๐ฒ๐ฝ
octageeks.com
2026-06-03 04:07:48
(3 months ago)
Wordpress malicious attack:[octablocked]
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-02 05:37:18
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 145.79.211.185 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 145.79.211.185 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 02 01:37:13.709712 2026] [security2:error] [pid 3613:tid 3613] [client 145.79.211.185:54728] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "visitcampbellford.com"] [uri "/core/.env"] [unique_id "ah5sCVgQOpQoFtyRgnT5xQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-02 04:51:49
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 145.79.211.185 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 145.79.211.185 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 02 00:51:43.464687 2026] [security2:error] [pid 4925:tid 4925] [client 145.79.211.185:56538] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "breinesberger.com"] [uri "/app/.env"] [unique_id "ah5hX6Mg7RrOuvDxn1woYQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-02 03:11:24
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 145.79.211.185 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 145.79.211.185 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 01 23:11:18.457864 2026] [security2:error] [pid 2177:tid 2177] [client 145.79.211.185:63304] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "brunellecpa.com"] [uri "/core/.env"] [unique_id "ah5J1vRzFBM202FHlpWW9gAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-02 02:05:51
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 145.79.211.185 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 145.79.211.185 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 01 22:05:45.178426 2026] [security2:error] [pid 28637:tid 28637] [client 145.79.211.185:58588] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "vc1.com"] [uri "/core/.env"] [unique_id "ah46efZ_UwuSa89ZHNYplQAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
Matthew Ping
2026-06-02 01:15:26
(3 months ago)
ModSecurity rule 949110 triggered on wp1. Web application attack blocked by CSF/LFD.
Web App Attack
Hacking
Anonymous
2026-06-02 00:47:07
(3 months ago)
(caddyscan) Scanner path probe from 145.79.211.185 (IN/India/-): 5 in the last 3600 secs; Ports: *; ...
show more
(caddyscan) Scanner path probe from 145.79.211.185 (IN/India/-): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 2627 145.79.211.185 - - [02/Jun/2026:00:47:05 +0000] "GET /member/.env HTTP/1.1"
[REDACTED] 200 2627 145.79.211.185 - - [02/Jun/2026:00:47:05 +0000] "GET /backend/.env HTTP/1.1"
[REDACTED] 200 2627 145.79.211.185 - - [02/Jun/2026:00:47:05 +0000] "GET /app/.env HTTP/1.1"
[REDACTED] 200 2627 145.79.211.185 - - [02/Jun/2026:00:47:05 +0000] "GET /new/.env HTTP/1.1"
[REDACTED] 200 2627 145.79.211.185 - - [02/Jun/2026:00:47:05 +0000] "GET /api/.env HTTP/1.1"
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-06-02 00:40:15
(3 months ago)
(mod_security) mod_security (id:949110) triggered by 145.79.211.185 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:949110) triggered by 145.79.211.185 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 01 20:40:04.737709 2026] [security2:error] [pid 31206:tid 31206] [client 145.79.211.185:57508] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "historycruisesbookings.com"] [uri "/app/.env"] [unique_id "ah4mZJznjSyouUEENJ2M-wAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-01 23:51:01
(3 months ago)
Bot / scanning and/or hacking attempts: GET /new/.env HTTP/1.1, GET /backend/.env HTTP/1.1, GET /adm ...
show more
Bot / scanning and/or hacking attempts: GET /new/.env HTTP/1.1, GET /backend/.env HTTP/1.1, GET /admin/.env HTTP/1.1
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-01 22:32:09
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 145.79.211.185 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 145.79.211.185 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 01 18:32:03.742898 2026] [security2:error] [pid 19528:tid 19528] [client 145.79.211.185:60154] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "merrilymovie.com"] [uri "/.env"] [unique_id "ah4IY3jwiHaef6_sDHy7HAAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-01 21:42:06
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 145.79.211.185 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 145.79.211.185 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 01 17:42:02.199456 2026] [security2:error] [pid 13829:tid 13829] [client 145.79.211.185:45016] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "amychop.com"] [uri "/core/.env"] [unique_id "ah38qgaOUsMC_BK_oH2W_gAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-06-01 19:05:45
(3 months ago)
Too many Status 40X (18)
Scanning/Probing (18)
Brute-Force
Web App Attack
๐ซ๐ท
dynamix
2026-06-01 18:57:56
(3 months ago)
Multiple WAF Violations
Web App Attack
Anonymous
2026-06-01 18:50:07
(3 months ago)
suspicious request in access.log
Web App Attack
Anonymous
2026-06-01 18:47:23
(3 months ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH