๐ฎ๐ฉ
soc-yk
2026-06-06 18:42:15
(3 hours ago)
Type: suspicious_network_activity
Risk: 86
Events: 62
Evidence:
- Persistent suspicious network act ...
show more
Type: suspicious_network_activity
Risk: 86
Events: 62
Evidence:
- Persistent suspicious network activity detected
- Repeated hostile operational behavior observed
- Multi-event operational persistence identified
- Threat escalation behavior observed
show less
Port Scan
Hacking
๐ง๐ช
voormedia
2026-06-06 18:37:47
(3 hours ago)
Accessed trap at '/.env'
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-06 10:55:34
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 80.76.49.250 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 80.76.49.250 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 06 06:55:29.424318 2026] [security2:error] [pid 5304:tid 5304] [client 80.76.49.250:61061] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kountz.org"] [uri "/.env"] [unique_id "aiP8oYCj1mW_hojbPf6LjAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
AvonleaConsulting
2026-06-06 10:19:16
(12 hours ago)
Scanning unused Default website or suspicious access to valid sites from IP marked as abusive
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-06 09:34:17
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 80.76.49.250 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 80.76.49.250 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 06 05:34:11.621318 2026] [security2:error] [pid 18405:tid 18405] [client 80.76.49.250:57611] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "spacerecording.com"] [uri "/.env"] [unique_id "aiPpkzTosYSPFW7B5KVdUAAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
2000cn.com.au
2026-06-06 09:31:19
(12 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-06-06 08:35:21
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 80.76.49.250 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 80.76.49.250 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 06 04:35:15.453645 2026] [security2:error] [pid 24518:tid 24518] [client 80.76.49.250:63812] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.easternimport.com"] [uri "/.env"] [unique_id "aiPbw2Q4EurSv5TAFK7R4gAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-06 08:06:45
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 80.76.49.250 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 80.76.49.250 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 06 04:06:40.330186 2026] [security2:error] [pid 23309:tid 23333] [client 80.76.49.250:62486] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.uoexpanse.com"] [uri "/.env"] [unique_id "aiPVEGgWTlHzdKMTFaDUowAAAVU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-06 07:57:02
(14 hours ago)
80.76.49.250 - - [06/Jun/2026:07:57:01 +0000] "GET /bothole/stinkwell.php?p=%27nvOpzp;%20AND%201=1%2 ...
show more
80.76.49.250 - - [06/Jun/2026:07:57:01 +0000] "GET /bothole/stinkwell.php?p=%27nvOpzp;%20AND%201=1%20OR%20(%3C%27%22%3EiKO)), HTTP/1.1" 307 6394 "https://www.cotswoldclapton.com/viewtopic.php?p=%27nvOpzp;%20AND%201=1%20OR%20(%3C%27%22%3EiKO))," "-"
...
show less
SQL Injection
๐ฎ๐ช
RoboSOC
2026-06-05 22:49:22
(23 hours ago)
HTTP Cross Site Scripting Vulnerability , PTR: PTR record not found
Web App Attack
๐ฎ๐น
alessio loto
2026-06-05 21:19:49
(1 day ago)
WAF Detection: Empty_UserAgent (High Risk IP). AI Confirmed Attack Payload.
Web App Attack
๐จ๐ฟ
ptlab
2026-06-05 20:45:17
(1 day ago)
Detected php_null_array_access attack from WP-host.
Hacking
Web App Attack
๐บ๐ธ
fortypoundhead
2026-06-05 20:06:24
(1 day ago)
Banned IP Address
Hacking
Web App Attack
๐ช๐ธ
el-brujo
2026-06-05 19:51:04
(1 day ago)
Cloudflare WAF: Request Path: /whois.html Request Query: ?domain=%27nvOpzp;%20AND%201=1%20OR%20(%3C% ...
show more
Cloudflare WAF: Request Path: /whois.html Request Query: ?domain=%27nvOpzp;%20AND%201=1%20OR%20(%3C%27%22%3EiKO)), Host: www.elhacker.net userAgent: Action: block Source: firewallManaged ASN Description: 12651980 CANADA INC. Country: US Method: GET Timestamp: 2026-06-05T19:51:04Z ruleId: 8152816062ed47f69be0f907f4bdb492. Report generated by Cloudflare-WAF-to-AbuseIPDB (https://github.com/MHG-LAB/Cloudflare-WAF-to-AbuseIPDB).
show less
Hacking
SQL Injection
Web App Attack
๐ฌ๐ง
SilverZippo
2026-06-05 19:20:42
(1 day ago)
Web App Attack
Web App Attack