๐ฉ๐ช
big-cloud.nl
2026-08-28 00:12:48
(23 hours ago)
Try to access /.env
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-08-27 22:00:01
(1 day ago)
Auto-ban: >3000 req/min op 2026-08-27
Web App Attack
SSH
Hacking
๐บ๐ธ
TPI-Abuse
2026-08-27 18:28:44
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 94.154.128.11 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 94.154.128.11 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 14:28:38.410755 2026] [security2:error] [pid 16036:tid 16036] [client 94.154.128.11:57840] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "longhandmedia.com"] [uri "/.env"] [unique_id "apCB1kzMpAmbjk04pcMf-AAAACg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ต๐ฑ
Budyn
2026-08-27 15:11:35
(1 day ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scan ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scanner. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: pma.astropot.store | URI: /.env | UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.5 Safari/605.9.17 | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-08-26 21:59:29
(2 days ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-08-25.
show less
Web App Attack
SSH
Hacking
๐จ๐ญ
backslash
2026-08-25 14:21:01
(3 days ago)
block ruleset bad bot: wordpress scans 82C095539D4FDAF84E2E2FD6B6FC0664645851A8
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-08-25 13:24:30
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 94.154.128.11 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 94.154.128.11 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 09:24:24.834555 2026] [security2:error] [pid 13618:tid 13618] [client 94.154.128.11:35034] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "b2qc.com.anthonyanimalclinic.net"] [uri "/.env"] [unique_id "ao2XiIvBn3Ey9eZ8TKbFjgAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-08-25 11:36:15
(3 days ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
๐ฉ๐ช
EGP Abuse Dept
2026-08-25 10:18:55
(3 days ago)
Scanning for web/db/file exploits on www.verandaworld.nu
SQL Injection
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-25 09:46:06
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 94.154.128.11 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 94.154.128.11 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 05:46:00.881678 2026] [security2:error] [pid 2111:tid 2111] [client 94.154.128.11:48844] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "thebumans.com"] [uri "/.git/config"] [unique_id "ao1kWDf7Q39zLezNuBkrbwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-25 05:41:48
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 94.154.128.11 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 94.154.128.11 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 01:41:39.735543 2026] [security2:error] [pid 1219378:tid 1219505] [client 94.154.128.11:43894] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.destination-kitchen.com"] [uri "/.env"] [unique_id "ao0rE6hAv9q3w9CElHhoCQAAAk8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐ฉ
Burayot
2026-08-25 05:14:42
(3 days ago)
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 94.154.128.11 (UZ/Uzbekistan/-): 2 ...
show more
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 94.154.128.11 (UZ/Uzbekistan/-): 2 in the last 3600 secs
show less
Web App Attack
๐ซ๐ท
masterguru
2026-08-25 04:36:40
(3 days ago)
Restricted File Access Attempt. Matched phrase ".env" at REQUEST_FILENAME. (930130-196)
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-25 04:33:50
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 94.154.128.11 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 94.154.128.11 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 00:33:42.233153 2026] [security2:error] [pid 3544:tid 3544] [client 94.154.128.11:47168] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.usaenquirer.com"] [uri "/.git/config"] [unique_id "ao0bJiRNaa9lLU-QWqDD4gAAAD8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob
2026-08-25 02:15:48
(3 days ago)
Malicious web request: probing for secrets, traversal or a known exploit path | method: GET | path: ...
show more
Malicious web request: probing for secrets, traversal or a known exploit path | method: GET | path: /wp-json/batch/v1 | 2026-08-25 02:15 UTC
show less
Hacking
Web App Attack