π²πΎ
Rizzy
2026-08-01 23:01:15
(3 hours ago)
Multiple WAF Violations
Brute-Force
Web App Attack
πͺπΈ
alferez
2026-08-01 08:37:30
(18 hours ago)
Searching .(env|sql|zip|tar|rar) files
Hacking
Exploited Host
Web App Attack
π¨π
4server
2026-08-01 06:30:53
(20 hours ago)
[SatAug0108:30:46.7931972026][security2:error][pid2338072:tid2338187][client51.75.69.207:0]ModSecuri ...
show more
[SatAug0108:30:46.7931972026][security2:error][pid2338072:tid2338187][client51.75.69.207:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\".env\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"365\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"marcionetti.es\"][uri\"/.env\"][unique_id\"am2SloEB1XDm3_og97cRnAAAAIg\"]
show less
Hacking
Web App Attack
π§πͺ
delabiemedia.be
2026-08-01 02:25:27
(1 day ago)
51.75.69.207 - - [01/Aug/2026:04:25:27 +0200] "GET /users/sign_in HTTP/1.1" 404 196 "-" "Mozilla/5.0 ...
show more
51.75.69.207 - - [01/Aug/2026:04:25:27 +0200] "GET /users/sign_in HTTP/1.1" 404 196 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/138.0.0.0 Safari/537.36 Edg/138.0.0.0"
51.75.69.207 - - [01/Aug/2026:04:25:27 +0200] "GET /.env HTTP/1.1" 404 196 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/138.0.0.0 Safari/537.36 Edg/138.0.0.0"
51.75.69.207 - - [01/Aug/2026:04:25:27 +0200] "GET /a1b2c3d4e5f6-not-found HTTP/1.1" 404 196 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/138.0.0.0 Safari/537.36 Edg/138.0.0.0"
51.75.69.207 - - [01/Aug/2026:04:25:27 +0200] "GET /_ignition/health-check HTTP/1.1" 404 196 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/138.0.0.0 Safari/537.36 Edg/138.0.0.0"
51.75.69.207 - - [01/Aug/2026:04:25:27 +0200] "GET /_debugbar/open HTTP/1.1" 404 196 "-" "Mozilla/5.0 (Windows NT 10.0; Win64;
...
show less
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-01 01:03:08
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 51.75.69.207 (vps-3e0e974c.vps.ovh.net): 1 in t ...
show more
(mod_security) mod_security (id:210492) triggered by 51.75.69.207 (vps-3e0e974c.vps.ovh.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 31 21:03:04.025597 2026] [security2:error] [pid 994213:tid 994213] [client 51.75.69.207:53942] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "whm.fiestadj.com.mx"] [uri "/.env"] [unique_id "am1FyJ8KoRJONtDI_99IeAAAAH4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-07-31 20:51:01
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 51.75.69.207 (vps-3e0e974c.vps.ovh.net): 1 in t ...
show more
(mod_security) mod_security (id:210492) triggered by 51.75.69.207 (vps-3e0e974c.vps.ovh.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 31 16:50:57.156554 2026] [security2:error] [pid 911785:tid 911785] [client 51.75.69.207:45126] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.elpais.mx"] [uri "/.env"] [unique_id "am0KsRCl3b51z8mgvbMbpAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-07-31 20:27:45
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 51.75.69.207 (vps-3e0e974c.vps.ovh.net): 1 in t ...
show more
(mod_security) mod_security (id:210492) triggered by 51.75.69.207 (vps-3e0e974c.vps.ovh.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 31 16:27:40.336560 2026] [security2:error] [pid 3142783:tid 3142783] [client 51.75.69.207:39952] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.dosrios.com.mx"] [uri "/.env"] [unique_id "am0FPEM4h5EgdDMAomGbdgAAAG4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π¨π¦
polycoda
2026-07-31 19:17:08
(1 day ago)
AutoBlock: π― Vulnerability Scanner (Non Decay-Based) - π Directory Listings (Decay-Based) - β Excess ...
show more
AutoBlock: π― Vulnerability Scanner (Non Decay-Based) - π Directory Listings (Decay-Based) - β Excessive 40X Errors (Decay-Based)
show less
Hacking
Bad Web Bot
Web App Attack
π¨π¦
Anymous
2026-07-31 16:39:11
(1 day ago)
GET /users/sign_in HTTP/1.1 404 443 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.3 ...
show more
GET /users/sign_in HTTP/1.1 404 443 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML
show less
Port Scan
Web App Attack
π§πͺ
cmbplf
2026-07-31 11:29:08
(1 day ago)
135 requests with url.path *.env
Brute-Force
Bad Web Bot
Anonymous
2026-07-31 10:19:10
(1 day ago)
51.75.69.207 www.patrz.eu - [31/Jul/2026:12:19:09 +0200] "GET /.env HTTP/1.1" 301 0 "-" "Mozilla/5.0 ...
show more
51.75.69.207 www.patrz.eu - [31/Jul/2026:12:19:09 +0200] "GET /.env HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/138.0.0.0 Safari/537.36 Edg/138.0.0.0"
...
show less
Hacking
Web App Attack
π©πͺ
big-cloud.nl
2026-07-31 09:50:14
(1 day ago)
Try to access /.env
Web App Attack
π«π·
IRISIO
2026-07-31 08:38:07
(1 day ago)
scans/SQL injection/spam posts : 200 queries
Web App Attack
SQL Injection
πΊπΈ
TPI-Abuse
2026-07-30 23:38:27
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 51.75.69.207 (vps-3e0e974c.vps.ovh.net): 1 in t ...
show more
(mod_security) mod_security (id:210492) triggered by 51.75.69.207 (vps-3e0e974c.vps.ovh.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 30 19:38:20.524222 2026] [security2:error] [pid 2062969:tid 2062969] [client 51.75.69.207:58942] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "whm.nmorganist.org"] [uri "/.env"] [unique_id "amvgbPwAjqVQdvZvmVxwKQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-07-30 23:10:34
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 51.75.69.207 (vps-3e0e974c.vps.ovh.net): 1 in t ...
show more
(mod_security) mod_security (id:210492) triggered by 51.75.69.207 (vps-3e0e974c.vps.ovh.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 30 19:10:26.741024 2026] [security2:error] [pid 2396733:tid 2396733] [client 51.75.69.207:35782] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "whm.chezlubacov.org"] [uri "/.env"] [unique_id "amvZ4nvaztFSA216lYVWmAAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack