๐บ๐ธ
TPI-Abuse
2026-09-01 20:19:10
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 69.30.247.59 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 69.30.247.59 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 16:19:04.638238 2026] [security2:error] [pid 4593:tid 4593] [client 69.30.247.59:40848] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "hendersonhomes.com"] [uri "/.env"] [unique_id "apczOIwqNhQROauxNKAZeQAAACk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
thesimonmanuel
2026-09-01 20:14:06
(9 hours ago)
2026/09/02 01:44:05 [error] 1664561#1664561: *338963 access forbidden by rule, client: 69.30.247.59, ...
show more
2026/09/02 01:44:05 [error] 1664561#1664561: *338963 access forbidden by rule, client: 69.30.247.59, server: connect.[redacted].com, request: "GET /.env.local HTTP/1.1", host: "connect.[redacted].com"
2026/09/02 01:44:06 [error] 1664561#1664561: *338963 access forbidden by rule, client: 69.30.247.59, server: connect.[redacted].com, request: "GET /.git/config HTTP/1.1", host: "connect.[redacted].com"
2026/09/02 01:44:05 [error] 1664561#1664561: *338963 access forbidden by rule, client: 69.30.247.59, server: connect.[redacted].com, request: "GET /.env.local HTTP/1.1", host: "connect.[redacted].com"
show less
Port Scan
Web App Attack
๐ฉ๐ช
big-cloud.nl
2026-09-01 19:18:31
(10 hours ago)
Try to access /.env
Web App Attack
๐บ๐ธ
MPL
2026-09-01 12:40:38
(16 hours ago)
tcp/443 (2 or more attempts)
Port Scan
๐ฎ๐ฉ
soc-yk
2026-08-29 21:06:18
(3 days ago)
Type: suspicious_network_activity
Risk: 79
Events: 28
Evidence:
- Persistent suspicious network act ...
show more
Type: suspicious_network_activity
Risk: 79
Events: 28
Evidence:
- Persistent suspicious network activity detected
- Repeated hostile operational behavior observed
- Threat escalation behavior observed
show less
Port Scan
Hacking
๐ฉ๐ช
Reinhard
2026-08-29 19:28:17
(3 days ago)
Unknown activity, but too many attacks with too many users.
Hacking
๐บ๐ธ
rdpguard.com
2026-08-29 19:27:24
(3 days ago)
RdpGuard detected brute-force attempt on HTTP
Brute-Force
๐ฎ๐ฑ
spd.co.il
2026-08-28 15:03:19
(4 days ago)
Web application attack detected
Hacking
Web App Attack
๐ฟ๐ฆ
conure.sh
2026-08-28 12:14:48
(4 days ago)
csagent: score 20.4: secrets grab x2, 404 noise floor x2; 1 domain(s) in 1s
Web App Attack
๐บ๐ธ
mnsf
2026-08-26 18:05:14
(6 days ago)
Abuse Detected (10)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-26 18:02:02
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 69.30.247.59 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 69.30.247.59 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 14:01:56.614882 2026] [security2:error] [pid 13433:tid 13433] [client 69.30.247.59:45956] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.genevainvestors.com"] [uri "/privacy-policy/.env"] [unique_id "ao8qFHjO1Zbp8WlAtv1KMgAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-26 17:30:03
(6 days ago)
suspicious request in access.log
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-26 17:01:36
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 69.30.247.59 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 69.30.247.59 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 13:01:30.438638 2026] [security2:error] [pid 5240:tid 5240] [client 69.30.247.59:52208] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.aabondwnc.com"] [uri "/henderson/.env"] [unique_id "ao8b6sO0PyPSCUgIiPxvOQAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
paissangroup
2026-08-26 16:47:26
(6 days ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-26 16:02:10
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 69.30.247.59 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 69.30.247.59 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 12:02:02.318191 2026] [security2:error] [pid 25898:tid 25898] [client 69.30.247.59:58322] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "aupapierjaponais.com"] [uri "/index.php/.env"] [unique_id "ao8N-g4G9vKcPyWboZZxPwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack