attack. 45.33.4.246 - - [30/Jul/2026:13:22:01 +0200] "GET /.env HTTP/1.1" 401 574 "-" "Mozilla/5 ...
show more
Web attack. 45.33.4.246 - - [30/Jul/2026:13:22:01 +0200] "GET /.env HTTP/1.1" 401 574 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/138.0.0.0 Safari/537.36 Edg/138.0.0.0"
45.33.4.246 - - [30/Jul/2026:13:22:02 +0200] "GET /geoserver/web/ HTTP/1.1" 401 574 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/138.0.0.0 Safari/537.36 Edg/138.0.0.0"
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-30 10:48:25
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 45.33.4.246 (45-33-4-246.ip.linodeusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 45.33.4.246 (45-33-4-246.ip.linodeusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 30 06:48:19.385143 2026] [security2:error] [pid 1073787:tid 1073787] [client 45.33.4.246:55010] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "whm.jmms.mx"] [uri "/.env"] [unique_id "amsr80vf6XRcFQ3cGBBXZwAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-30 09:24:34
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 45.33.4.246 (45-33-4-246.ip.linodeusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 45.33.4.246 (45-33-4-246.ip.linodeusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 30 05:24:26.783960 2026] [security2:error] [pid 987229:tid 987229] [client 45.33.4.246:49596] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.juca.com.mx"] [uri "/.env"] [unique_id "amsYStb8L7yR6m5_ppoKEAAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-30 07:52:25
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 45.33.4.246 (45-33-4-246.ip.linodeusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 45.33.4.246 (45-33-4-246.ip.linodeusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 30 03:52:20.716100 2026] [security2:error] [pid 5720:tid 5720] [client 45.33.4.246:51724] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "whm.oxford-gliding-club.co.uk"] [uri "/.env"] [unique_id "amsCtMIFx74o1mWZpSaVPwAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-30 05:06:55
(2 days ago)
45.33.4.246 - - [30/Jul/2026:05:06:54 +0000] "GET /.env HTTP/1.1" 302 678 "-" "Mozilla/5.0 (Windows ...
show more
45.33.4.246 - - [30/Jul/2026:05:06:54 +0000] "GET /.env HTTP/1.1" 302 678 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/138.0.0.0 Safari/537.36 Edg/138.0.0.0"
...
show less
Bad Web Bot
Web App Attack