๐น๐ท
neron
2026-08-03 14:29:43
(2 weeks ago)
CrowdSec blocked: http:exploit detected via OPNsense firewall
Hacking
Web App Attack
๐น๐ท
neron
2026-08-02 08:16:22
(2 weeks ago)
CrowdSec blocked: http:exploit detected via OPNsense firewall
Hacking
Web App Attack
๐น๐ท
neron
2026-07-29 14:19:38
(3 weeks ago)
CrowdSec blocked: http:exploit detected via OPNsense firewall
Hacking
Web App Attack
๐น๐ท
neron
2026-07-27 02:19:46
(3 weeks ago)
CrowdSec blocked: http:exploit detected via OPNsense firewall
Hacking
Web App Attack
๐ฎ๐ณ
evicky2002
2026-07-24 06:00:00
(4 weeks ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
๐ฉ๐ช
Vegascosmetics
2026-07-23 23:58:43
(4 weeks ago)
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after sensitive config/credentials exposure ...
show more
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after sensitive config/credentials exposure probe. Evidence: AttackPattern: /\.env (Match: /.env)
show less
Hacking
Brute-Force
Web App Attack
๐บ๐ธ
conrad10781
2026-07-23 23:21:30
(4 weeks ago)
nginx-dot-env
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-23 12:47:48
(4 weeks ago)
(mod_security) mod_security (id:210492) triggered by 45.131.194.222 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 45.131.194.222 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 23 08:47:44.327533 2026] [security2:error] [pid 2803966:tid 2803966] [client 45.131.194.222:44685] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "gpaarch.com"] [uri "/.env"] [unique_id "amINcMC13up_8XG044jJywAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
BlueWire Hosting
2026-07-23 12:18:13
(4 weeks ago)
Probing websites for vulnerabilities
Web App Attack
๐ฉ๐ช
todix
2026-07-23 11:37:22
(4 weeks ago)
Web App Attack Exploid from 45.131.194.222
Web App Attack
๐ซ๐ท
masterguru
2026-07-23 11:03:12
(4 weeks ago)
Restricted File Access Attempt. Matched phrase ".env" at REQUEST_FILENAME. (930130-195)
Hacking
Web App Attack
๐ฆ๐บ
paulshipley.com.au
2026-07-23 09:29:39
(4 weeks ago)
[Thu Jul 23 19:29:38.390616 2026] [security2:error] [pid 495211] [client 45.131.194.222:36785] [clie ...
show more
[Thu Jul 23 19:29:38.390616 2026] [security2:error] [pid 495211] [client 45.131.194.222:36785] [client 45.131.194.222] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/modsecurity/crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "winesbydesign.com.au"] [uri "/.env"] [unique_id "amHfAiwTUIHCG5iOxGNL5AAAAAA"]
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-23 05:53:05
(4 weeks ago)
(mod_security) mod_security (id:210492) triggered by 45.131.194.222 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 45.131.194.222 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 23 01:52:57.180733 2026] [security2:error] [pid 209190:tid 209190] [client 45.131.194.222:28019] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "adamscott.us"] [uri "/.env"] [unique_id "amGsOTDxnR4t_fflI_w2ZwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-23 05:36:32
(4 weeks ago)
(mod_security) mod_security (id:210492) triggered by 45.131.194.222 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 45.131.194.222 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 23 01:36:29.012344 2026] [security2:error] [pid 2133310:tid 2133310] [client 45.131.194.222:32621] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "infalliblebible.com"] [uri "/.env"] [unique_id "amGoXbnlIUCEf4fM_AUGagAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-23 05:00:58
(4 weeks ago)
(mod_security) mod_security (id:210492) triggered by 45.131.194.222 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 45.131.194.222 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 23 01:00:52.159104 2026] [security2:error] [pid 1622187:tid 1622187] [client 45.131.194.222:20011] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "wingblade.net"] [uri "/.env"] [unique_id "amGgBKdJIlzUdFczHE07KwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack