Anonymous
2026-09-06 06:28:25
(1 hour ago)
fail2ban: Sensitive web probes detected
Web App Attack
🇺🇸
mnsf
2026-09-06 04:05:55
(3 hours ago)
Scanning/Probing (20)
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 03:53:44
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.155.99.154 (154.99.155.104.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 104.155.99.154 (154.99.155.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 23:53:37.181188 2026] [security2:error] [pid 681:tid 681] [client 104.155.99.154:45144] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.weddingmatches.com"] [uri "/.env"] [unique_id "apzjwRe-LtdQJ6lFEWgscQAAAIo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 03:33:45
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.155.99.154 (154.99.155.104.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 104.155.99.154 (154.99.155.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 23:33:37.939477 2026] [security2:error] [pid 28990:tid 29013] [client 104.155.99.154:57648] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "pinnaclemgmt.net"] [uri "/.env"] [unique_id "apzfEYnbmbWWpEL5qYYWvQAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
YF
2026-09-06 03:00:12
(4 hours ago)
WordPress config file probe
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 02:56:54
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.155.99.154 (154.99.155.104.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 104.155.99.154 (154.99.155.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 22:56:47.981508 2026] [security2:error] [pid 3925:tid 3925] [client 104.155.99.154:35422] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.interartny.com"] [uri "/wp-config.php~"] [unique_id "apzWb6vEDKRPlZ21h0U2wwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
Octopuce
2026-09-06 02:54:02
(4 hours ago)
Aggressive web search of vulnerable pages: /db.sql /backup.zip /database.sql /backup.tar /backup.sql ...
show more
Aggressive web search of vulnerable pages: /db.sql /backup.zip /database.sql /backup.tar /backup.sql ...
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 01:46:50
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.155.99.154 (154.99.155.104.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 104.155.99.154 (154.99.155.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 21:46:44.740582 2026] [security2:error] [pid 12844:tid 12844] [client 104.155.99.154:49088] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ftp.berksoft.com"] [uri "/.env"] [unique_id "apzGBJJpysdhlPF5K9N0wAAAADI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
GoodOldTOS
2026-09-06 01:40:24
(6 hours ago)
Highly suspect IP
Hacking
Web App Attack
🇦🇺
Bay13
2026-09-06 01:30:25
(6 hours ago)
CrowdSec:custom/http-sensitive-files
Web App Attack
🇩🇪
LRob
2026-09-06 01:24:17
(6 hours ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /wp-config.php.bak (+12 more) | 2026-09-06 01:24 UTC
show less
Hacking
Web App Attack
🇨🇭
4server
2026-09-06 01:19:44
(6 hours ago)
[SunSep0603:19:39.6566062026][security2:error][pid2584230:tid2584518][client104.155.99.154:0]ModSecu ...
show more
[SunSep0603:19:39.6566062026][security2:error][pid2584230:tid2584518][client104.155.99.154:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\".env\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"610\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"swiss-web-hosting.com\"][uri\"/.env\"][unique_id\"apy_q5h8oo2T4ggxHsBEBAAAANU\"]
show less
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 01:09:59
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.155.99.154 (154.99.155.104.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 104.155.99.154 (154.99.155.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 21:09:53.244077 2026] [security2:error] [pid 2158:tid 2158] [client 104.155.99.154:40610] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.goepf.com"] [uri "/.env"] [unique_id "apy9YQ5n4S3_X3TlxcYCkwAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-06 00:41:15
(7 hours ago)
Aggressive web scan
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 00:36:11
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.155.99.154 (154.99.155.104.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 104.155.99.154 (154.99.155.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 20:36:07.735737 2026] [security2:error] [pid 8856:tid 8856] [client 104.155.99.154:54592] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "huddleston.construction.savingshvac.com"] [uri "/.env.production"] [unique_id "apy1d1oPl7hF0qocwj8aHgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack