🇦🇺
Klaverstyn
2026-09-03 14:49:53
(14 minutes ago)
Cross-vhost secrets/RCE probing campaign
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-03 14:35:15
(28 minutes ago)
(mod_security) mod_security (id:210492) triggered by 69.176.89.19 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 69.176.89.19 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 10:35:08.322187 2026] [security2:error] [pid 27607:tid 27607] [client 69.176.89.19:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "betiqos.com"] [uri "/.env"] [unique_id "apmFnLMwuUnUs_kVGL0W1wAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇦🇺
Klaverstyn
2026-09-03 14:18:03
(46 minutes ago)
Repeated 403 Forbidden responses
Web App Attack
Anonymous
2026-09-03 14:02:37
(1 hour ago)
Automatically blocked after 1 security event. Observed sensitive configuration-file probes. Source: ...
show more
Automatically blocked after 1 security event. Observed sensitive configuration-file probes. Source: Cloudflare security controls.
show less
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-03 13:58:51
(1 hour ago)
(mod_security) mod_security (id:949110) triggered by 69.176.89.19 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:949110) triggered by 69.176.89.19 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 09:58:48.430263 2026] [security2:error] [pid 4180:tid 4180] [client 69.176.89.19:51083] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "advancedrentalandservice.com"] [uri "/.env"] [unique_id "apl9GPIZtnbdUf7wjtkYZwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇿
Tripwire
2026-09-03 13:26:40
(1 hour ago)
Scanning for exploits - /.env
Web App Attack
🇺🇸
TPI-Abuse
2026-09-03 12:34:52
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 69.176.89.19 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 69.176.89.19 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 08:34:46.364339 2026] [security2:error] [pid 17748:tid 17748] [client 69.176.89.19:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "local639.com"] [uri "/.env"] [unique_id "aplpZoJ3ZO8hGavVXzJcogAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-03 12:18:14
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 69.176.89.19 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 69.176.89.19 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 08:18:07.724719 2026] [security2:error] [pid 24443:tid 24560] [client 69.176.89.19:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mindgardens.com"] [uri "/.env"] [unique_id "apllf2yf5ZMpbKLB_FHlqgAAAhI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇦🇺
A.i.D.A.N.N
2026-09-03 11:42:47
(3 hours ago)
A.i.D.A.N.N: Anomaly Detected - Signature match Web Service - Web application attack detected
Web App Attack
🇳🇱
exxos
2025-03-03 09:55:20
(1 year ago)
Attacks with Bad user agents
Hacking
🇦🇺
MAGIC
2025-02-27 16:01:43
(1 year ago)
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot
🇩🇪
botreporter
2025-02-24 07:14:18
(1 year ago)
botnet ignoring robots.txt
Bad Web Bot
🇳🇱
exxos
2025-02-23 01:30:45
(1 year ago)
Attacks with Bad user agents
Hacking
🇦🇺
MAGIC
2025-02-20 16:06:02
(1 year ago)
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot
🇨🇭
backslash
2025-02-18 21:25:06
(1 year ago)
block ruleset Badbot using very old user-agents 5CF3CDB778C7D82564405B86B9242E612F378C68
Bad Web Bot