๐บ๐ธ
bluebrad
2026-04-26 04:24:50
(4 months ago)
Observed repeated malicious scanning and denied web requests in server logs. Reporting as hostile pr ...
show more
Observed repeated malicious scanning and denied web requests in server logs. Reporting as hostile probing and web attack activity.
show less
Port Scan
Hacking
Bad Web Bot
Web App Attack
๐ต๐ฑ
IROK
2026-04-06 11:17:50
(5 months ago)
Firewall Blocked - Unauthorized Port Scanning
...
Port Scan
๐ฉ๐ช
dbmwebdesign
2026-04-06 10:15:46
(5 months ago)
WAF repeated trigger detected by Fail2Ban in plesk-modsecurity jail
Web App Attack
๐ฉ๐ช
itsolon
2026-04-06 07:03:41
(5 months ago)
[06/Apr/2026:09:03:29 +0200] 177545900951.674488 91.234.6.163 41775 217.154.7.177 443
[06/Apr/2026:0 ...
show more
[06/Apr/2026:09:03:29 +0200] 177545900951.674488 91.234.6.163 41775 217.154.7.177 443
[06/Apr/2026:09:03:30 +0200] 177545901065.385257 91.234.6.163 41775 217.154.7.177 443
[06/Apr/2026:09:03:38 +0200] 177545901888.438902 91.234.6.163 41775 217.154.7.177 443
[06/Apr/2026:09:03:40 +0200] 177545902038.308683 91.234.6.163 41775 217.154.7.177 443
[06/Apr/2026:09:03:40 +0200] 177545902060.751645 91.234.6.163 41775 217.154.7.177 443
...
show less
Port Scan
Hacking
Brute-Force
Web App Attack
๐ช๐ธ
masterguru
2026-04-06 06:16:10
(5 months ago)
Restricted File Access Attempt. Matched phrase "/.env" at REQUEST_FILENAME. (930130-122)
Hacking
Web App Attack
Anonymous
2026-04-06 06:02:03
(5 months ago)
Bot / scanning and/or hacking attempts: GET /actuator/env HTTP/1.1, GET /.git/config HTTP/1.1
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-06 05:49:35
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 91.234.6.163 (dedicated.vsys.host): 1 in the la ...
show more
(mod_security) mod_security (id:210492) triggered by 91.234.6.163 (dedicated.vsys.host): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Apr 06 01:49:31.248552 2026] [security2:error] [pid 3857:tid 3923] [client 91.234.6.163:39525] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.ywt.bestofthis.com"] [uri "/api/.env"] [unique_id "adNJa6MlCBJzHApGCmIL4AAAAUA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-04-06 05:29:21
(5 months ago)
Restricted File Access Attempt. Matched phrase ".env" at REQUEST_FILENAME. (930130-196)
Hacking
Web App Attack
๐บ๐ธ
JustMeHere
2026-04-06 05:27:36
(5 months ago)
[Mon Apr 06 01:27:32.230743 2026] [security2:error] [pid 438466:tid 438571] [client 91.234.6.163:509 ...
show more
[Mon Apr 06 01:27:32.230743 2026] [security2:error] [pid 438466:tid 438571] [client 91.234.6.163:50965] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:blocking_inbound_anomaly_score. [file "/etc/httpd/modsecurity.d/activated_rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "233"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [ver "OWASP_CRS/4.15.0"] [tag "anomaly-evaluation"] [tag "OWASP_CRS"] [hostname "www.yorknation.com"] [uri "/.env.save"] [unique_id "adNERARVUbSEHXa_TwhUvgAAAEM"]
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-06 05:12:54
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 91.234.6.163 (dedicated.vsys.host): 1 in the la ...
show more
(mod_security) mod_security (id:210492) triggered by 91.234.6.163 (dedicated.vsys.host): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Apr 06 01:12:48.278468 2026] [security2:error] [pid 10833:tid 10857] [client 91.234.6.163:38581] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.yellowsunset.com.appraisalteam.net"] [uri "/.env.save"] [unique_id "adNA0BqXBRAMKDaR6ydSgAAAAJY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-04-06 04:47:14
(5 months ago)
Multiple WAF Violations
Web App Attack
๐ฉ๐ช
ger-stg-sifi1
2026-04-06 01:57:25
(5 months ago)
(wordpress) Failed wordpress login using wp-login.php or xmlrpc.php
Web App Attack
๐บ๐ธ
WellSpring
2026-04-06 01:43:23
(5 months ago)
Automated probe detected by Ody Sentinel / WellSpr.ing. Type: env_leak. Path: /backend/.env. Auto-bl ...
show more
Automated probe detected by Ody Sentinel / WellSpr.ing. Type: env_leak. Path: /backend/.env. Auto-blocked after threshold exceeded. Dossier: https://wellspr.ing/dossier/sentinel-91-234-6-163
show less
Web App Attack
๐บ๐ธ
mnsf
2026-04-06 01:06:04
(5 months ago)
Scanning/Probing (20)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-06 01:01:53
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 91.234.6.163 (dedicated.vsys.host): 1 in the la ...
show more
(mod_security) mod_security (id:210492) triggered by 91.234.6.163 (dedicated.vsys.host): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Apr 05 21:01:45.222626 2026] [security2:error] [pid 14028:tid 14028] [client 91.234.6.163:58125] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.whml.jazziientertainment.com"] [uri "/.env.development"] [unique_id "adMF-TWyUXYkOxkC-CdG1AAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack