🇨🇳
primal
2026-08-16 10:30:00
(1 week ago)
Automated attack traffic against a WordPress site: CDN web firewall rule triggered (1x). Blocked by ...
show more
Automated attack traffic against a WordPress site: CDN web firewall rule triggered (1x). Blocked by CDN/WAF/application security layers. Total 1 hits in last 30 days.
show less
Web App Attack
Anonymous
2026-08-15 04:34:36
(2 weeks ago)
Failed login attempt detected by Fail2Ban in plesk-modsecurity jail
Exploited Host
🇦🇺
Klaverstyn
2026-08-12 00:44:53
(2 weeks ago)
Persistent attacker, repeat offender
Hacking
🇳🇱
homeshowdomain.nl
2026-08-11 21:59:28
(2 weeks ago)
Auto-ban: >3000 req/min op 2026-08-11
Web App Attack
SSH
Hacking
🇧🇪
cmbplf
2026-08-11 05:38:06
(2 weeks ago)
198 requests with url.path *.aws/*
152 requests with url.path *credentials.json
Brute-Force
Bad Web Bot
🇳🇱
e.fierstra
2026-08-11 02:24:23
(2 weeks ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-11 02:11:20
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 107.167.181.162 (162.181.167.107.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 107.167.181.162 (162.181.167.107.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 10 22:11:15.585941 2026] [security2:error] [pid 944654:tid 944654] [client 107.167.181.162:9472] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "calendar.jefflowenstein.com"] [uri "/@fs/../.env"] [unique_id "anqEwysIcppuiAnv7kJhPQAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
Ba-Yu
2026-08-11 01:52:09
(2 weeks ago)
General hacking/exploits/scanning
Web Spam
Hacking
Brute-Force
Exploited Host
Web App Attack
🇺🇸
TPI-Abuse
2026-08-11 01:25:45
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 107.167.181.162 (162.181.167.107.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 107.167.181.162 (162.181.167.107.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 10 21:25:37.062539 2026] [security2:error] [pid 1961226:tid 1961226] [client 107.167.181.162:48200] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.gdg1.com"] [uri "/media../.env"] [unique_id "anp6ERH-fhriXkK0eNPnaQAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-11 01:09:57
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 107.167.181.162 (162.181.167.107.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 107.167.181.162 (162.181.167.107.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 10 21:09:49.458631 2026] [security2:error] [pid 316289:tid 316289] [client 107.167.181.162:63988] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.inquisitivequincie.com"] [uri "/static../.env"] [unique_id "anp2XSU4Jfz-LcJg9P337AAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-11 00:22:46
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 107.167.181.162 (162.181.167.107.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 107.167.181.162 (162.181.167.107.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 10 20:22:42.117470 2026] [security2:error] [pid 3384327:tid 3384327] [client 107.167.181.162:27058] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.aviil.net"] [uri "/static../.env"] [unique_id "anprUjiJMHvfP1HREkboBwAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-10 23:53:54
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 107.167.181.162 (162.181.167.107.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 107.167.181.162 (162.181.167.107.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 10 19:53:49.436211 2026] [security2:error] [pid 12825:tid 12879] [client 107.167.181.162:2192] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.aisapy.com"] [uri "/media../.env"] [unique_id "anpkjQOAJFuZWY_C02ULqAAAAFQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇦🇺
Klaverstyn
2026-08-10 23:52:48
(2 weeks ago)
Excessive HTTP request rate
Web App Attack
🇩🇪
ger-stg-sifi1
2026-08-10 22:53:47
(2 weeks ago)
(wordpress) Failed wordpress login using wp-login.php or xmlrpc.php
Web App Attack
🇺🇸
CDO
2026-08-10 22:41:45
(2 weeks ago)
URL Injection attempt detected. Automated web attack.
Hacking
Bad Web Bot
Web App Attack