๐บ๐ธ
TPI-Abuse
2026-08-23 05:36:21
(8 minutes ago)
(mod_security) mod_security (id:210492) triggered by 104.28.219.35 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.28.219.35 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 23 01:36:15.793353 2026] [security2:error] [pid 17425:tid 17425] [client 104.28.219.35:32553] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "dwipapuri-abadi.com"] [uri "/.env"] [unique_id "aoqGz0VPQJzlOj8yCjFy5gAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-23 04:46:15
(58 minutes ago)
Bot / scanning and/or hacking attempts: GET /.env HTTP/1.1
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-23 04:41:18
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 104.28.219.35 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.28.219.35 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 23 00:41:12.535492 2026] [security2:error] [pid 21345:tid 21397] [client 104.28.219.35:32702] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "djkirby.com"] [uri "/.env"] [unique_id "aop56Jx1JpG8IGvJ1fLT7AAAAIY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฒ๐ฝ
octageeks.com
2026-08-23 04:15:46
(1 hour ago)
Wordpress malicious attack:[octablocked]
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-23 03:57:15
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 104.28.219.35 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.28.219.35 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 23:57:11.702750 2026] [security2:error] [pid 23919:tid 23919] [client 104.28.219.35:32340] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "dshgraphics.com"] [uri "/.env"] [unique_id "aopvl739g3WTy0sNuA1OAgAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-23 03:19:21
(2 hours ago)
(mod_security) mod_security (id:949110) triggered by 104.28.219.35 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:949110) triggered by 104.28.219.35 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 23:19:14.378027 2026] [security2:error] [pid 24914:tid 24914] [client 104.28.219.35:32597] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "dplmat.com"] [uri "/.env"] [unique_id "aopmsiLgEdCIqniXejgVdgAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-23 02:49:53
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.28.219.35 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.28.219.35 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 22:49:47.905630 2026] [security2:error] [pid 18654:tid 18654] [client 104.28.219.35:32471] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "dwightbrown.com"] [uri "/.env"] [unique_id "aopfy-_HJVtcm4niGzq0KgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob
2026-08-22 23:26:27
(6 hours ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /.env
show less
Hacking
Web App Attack
๐ฌ๐ง
thetomtaylor.co.uk
2026-08-22 21:08:01
(8 hours ago)
Fail2Ban - [WEB]Custom exploit pattern detected on customexploits ... [ice01,ice02,wa01,wa02]
Hacking
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-22 20:19:19
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.28.219.35 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.28.219.35 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 16:19:13.721587 2026] [security2:error] [pid 26381:tid 26381] [client 104.28.219.35:32293] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "drxcontent.com"] [uri "/.env"] [unique_id "aooEQcAXRJzkctXy7_G7LQAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-22 17:13:39
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.28.219.35 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.28.219.35 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 13:13:35.678569 2026] [security2:error] [pid 1805:tid 1805] [client 104.28.219.35:32367] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "drhoss.com"] [uri "/.env"] [unique_id "aonYv6-Kw_dcG6RIHaZWvQAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-22 14:16:24
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.28.219.35 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.28.219.35 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 10:16:19.331783 2026] [security2:error] [pid 26032:tid 26032] [client 104.28.219.35:32269] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "dpcfab.com"] [uri "/.env"] [unique_id "aomvM9JpVljAw57qZdcpvQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
CoreTech srl
2026-08-20 12:53:56
(2 days ago)
cloudlinux2 fail2ban: 2026-08-20 14:49:39,058 fail2ban.actions [1468]: NOTICE [plesk-modsecu ...
show more
cloudlinux2 fail2ban: 2026-08-20 14:49:39,058 fail2ban.actions [1468]: NOTICE [plesk-modsecurity] Unban 103.192.157.228cloudlinux2 fail2ban: 2026-08-20 14:50:44,696 fail2ban.filter [1468]: INFO [plesk-wordpress] Found 193.36.225.231 - 2026-08-20 14:50:44cloudlinux2 fail2ban: 2026-08-20 14:52:26,829 fail2ban.filter [1468]: INFO [plesk-wordpress] Found 136.144.35.165 - 2026-08-20 14:52:26cloudlinux2 fail2ban: 2026-08-20 14:52:36,357 fail2ban.filter [1468]: INFO [plesk-proftpd] Found 104.28.219.35 - 2026-08-20 14:52:36cloudlinux2 fail2ban: 2026-08-20 14:52:42,915 fail2ban.filter [1468]: INFO [plesk-proftpd] Found 104.28.219.35 - 2026-08-20 14:52:42cloudlinux2 fail2ban: 2026-08-20 14:53:14,486 fail2ban.filter [1468]: INFO [plesk-modsecurity] Found 35.243.229.176 - 2026-08-20 14:53:14cloudlinux2 fail2ban: 2026-08-20 14:53:14,227 fail2ban.filter [1468]: INFO [plesk-modsecurity] Found 35.243.229.176 - 2026-08-20 14:53:14cloudlinux2 fail2ban: 2
show less
FTP Brute-Force
Web App Attack
Anonymous
2026-08-19 06:30:02
(3 days ago)
28x FTP auth failed (on 2 different accounts)
FTP Brute-Force
Anonymous
2026-08-19 00:06:24
(4 days ago)
Trying to access config files
Web App Attack