๐ฆ๐บ
paulshipley.com.au
2026-06-03 08:19:09
(1 day ago)
[Wed Jun 03 18:19:09.309334 2026] [security2:error] [pid 361375] [client 72.60.93.10:48676] [client ...
show more
[Wed Jun 03 18:19:09.309334 2026] [security2:error] [pid 361375] [client 72.60.93.10:48676] [client 72.60.93.10] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/modsecurity/crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "mareeshefford.com"] [uri "/api/.env"] [unique_id "ah_jfUphb-UMl7S0WU7tbAAAAAE"]
...
show less
Web App Attack
๐ซ๐ท
Baking333
2026-06-03 03:17:24
(1 day ago)
[redacted] 72.60.93.10 - - [03/Jun/2026:04:17:22 +0100] "GET /api/.env HTTP/1.1" 302 5254 0/140307 " ...
show more
[redacted] 72.60.93.10 - - [03/Jun/2026:04:17:22 +0100] "GET /api/.env HTTP/1.1" 302 5254 0/140307 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.124 Safari/537.36" [redacted] 72.60.93.10 - - [03/Jun/2026:04:17:22 +0100] "GET /core/.env HTTP/1.1" 302 5222 0/144641 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.124 Safari/537.36"
show less
Bad Web Bot
Web App Attack
๐ซ๐ท
Nexia
2026-06-03 02:43:14
(1 day ago)
[SENTINEL-HQ] Sentinel detected Critical Trap on /.env
Web App Attack
๐ณ๐ฑ
debestelapp
2026-06-03 01:30:05
(1 day ago)
Web App Attack
๐บ๐ธ
mw
2026-06-03 00:01:21
(1 day ago)
GET /new/.env HTTP/1.1
Web App Attack
๐ฌ๐ง
Yosi
2026-06-02 23:15:33
(1 day ago)
RdpGuard detected brute-force attempt on HTTP
Brute-Force
Anonymous
2026-06-02 21:35:09
(1 day ago)
Failed login attempt detected by Fail2Ban in plesk-modsecurity jail
Exploited Host
๐ซ๐ท
dynamix
2026-06-02 20:08:33
(1 day ago)
Multiple WAF Violations
Web App Attack
๐ฉ๐ช
LRob.fr
2026-06-02 19:45:02
(1 day ago)
Repeated 404 errors, blocked by Fail2ban in custom-404 jail
Bad Web Bot
๐ฌ๐ง
consul.to
2026-06-02 06:29:40
(2 days ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ธ
Matthew Ping
2026-06-02 03:11:45
(2 days ago)
ModSecurity rule 949110 triggered on wp1. Web application attack blocked by CSF/LFD.
Web App Attack
Hacking
๐บ๐ธ
zwebvigil
2026-06-02 02:43:37
(2 days ago)
72.60.93.10 [01/Jun/2026:19:43:37 -0700] "GET /.env HTTP/1.1" 404 22 "-" port=30484 "Mozilla/5.0 (M ...
show more
72.60.93.10 [01/Jun/2026:19:43:37 -0700] "GET /.env HTTP/1.1" 404 22 "-" port=30484 "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.124 Safari/537.36" "-" "-" "<host>" 4540
72.60.93.10 [01/Jun/2026:19:43:37 -0700] "GET /admin/.env HTTP/1.1" 404 22 "-" port=30476 "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.124 Safari/537.36" "-" "-" "<host>" 5926
72.60.93.10 [01/Jun/2026:19:43:37 -0700] "GET /api/.env HTTP/1.1" 404 22 "-" port=30498 "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.124 Safari/537.36" "-" "-" "<host>" 3900
72.60.93.10 [01/Jun/2026:19:43:37 -0700] "GET /app/.env HTTP/1.1" 404 22 "-" port=30508 "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.124 Safari/537.36" "-" "-" "<host>" 5211
72.60.93.10 [01/J
show less
Web App Attack
Anonymous
2026-06-02 02:19:38
(2 days ago)
Honeytrap
Web App Attack
Hacking
๐ซ๐ท
SpaceHost-Server
2026-06-01 22:35:58
(2 days ago)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-01 19:47:12
(2 days ago)
(mod_security) mod_security (id:949110) triggered by 72.60.93.10 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:949110) triggered by 72.60.93.10 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 01 15:47:09.116667 2026] [security2:error] [pid 27523:tid 27523] [client 72.60.93.10:32516] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "rahmwashservice.com"] [uri "/member/.env"] [unique_id "ah3hvWcE8q1kJoHSU462eQAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack