Anonymous
2026-07-20 16:31:43
(2 days ago)
Failed login attempt detected by Fail2Ban in plesk-modsecurity jail
Exploited Host
๐ฒ๐ฝ
octageeks.com
2026-07-18 04:13:13
(5 days ago)
Wordpress malicious attack:[octablocked]
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-17 16:26:10
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 14.116.184.216 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 14.116.184.216 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 17 12:26:04.330446 2026] [security2:error] [pid 3829:tid 3829] [client 14.116.184.216:41811] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.tours.enchantmenttours.com"] [uri "/.env.local"] [unique_id "alpXnJYFlxXLpIp7wznznwAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob
2026-07-17 16:04:15
(5 days ago)
CrowdSec: crowdsecurity/http-sensitive-files | req: /.env.prod | 5 distinct paths | UA: Mozilla/5.0 ...
show more
CrowdSec: crowdsecurity/http-sensitive-files | req: /.env.prod | 5 distinct paths | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/136.0.0.0 Safari/537.36 (Silvy X Ran; +https://silvyxran.love;
show less
Hacking
๐บ๐ธ
TPI-Abuse
2026-07-17 13:58:10
(5 days ago)
(mod_security) mod_security (id:949110) triggered by 14.116.184.216 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:949110) triggered by 14.116.184.216 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 17 09:58:06.034463 2026] [security2:error] [pid 892025:tid 892025] [client 14.116.184.216:45740] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "www.weddingb.trophiesetc.us"] [uri "/.env.sample"] [unique_id "alo07ty_JZIRy29q8n-vmQAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-17 13:27:22
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 14.116.184.216 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 14.116.184.216 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 17 09:27:16.310459 2026] [security2:error] [pid 12263:tid 12263] [client 14.116.184.216:32942] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.wandathelittlestwizard.dvdmasters.com"] [uri "/.env"] [unique_id "alottAtsMxxurUEpw-Se9QAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-17 11:47:23
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 14.116.184.216 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 14.116.184.216 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 17 07:47:19.408685 2026] [security2:error] [pid 25862:tid 25862] [client 14.116.184.216:36968] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "grayhost.net"] [uri "/.env.staging"] [unique_id "aloWRwHjUkQHj3DbHf5-dAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-17 10:57:15
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 14.116.184.216 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 14.116.184.216 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 17 06:57:09.398382 2026] [security2:error] [pid 10224:tid 10224] [client 14.116.184.216:49688] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "brexitop.com"] [uri "/.env~"] [unique_id "aloKhTg7Qf5iKPQyYQORoAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-17 10:34:46
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 14.116.184.216 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 14.116.184.216 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 17 06:34:39.364168 2026] [security2:error] [pid 31320:tid 31320] [client 14.116.184.216:46704] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "hesterpark.braunfamily.info"] [uri "/.env.production"] [unique_id "aloFP8T6erVppMBuvSa4dAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-17 10:20:03
(5 days ago)
| [Dangerous/China] Aggressive IP 14.116.184.216 (~30 hits). Type: DoS Defender- Web server 400 erro ...
show more
| [Dangerous/China] Aggressive IP 14.116.184.216 (~30 hits). Type: DoS Defender- Web server 400 error code
show less
Web App Attack
Hacking
SQL Injection
๐บ๐ธ
TPI-Abuse
2026-07-17 09:56:15
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 14.116.184.216 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 14.116.184.216 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 17 05:56:07.302581 2026] [security2:error] [pid 9579:tid 9579] [client 14.116.184.216:60064] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.piperwaite.com.bonefrog.com"] [uri "/.env.production"] [unique_id "aln8N8UDhj4favoQ76seBQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-07-17 09:36:48
(5 days ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-17 09:13:56
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 14.116.184.216 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 14.116.184.216 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 17 05:13:47.254933 2026] [security2:error] [pid 6097:tid 6097] [client 14.116.184.216:59181] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "siedersoft.com.ar.sieder.com"] [uri "/.env"] [unique_id "alnySytoE57ElkTu9i78ygAAACM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-17 08:35:10
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 14.116.184.216 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 14.116.184.216 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 17 04:35:06.135231 2026] [security2:error] [pid 11913:tid 11913] [client 14.116.184.216:39373] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.nowdigitaltalent.com"] [uri "/.env.old"] [unique_id "alnpOo3eI65-Ktz7Uzj2YgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-17 08:09:36
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 14.116.184.216 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 14.116.184.216 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 17 04:09:27.769571 2026] [security2:error] [pid 12712:tid 12758] [client 14.116.184.216:60443] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.oconnorpest2.oconnorpest.biz"] [uri "/.env.bak"] [unique_id "alnjN2C05SpjsVMin89VLwAAAIM"]
show less
Brute-Force
Bad Web Bot
Web App Attack