๐ฉ๐ช
Phenix Info
2026-08-19 03:07:17
(12 hours ago)
SmallGuard.fr - HoneyPot
Web App Attack
๐ธ๐ช
vaia.cloud
2026-08-18 14:35:02
(1 day ago)
crowdsecurity/http-cve-probing
Brute-Force
Web App Attack
๐ฎ๐ณ
evicky2002
2026-08-17 03:44:05
(2 days ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
๐ณ๐ฑ
homeshowdomain.nl
2026-08-16 21:59:03
(2 days ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-08-15.
show less
Web App Attack
SSH
Hacking
๐ฉ๐ช
jocurionline
2026-08-16 01:30:10
(3 days ago)
Auto-blocked by WAF: AUTO-BAN: Sensitive file probe 1 h
Web App Attack
Port Scan
๐ณ๐ฑ
homeshowdomain.nl
2026-08-15 21:59:07
(3 days ago)
Auto-ban: >3000 req/min op 2026-08-15
Web App Attack
SSH
Hacking
๐บ๐ธ
TPI-Abuse
2026-08-15 10:16:12
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 96.0.161.213 (ec2-96-0-161-213.us-west-2.comput ...
show more
(mod_security) mod_security (id:210492) triggered by 96.0.161.213 (ec2-96-0-161-213.us-west-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 15 06:16:05.946344 2026] [security2:error] [pid 13247:tid 13247] [client 96.0.161.213:51093] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "johnandre.org"] [uri "/.env/.env.bak"] [unique_id "aoA8ZWBHMm3HMt3F0jAAhwAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-15 08:47:59
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 96.0.161.213 (ec2-96-0-161-213.us-west-2.comput ...
show more
(mod_security) mod_security (id:210492) triggered by 96.0.161.213 (ec2-96-0-161-213.us-west-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 15 04:47:54.418072 2026] [security2:error] [pid 21133:tid 21267] [client 96.0.161.213:53300] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "joeandlane.com"] [uri "/.env/.env.bak"] [unique_id "aoAnurQAujLjae_-ioMoZQAAARQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
elleray
2026-08-15 08:28:00
(4 days ago)
Apache noscript intrusion Banned by Fail2Ban
Brute-Force
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-08-15 08:04:14
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 96.0.161.213 (ec2-96-0-161-213.us-west-2.comput ...
show more
(mod_security) mod_security (id:210492) triggered by 96.0.161.213 (ec2-96-0-161-213.us-west-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 15 04:04:08.793078 2026] [security2:error] [pid 15768:tid 15768] [client 96.0.161.213:56838] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kaibeth.com"] [uri "/.env/.env.bak"] [unique_id "aoAdeLxG2IW_Zg7mrlywagAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ฆ
Anytech
2026-08-15 07:55:40
(4 days ago)
Blocked by Conn-Monitor: Automated bot activity
Bad Web Bot
Web App Attack
๐บ๐ธ
LotPhantom
2026-08-15 06:36:16
(4 days ago)
2026/08/15 06:36:16 [error] 4005363#4005363: *46229 access forbidden by rule, client: 96.0.161.213, ...
show more
2026/08/15 06:36:16 [error] 4005363#4005363: *46229 access forbidden by rule, client: 96.0.161.213, server: job-search-api.bridginggaps.tech, request: "GET /.env/.env.bak HTTP/1.1", host: "job-search-api.bridginggaps.tech"
...
show less
Web App Attack
๐ฉ๐ช
Viveronese
2026-08-15 05:47:32
(4 days ago)
HTTP vulnerability scanning
Web App Attack
๐บ๐ธ
Keith Beucler
2026-08-15 04:27:57
(4 days ago)
K5 Services fail2ban jail nginx-k5-web-probes detected high-confidence web abuse. Local web ban appl ...
show more
K5 Services fail2ban jail nginx-k5-web-probes detected high-confidence web abuse. Local web ban applied. Categories: 19,21.
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-15 03:52:37
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 96.0.161.213 (ec2-96-0-161-213.us-west-2.comput ...
show more
(mod_security) mod_security (id:210492) triggered by 96.0.161.213 (ec2-96-0-161-213.us-west-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 14 23:52:31.587828 2026] [security2:error] [pid 5652:tid 5652] [client 96.0.161.213:60685] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "k2medianetworks.com"] [uri "/.env/.env.bak"] [unique_id "an_if9aRnR78FlafRPV8sQAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack