๐ธ๐ฐ
EVISION
2026-05-19 01:09:49
(3 weeks ago)
Automatic report from EV firewall log.
https://github.com/Ragnarocek/Windows_FW_AbuseIPDB_Reporti ...
show more
Automatic report from EV firewall log.
https://github.com/Ragnarocek/Windows_FW_AbuseIPDB_Reporting ID: LAAbpqqn1DtMa1SLMUXUQfxFoEIQeGba
show less
Port Scan
Hacking
Brute-Force
๐ณ๐ฑ
homeshowdomain.nl
2026-05-15 22:00:53
(3 weeks ago)
Auto-ban: >3000 req/min op 2026-05-15
Web App Attack
SSH
Hacking
๐น๐ท
baku.hosting
2026-05-15 10:19:53
(3 weeks ago)
CSF Auto Report: (mod_security) mod_security (id:949110) triggered by 34.182.167.245 (US/United Stat ...
show more
CSF Auto Report: (mod_security) mod_security (id:949110) triggered by 34.182.167.245 (US/United States/245.167.182.34.bc.googleusercontent.com): 5 in the last 3600 secs
show less
Brute-Force
Web App Attack
๐ฆ๐บ
screwlooseit.com.au
2026-05-15 10:04:10
(3 weeks ago)
Blocked by CSF 13 firewall - Rule: config-dotfile
US/United States/245.167.182.34.bc.googleuserconte ...
show more
Blocked by CSF 13 firewall - Rule: config-dotfile
US/United States/245.167.182.34.bc.googleusercontent.com
show less
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-05-15 08:15:39
(3 weeks ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐ฌ๐ง
consul.to
2026-05-15 06:18:45
(3 weeks ago)
Web attack/malicious scanning detected
Web App Attack
๐จ๐ญ
4server
2026-05-15 02:40:07
(3 weeks ago)
[FriMay1504:40:04.0691542026][security2:error][pid2879212:tid2879250][client34.182.167.245:0]ModSecu ...
show more
[FriMay1504:40:04.0691542026][security2:error][pid2879212:tid2879250][client34.182.167.245:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\".env\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"364\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"nexxa.ch.81-17-25-250.cpanel.site\"][uri\"/.env.development.local\"][unique_id\"agaHhPz70cEV_kub73lLugAAABE\"]
show less
Hacking
Web App Attack
Anonymous
2026-05-15 02:23:17
(3 weeks ago)
(caddyscan) Scanner path probe from 34.182.167.245 (US/United States/245.167.182.34.bc.googleusercon ...
show more
(caddyscan) Scanner path probe from 34.182.167.245 (US/United States/245.167.182.34.bc.googleusercontent.com): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 2627 34.182.167.245 - - [15/May/2026:02:23:12 +0000] "GET /admin/.env HTTP/1.1"
[REDACTED] 200 2627 34.182.167.245 - - [15/May/2026:02:23:12 +0000] "GET /app/.env.local HTTP/1.1"
[REDACTED] 200 2627 34.182.167.245 - - [15/May/2026:02:23:12 +0000] "GET /api/.env HTTP/1.1"
[REDACTED] 200 2627 34.182.167.245 - - [15/May/2026:02:23:12 +0000] "GET /.env.docker HTTP/1.1"
[REDACTED] 200 2627 34.182.167.245 - - [15/May/2026:02:23:12 +0000] "GET /.env.local HTTP/1.1"
show less
Port Scan
Anonymous
2026-05-15 01:48:08
(3 weeks ago)
(caddyscan) Scanner path probe from 34.182.167.245 (US/United States/245.167.182.34.bc.googleusercon ...
show more
(caddyscan) Scanner path probe from 34.182.167.245 (US/United States/245.167.182.34.bc.googleusercontent.com): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 2627 34.182.167.245 - - [15/May/2026:01:48:06 +0000] "GET /.env.local HTTP/1.1"
[REDACTED] 200 2627 34.182.167.245 - - [15/May/2026:01:48:06 +0000] "GET /admin/.env HTTP/1.1"
[REDACTED] 200 2627 34.182.167.245 - - [15/May/2026:01:48:06 +0000] "GET /.env HTTP/1.1"
[REDACTED] 200 2627 34.182.167.245 - - [15/May/2026:01:48:06 +0000] "GET /app/.env HTTP/1.1"
[REDACTED] 200 2627 34.182.167.245 - - [15/May/2026:01:48:06 +0000] "GET /api/.env HTTP/1.1"
show less
Port Scan
Anonymous
2026-05-15 01:32:15
(3 weeks ago)
(caddyscan) Scanner path probe from 34.182.167.245 (US/United States/245.167.182.34.bc.googleusercon ...
show more
(caddyscan) Scanner path probe from 34.182.167.245 (US/United States/245.167.182.34.bc.googleusercontent.com): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 2627 34.182.167.245 - - [15/May/2026:01:32:10 +0000] "GET /app/.env HTTP/1.1"
[REDACTED] 200 2627 34.182.167.245 - - [15/May/2026:01:32:10 +0000] "GET /.env HTTP/1.1"
[REDACTED] 200 2627 34.182.167.245 - - [15/May/2026:01:32:10 +0000] "GET /.env.docker HTTP/1.1"
[REDACTED] 200 2627 34.182.167.245 - - [15/May/2026:01:32:10 +0000] "GET /api/.env HTTP/1.1"
[REDACTED] 200 2627 34.182.167.245 - - [15/May/2026:01:32:10 +0000] "GET /admin/.env HTTP/1.1"
show less
Port Scan
Anonymous
2026-05-15 00:16:08
(3 weeks ago)
(caddyscan) Scanner path probe from 34.182.167.245 (US/United States/245.167.182.34.bc.googleusercon ...
show more
(caddyscan) Scanner path probe from 34.182.167.245 (US/United States/245.167.182.34.bc.googleusercontent.com): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 2627 34.182.167.245 - - [15/May/2026:00:16:08 +0000] "GET /admin/.env HTTP/1.1"
[REDACTED] 200 2627 34.182.167.245 - - [15/May/2026:00:16:08 +0000] "GET /.env HTTP/1.1"
[REDACTED] 200 2627 34.182.167.245 - - [15/May/2026:00:16:08 +0000] "GET /.env.local HTTP/1.1"
[REDACTED] 200 2627 34.182.167.245 - - [15/May/2026:00:16:08 +0000] "GET /api/.env HTTP/1.1"
[REDACTED] 200 2627 34.182.167.245 - - [15/May/2026:00:16:08 +0000] "GET /.env.dev HTTP/1.1"
show less
Port Scan
Anonymous
2026-05-14 22:45:02
(3 weeks ago)
suspicious request in access.log
Web App Attack
๐บ๐ธ
mnsf
2026-05-14 22:05:32
(3 weeks ago)
Scanning/Probing (20)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-14 19:08:43
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 34.182.167.245 (245.167.182.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.182.167.245 (245.167.182.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 14 15:08:36.296541 2026] [security2:error] [pid 14033:tid 14037] [client 34.182.167.245:42228] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.agrigrailtech.com"] [uri "/.env.docker"] [unique_id "agYdtMh7lgvZ771dRIHc0AAAAMI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
XICTRON
2026-05-14 18:55:03
(3 weeks ago)
ModSecurity rule violation detected by Fail2Ban
Web App Attack