๐ฆ๐บ
paulshipley.com.au
2026-06-03 13:32:31
(21 hours ago)
[Wed Jun 03 23:32:30.310923 2026] [security2:error] [pid 385784] [client 82.25.96.232:61220] [client ...
show more
[Wed Jun 03 23:32:30.310923 2026] [security2:error] [pid 385784] [client 82.25.96.232:61220] [client 82.25.96.232] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/modsecurity/crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "whoson2day.com"] [uri "/.env"] [unique_id "aiAs7ji_0sm32xPNoxCAxwAAAA4"]
...
show less
Web App Attack
๐ซ๐ท
masterguru
2026-06-03 12:32:59
(22 hours ago)
Restricted File Access Attempt. Matched phrase ".env" at REQUEST_FILENAME. (930130-196)
Hacking
Web App Attack
๐ซ๐ท
masterguru
2026-06-03 10:51:31
(1 day ago)
Restricted File Access Attempt. Matched phrase ".env" at REQUEST_FILENAME. (930130-201)
Hacking
Web App Attack
๐ฎ๐น
www.tana.it
2026-06-03 08:29:18
(1 day ago)
PHP scan
Web App Attack
๐ฉ๐ช
paissangroup
2026-06-03 04:42:51
(1 day ago)
Multiple WAF Violations
Web App Attack
๐น๐ท
baku.hosting
2026-06-03 02:02:24
(1 day ago)
CSF Auto Report: (mod_security) mod_security (id:949110) triggered by 82.25.96.232 (DE/Germany/-): 5 ...
show more
CSF Auto Report: (mod_security) mod_security (id:949110) triggered by 82.25.96.232 (DE/Germany/-): 5 in the last 3600 secs
show less
Brute-Force
Web App Attack
๐ซ๐ท
โจ
2026-06-03 01:57:12
(1 day ago)
Domain : sherwoods.uk.com
Rule : WEB
IP in black list
Port Scan
Anonymous
2026-06-03 01:53:29
(1 day ago)
(caddyscan) Scanner path probe from 82.25.96.232 (DE/Germany/-): 5 in the last 3600 secs; Ports: *; ...
show more
(caddyscan) Scanner path probe from 82.25.96.232 (DE/Germany/-): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 2627 82.25.96.232 - - [03/Jun/2026:01:53:24 +0000] "GET /core/.env HTTP/1.1"
[REDACTED] 200 2627 82.25.96.232 - - [03/Jun/2026:01:53:24 +0000] "GET /.env HTTP/1.1"
[REDACTED] 200 2627 82.25.96.232 - - [03/Jun/2026:01:53:24 +0000] "GET /dev/.env HTTP/1.1"
[REDACTED] 200 2627 82.25.96.232 - - [03/Jun/2026:01:53:24 +0000] "GET /backend/.env HTTP/1.1"
[REDACTED] 200 2627 82.25.96.232 - - [03/Jun/2026:01:53:24 +0000] "GET /admin/.env HTTP/1.1"
show less
Port Scan
๐ง๐ท
Halux
2026-06-03 01:37:45
(1 day ago)
82.25.96.232 Web Application Firewall multiple violations
Hacking
Web App Attack
๐ฒ๐พ
Rizzy
2026-06-02 20:40:43
(1 day ago)
Multiple WAF Violations
Brute-Force
Web App Attack
Anonymous
2026-06-02 14:15:06
(1 day ago)
(caddyscan) Scanner path probe from 82.25.96.232 (DE/Germany/-): 5 in the last 3600 secs; Ports: *; ...
show more
(caddyscan) Scanner path probe from 82.25.96.232 (DE/Germany/-): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 301 375 82.25.96.232 - - [02/Jun/2026:14:15:06 +0000] "GET /api/.env HTTP/1.1"
[REDACTED] 301 378 82.25.96.232 - - [02/Jun/2026:14:15:06 +0000] "GET /member/.env HTTP/1.1"
[REDACTED] 301 371 82.25.96.232 - - [02/Jun/2026:14:15:06 +0000] "GET /.env HTTP/1.1"
[REDACTED] 301 375 82.25.96.232 - - [02/Jun/2026:14:15:06 +0000] "GET /new/.env HTTP/1.1"
[REDACTED] 301 375 82.25.96.232 - - [02/Jun/2026:14:15:06 +0000] "GET /dev/.env HTTP/1.1"
show less
Port Scan
๐ซ๐ท
masterguru
2026-06-02 14:03:19
(1 day ago)
Restricted File Access Attempt. Matched phrase ".env" at REQUEST_FILENAME. (930130-197)
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-02 11:12:36
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 82.25.96.232 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 82.25.96.232 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 02 07:12:28.657610 2026] [security2:error] [pid 30629:tid 30629] [client 82.25.96.232:32356] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "wisdomsco.com"] [uri "/core/.env"] [unique_id "ah66nFU5OjJ3ECXPR03C_AAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-02 08:41:42
(2 days ago)
82.25.96.232 - - [02/Jun/2026:10:41:42 +0200] "GET /.env HTTP/1.1" 301 169 "-" "Mozilla/5.0 (Macinto ...
show more
82.25.96.232 - - [02/Jun/2026:10:41:42 +0200] "GET /.env HTTP/1.1" 301 169 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.124 Safari/537.36"
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-02 08:23:37
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 82.25.96.232 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 82.25.96.232 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 02 04:23:31.307727 2026] [security2:error] [pid 18035:tid 18035] [client 82.25.96.232:20742] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "printorganic.com"] [uri "/admin/.env"] [unique_id "ah6TA_hXc96oj6-Sj_kCFgAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack