🇮🇹
CoreTech srl
2026-09-12 12:33:56
(7 minutes ago)
cloudlinux2 fail2ban: 2026-09-12 14:28:49,244 fail2ban.filter [1606]: INFO [plesk-wordpre ...
show more
cloudlinux2 fail2ban: 2026-09-12 14:28:49,244 fail2ban.filter [1606]: INFO [plesk-wordpress] Found 193.56.116.108 - 2026-09-12 14:28:48cloudlinux2 fail2ban: 2026-09-12 14:28:53,409 fail2ban.filter [1606]: INFO [plesk-wordpress] Found 193.56.116.108 - 2026-09-12 14:28:53cloudlinux2 fail2ban: 2026-09-12 14:29:12,679 fail2ban.filter [1606]: INFO [plesk-modsecurity] Found 93.34.146.226 - 2026-09-12 14:29:12cloudlinux2 fail2ban: 2026-09-12 14:29:13,031 fail2ban.actions [1606]: NOTICE [plesk-modsecurity] Ban 93.34.146.226cloudlinux2 fail2ban: 2026-09-12 14:29:13,021 fail2ban.filter [1606]: INFO [plesk-modsecurity] Found 93.34.146.226 - 2026-09-12 14:29:13cloudlinux2 fail2ban: 2026-09-12 14:29:12,662 fail2ban.filter [1606]: INFO [plesk-modsecurity] Found 93.34.146.226 - 2026-09-12 14:29:12cloudlinux2 fail2ban: 2026-09-12 14:29:13,033 fail2ban.filter [1606]: INFO [recidive] Found 93.34.146.226 - 2026-09-12 14:29:13cloudlinux2 fail2ban: 2026-09-
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-12 11:52:15
(48 minutes ago)
(mod_security) mod_security (id:210492) triggered by 147.124.214.112 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 147.124.214.112 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 07:52:12.016848 2026] [security2:error] [pid 1182:tid 1182] [client 147.124.214.112:35662] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "prezence.com"] [uri "/.env"] [unique_id "aqU87B8qJneghfzXPWfzcgAAAB8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-12 11:33:53
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 147.124.214.112 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 147.124.214.112 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 07:33:46.471887 2026] [security2:error] [pid 16987:tid 16987] [client 147.124.214.112:37352] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "loupgaroupress.freerein.info"] [uri "/.env"] [unique_id "aqU4mv9EVKwVgLGkAa765AAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
Bedios GmbH
2026-09-12 11:29:55
(1 hour ago)
Login credentials theft attempt
Hacking
🇩🇪
Teufel100
2026-09-12 11:21:42
(1 hour ago)
ModSecurity rejected a query
Brute-Force
Hacking
Web App Attack
🇳🇱
Alt255
2026-09-12 10:13:58
(2 hours ago)
147.124.214.112 - - [12/Sep/2026:12:13:57 +0200] "GET /.env HTTP/1.1" 404 11844 "-" "Mozilla/5.0 (X1 ...
show more
147.124.214.112 - - [12/Sep/2026:12:13:57 +0200] "GET /.env HTTP/1.1" 404 11844 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
🇺🇸
kosada.com
2026-09-12 10:10:43
(2 hours ago)
Repeated exploit attempts, for example: / Access denied with code 406 (phase 2), Failed to lock glob ...
show more
Repeated exploit attempts, for example: / Access denied with code 406 (phase 2), Failed to lock global mutex: Invalid argument (HTTP/1.1 port 443)
show less
Web App Attack
Anonymous
2026-09-12 00:57:29
(11 hours ago)
SecLists/Fuzzing Scanner detected (SecLists/Fuzzer Hedef Dosya Taraması (/.env)). Subnet karantinaya ...
show more
SecLists/Fuzzing Scanner detected (SecLists/Fuzzer Hedef Dosya Taraması (/.env)). Subnet karantinaya alındı.
show less
Port Scan
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-11 23:31:39
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 147.124.214.112 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 147.124.214.112 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 19:31:34.122240 2026] [security2:error] [pid 26781:tid 26781] [client 147.124.214.112:36754] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "egelfitness.nl"] [uri "/.env"] [unique_id "aqSPVnCqUdkKrIJWqcaPGgAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
Swiptly
2026-09-11 22:15:05
(14 hours ago)
Bot scanning for environment files .env .env/\*
...
Web App Attack
🇳🇱
homeshowdomain.nl
2026-09-11 21:59:21
(14 hours ago)
Auto-ban: >3000 req/min op 2026-09-11
Web App Attack
SSH
Hacking
🇳🇱
e.fierstra
2026-09-11 21:47:15
(14 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
🇮🇹
CoreTech srl
2026-09-11 20:38:56
(16 hours ago)
cloudlinux2 fail2ban: 2026-09-11 22:34:48,243 fail2ban.filter [1606]: INFO [plesk-modsecu ...
show more
cloudlinux2 fail2ban: 2026-09-11 22:34:48,243 fail2ban.filter [1606]: INFO [plesk-modsecurity] Found 147.124.214.112 - 2026-09-11 22:34:48cloudlinux2 fail2ban: 2026-09-11 22:34:48,295 fail2ban.filter [1606]: INFO [plesk-modsecurity] Found 147.124.214.112 - 2026-09-11 22:34:48cloudlinux2 fail2ban: 2026-09-11 22:37:04,276 fail2ban.filter [1606]: INFO [plesk-wordpress] Found 186.189.88.2 - 2026-09-11 22:37:03cloudlinux2 fail2ban: 2026-09-11 22:37:45,557 fail2ban.filter [1606]: INFO [plesk-modsecurity] Found 136.66.243.136 - 2026-09-11 22:37:45cloudlinux2 fail2ban: 2026-09-11 22:37:46,087 fail2ban.filter [1606]: INFO [recidive] Found 136.66.243.136 - 2026-09-11 22:37:46cloudlinux2 fail2ban: 2026-09-11 22:37:46,025 fail2ban.filter [1606]: INFO [plesk-modsecurity] Found 136.66.243.136 - 2026-09-11 22:37:46cloudlinux2 fail2ban: 2026-09-11 22:37:45,810 fail2ban.filter [1606]: INFO [plesk-modsecurity] Found 136.66.243.136 - 2026-09-11 22:37:4
show less
Web App Attack
🇱🇻
garmtech.com
2026-09-11 19:54:35
(16 hours ago)
Attempted access to sensitive endpoint (/.env) detected. Automated scan or unauthorized probing.
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 19:06:21
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 147.124.214.112 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 147.124.214.112 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 15:06:13.211905 2026] [security2:error] [pid 5040:tid 5040] [client 147.124.214.112:41928] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "joesteiner.com"] [uri "/.env"] [unique_id "aqRRJYwsTZccJSoKwmt07gAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack