๐ซ๐ท
Flo Flo
2026-05-11 14:21:50
(3 months ago)
67.205.173.206 - - - [11/May/2026:16:21:49 +0200] "flad.xyz" "GET / HTTP/1.1" 444 0 "-" "Mozilla/5.0 ...
show more
67.205.173.206 - - - [11/May/2026:16:21:49 +0200] "flad.xyz" "GET / HTTP/1.1" 444 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 Chrome/131.0.0.0 Safari/537.36" 0.000
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-11 12:47:13
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 67.205.173.206 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 67.205.173.206 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon May 11 08:47:06.541883 2026] [security2:error] [pid 17097:tid 17154] [client 67.205.173.206:54272] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.oftv.xyz"] [uri "/.env~"] [unique_id "agHPyklOQjdcFsDF9lbx4wAAAFE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-11 04:21:11
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 67.205.173.206 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 67.205.173.206 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon May 11 00:21:04.646969 2026] [security2:error] [pid 6655:tid 6655] [client 67.205.173.206:34210] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.mlsdirect.xyz"] [uri "/.env.development"] [unique_id "agFZMA6KV9m2E0QfrxBepQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-10 22:31:14
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 67.205.173.206 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 67.205.173.206 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 10 18:31:06.578848 2026] [security2:error] [pid 20897:tid 20897] [client 67.205.173.206:35848] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.carmel.xyz"] [uri "/config/.env"] [unique_id "agEHKs8zVdR_SSa2FBdPwwAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
itsnixk
2026-05-10 17:16:24
(3 months ago)
(mod_security) mod_security (id:930130) triggered by 67.205.173.206 (US/United States/-): 1 in the l ...
show more
(mod_security) mod_security (id:930130) triggered by 67.205.173.206 (US/United States/-): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_TRIGGER; Logs: [Sun May 10 13:16:23.059478 2026] [security2:error] [pid 11356:tid 11780] [client 67.205.173.206:39172] ModSecurity: Access denied with code 406 (phase 1). Matched phrase ".env" at REQUEST_FILENAME. [file "/etc/modsecurity.d/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "150"] [id "930130"] [msg "Restricted File Access Attempt"] [redacted] [severity "CRITICAL"] [ver "OWASP_CRS/4.25.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/ATTACK-LFI"] [tag "capec/1000/255/153/126"] [redacted] [uri "/backend/.env"] [unique_id "agC9Z4ZnLCtmir_j_bPptQAAANw"]
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-05-10 15:41:36
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 67.205.173.206 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 67.205.173.206 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 10 11:41:30.658416 2026] [security2:error] [pid 13089:tid 13089] [client 67.205.173.206:34280] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.whatifandwhynot.xyz"] [uri "/.env.swp"] [unique_id "agCnKtFuM6Qa7EAUgBY8kAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
piticu iuli
2026-05-10 11:57:20
(3 months ago)
(mod_security) mod_security triggered on hostname [redacted] 67.205.173.206 (US/United States/-)
SQL Injection
๐บ๐ธ
TPI-Abuse
2026-05-10 10:27:51
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 67.205.173.206 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 67.205.173.206 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 10 06:27:43.746147 2026] [security2:error] [pid 7085:tid 7085] [client 67.205.173.206:49314] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.drgas.xyz"] [uri "/backend/.env"] [unique_id "agBdnxEaC4G_E81h0pLYjQAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
VanKoh
2026-05-10 09:36:34
(3 months ago)
67.205.173.206 - - [10/May/2026:03:36:27 -0600] "GET / HTTP/1.1" 200 43775 "-" "Mozilla/5.0 (Windows ...
show more
67.205.173.206 - - [10/May/2026:03:36:27 -0600] "GET / HTTP/1.1" 200 43775 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 Chrome/131.0.0.0 Safari/537.36"
67.205.173.206 - - [10/May/2026:03:36:34 -0600] "GET /backend/.env HTTP/1.1" 404 548 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 Chrome/131.0.0.0 Safari/537.36"
67.205.173.206 - - [10/May/2026:03:36:34 -0600] "GET /.env.save HTTP/1.1" 404 548 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 Chrome/131.0.0.0 Safari/537.36"
...
show less
DDoS Attack
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-10 09:10:14
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 67.205.173.206 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 67.205.173.206 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 10 05:10:10.759730 2026] [security2:error] [pid 6783:tid 6783] [client 67.205.173.206:39166] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.kdgsf.xyz"] [uri "/.env.bak"] [unique_id "agBLcndT8V4c2RaZwHePWQAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
antivoid.xyz
2026-05-10 08:03:09
(3 months ago)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-10 05:20:52
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 67.205.173.206 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 67.205.173.206 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 10 01:20:45.634676 2026] [security2:error] [pid 9882:tid 9882] [client 67.205.173.206:45958] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.neuromancer.xyz"] [uri "/.env.swp"] [unique_id "agAVrap5b_2YeP1Rn5rKAAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
AWW-Admin
2026-05-09 04:43:37
(3 months ago)
(mod_security) mod_security triggered on hostname [redacted] 67.205.173.206 (US/United States/-)
SQL Injection
๐บ๐ธ
gamabe
2026-05-08 11:25:36
(3 months ago)
Detected crowdsecurity/http-sensitive-files attack pattern. Reported by CrowdSec IDS.
Hacking
๐บ๐ธ
Matthew Ping
2026-05-08 03:00:01
(3 months ago)
ModSecurity rule 949110 triggered on wp2. Web application attack blocked by CSF/LFD.
Web App Attack
Hacking