๐ง๐ช
voormedia
2026-06-30 09:22:29
(1 month ago)
Accessed trap at '/.env'
Web App Attack
๐ซ๐ท
Octopuce
2026-06-30 09:16:45
(1 month ago)
Aggressive web search of vulnerable pages: /swagger/v2/swagger.json /api/v1/swagger.json /api-docs.j ...
show more
Aggressive web search of vulnerable pages: /swagger/v2/swagger.json /api/v1/swagger.json /api-docs.json /api/swagger.json /swagger.json ...
show less
Web App Attack
๐ซ๐ท
Tonga-Soa
2026-06-30 09:02:49
(1 month ago)
"Hack file passwd etc/passwd..."
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-06-30 08:28:37
(1 month ago)
(mod_security) mod_security (id:210580) triggered by 52.237.167.19 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210580) triggered by 52.237.167.19 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 30 04:28:33.756562 2026] [security2:error] [pid 4884:tid 4899] [client 52.237.167.19:55964] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "etc/passwd" at ARGS:lr. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/08_Global_Other.conf"] [line "57"] [id "210580"] [rev "2"] [msg "COMODO WAF: OS File Access Attempt||www.aspencommission.com|F|2"] [data "Matched Data: etc/passwd found within ARGS:lr: ../../../../../../../../../etc/passwd"] [severity "CRITICAL"] [tag "CWAF"] [tag "Other"] [hostname "www.aspencommission.com"] [uri "/Government-Jobs.html"] [unique_id "akN-Mb_U_NjATSPH01twMwAAAIw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-30 08:19:42
(1 month ago)
SQL Injection
SQL Injection
๐บ๐ธ
TPI-Abuse
2026-06-30 07:06:05
(1 month ago)
(mod_security) mod_security (id:210580) triggered by 52.237.167.19 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210580) triggered by 52.237.167.19 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 30 03:05:57.245070 2026] [security2:error] [pid 4686:tid 4686] [client 52.237.167.19:49962] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "etc/passwd" at ARGS:main_page. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/08_Global_Other.conf"] [line "57"] [id "210580"] [rev "2"] [msg "COMODO WAF: OS File Access Attempt||madrigalscripts.com|F|2"] [data "Matched Data: etc/passwd found within ARGS:main_page: ../../../../../../../../../etc/passwd"] [severity "CRITICAL"] [tag "CWAF"] [tag "Other"] [hostname "madrigalscripts.com"] [uri "/index.php"] [unique_id "akNq1RA31_dSwapd0G6hFwAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
4server
2026-06-30 06:37:32
(1 month ago)
[TueJun3008:37:24.9571212026][security2:error][pid2176772:tid2177014][client52.237.167.19:0]ModSecur ...
show more
[TueJun3008:37:24.9571212026][security2:error][pid2176772:tid2177014][client52.237.167.19:0]ModSecurity:Accessdeniedwithcode403\(phase2\).Matchedphrase\"etc/passwd\"atARGS:lang.[file\"/etc/apache2/conf.d/modsec_rules/10_asl_rules.conf\"][line\"135\"][id\"344360\"][rev\"5\"][msg\"Atomicorp.comWAFRules:UnauthorizedOperatingSystemFileAccessAttempt\"][data\"MatchedData:etc/passwdfoundwithinARGS:lang:../../../../../../../../../etc/passwd\"][severity\"CRITICAL\"][tag\"attack-lfi\"][hostname\"whatsdecor.ch\"][uri\"/cgi-sys/suspendedpage.cgi\"][unique_id\"akNkJCtTxw_AXqKg5J1SIQAAAMA\"]
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-30 06:05:59
(1 month ago)
(mod_security) mod_security (id:212620) triggered by 52.237.167.19 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:212620) triggered by 52.237.167.19 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 30 02:05:51.682743 2026] [security2:error] [pid 8467:tid 8467] [client 52.237.167.19:63450] ModSecurity: Access denied with code 403 (phase 2). Pattern match "<script\\\\b" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/07_XSS_XSS.conf"] [line "65"] [id "212620"] [rev "3"] [msg "COMODO WAF: Cross-site Scripting (XSS) Attack||advancedmotorsports.com|F|2"] [data "Matched Data: <script found within REQUEST_URI: /cgi-sys/suspendedpage.cgi?utm_source=<script>alert('xss')</script>"] [severity "CRITICAL"] [tag "CWAF"] [tag "XSS"] [hostname "advancedmotorsports.com"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "akNcv7Apg63bpOiYkYzvmQAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-30 04:15:01
(1 month ago)
suspicious request in access.log
Web App Attack
Anonymous
2026-06-30 04:00:20
(1 month ago)
SIEM ALERT AUTO REPORT
Email Spam
๐ฉ๐ช
netclix.gr
2026-06-30 03:07:19
(1 month ago)
(mod_security) mod_security triggered on hostname [redacted] 52.237.167.19 (US/United States/-): (C ...
show more
(mod_security) mod_security triggered on hostname [redacted] 52.237.167.19 (US/United States/-): (CF_ENABLE)
show less
SQL Injection
๐ซ๐ท
Sklurk
2026-06-30 02:14:31
(1 month ago)
Web App Attack
Web App Attack
๐บ๐ธ
nyt
2026-06-30 01:52:05
(1 month ago)
DB Admin Probe, XSS
Web App Attack
๐บ๐ธ
fortypoundhead
2026-06-29 20:37:10
(1 month ago)
SQL Injection Attempt
SQL Injection
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-29 20:26:14
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 52.237.167.19 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 52.237.167.19 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 29 16:26:07.498738 2026] [security2:error] [pid 21934:tid 21934] [client 52.237.167.19:60750] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.fuentevictoria.com"] [uri "/.env"] [unique_id "akLU31HYXBeDfy6PXWJwVgAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack