๐บ๐ธ
mnsf
2026-09-02 00:05:33
(6 hours ago)
Scanning/Probing (20)
Brute-Force
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-09-01 21:59:18
(8 hours ago)
Auto-ban: >3000 req/min op 2026-09-01
Web App Attack
SSH
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-01 13:53:38
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 8.229.158.62 (62.158.229.8.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 8.229.158.62 (62.158.229.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 09:53:33.408569 2026] [security2:error] [pid 23309:tid 23309] [client 8.229.158.62:41114] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.barecreationsaz.com"] [uri "/.env.backup"] [unique_id "apbY3f_dB-D55RPm7ntIjgAAAEI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Vasile
2026-09-01 13:12:06
(17 hours ago)
Shield Guard: Blocklist: IP signalรฉe (blocklist_de) | Scanner: crusader-worker (+55) | Chemin suspec ...
show more
Shield Guard: Blocklist: IP signalรฉe (blocklist_de) | Scanner: crusader-worker (+55) | Chemin suspect: /.env
show less
Web App Attack
Anonymous
2026-09-01 12:54:55
(17 hours ago)
(mod_security) mod_security triggered on hostname [redacted])
SQL Injection
๐จ๐ญ
zynex
2026-09-01 12:37:37
(17 hours ago)
URL Probing: /wp-config.php.bak
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 11:20:54
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 8.229.158.62 (62.158.229.8.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 8.229.158.62 (62.158.229.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 07:20:47.104891 2026] [security2:error] [pid 5428:tid 5428] [client 8.229.158.62:34806] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.yeswedeliver.org"] [uri "/wp-config.php.swp"] [unique_id "apa1Dze2mawopqr5rwYauQAAAC8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
Apache
2026-09-01 09:27:15
(20 hours ago)
(mod_security) mod_security (id:210492) triggered by 8.229.158.62 (US/United States/62.158.229.8.bc. ...
show more
(mod_security) mod_security (id:210492) triggered by 8.229.158.62 (US/United States/62.158.229.8.bc.googleusercontent.com): 5 in the last 300 secs (CF_ENABLE)
show less
Brute-Force
Web App Attack
๐ฒ๐พ
Rizzy
2026-09-01 08:49:48
(21 hours ago)
Multiple WAF Violations
Brute-Force
Web App Attack
๐ฉ๐ช
Jochen Pretli
2026-09-01 08:47:42
(21 hours ago)
connection to honeypot
Email Spam
Port Scan
Anonymous
2026-09-01 08:32:41
(21 hours ago)
(config_exploit_scan) Configuratie Scanner / Nep GPTBot 8.229.158.62 (US/United States/62.158.229.8. ...
show more
(config_exploit_scan) Configuratie Scanner / Nep GPTBot 8.229.158.62 (US/United States/62.158.229.8.bc.googleusercontent.com): 3 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 8.229.158.62 - - [01/Sep/2026:10:32:38 +0200] "GET /.env.local HTTP/1.1" 406 4831 "-" "crusader-worker/1.0"
8.229.158.62 - - [01/Sep/2026:10:32:38 +0200] "GET /.env.old HTTP/1.1" 406 4831 "-" "crusader-worker/1.0"
8.229.158.62 - - [01/Sep/2026:10:32:38 +0200] "GET /.env.bak HTTP/1.1" 406 4831 "-" "crusader-worker/1.0"
show less
Port Scan
๐ซ๐ท
dynamix
2026-09-01 08:30:50
(21 hours ago)
Multiple WAF Violations
Web App Attack
๐ฌ๐ง
consul.to
2026-09-01 07:49:20
(22 hours ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 07:12:20
(23 hours ago)
(mod_security) mod_security (id:210492) triggered by 8.229.158.62 (62.158.229.8.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 8.229.158.62 (62.158.229.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 03:12:14.724198 2026] [security2:error] [pid 27077:tid 27077] [client 8.229.158.62:35410] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "moontouchmassage.com"] [uri "/.env"] [unique_id "apZ6zsXX8h8pXP52JbKm6gAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฟ๐ฆ
conure.sh
2026-09-01 07:08:44
(23 hours ago)
csagent: score 21.0: 404 noise floor x4, secrets grab x1, wp-config backup grab x1; 1 domain(s) in 0 ...
show more
csagent: score 21.0: 404 noise floor x4, secrets grab x1, wp-config backup grab x1; 1 domain(s) in 0s
show less
Web App Attack