๐ซ๐ท
Baking333
2026-10-08 23:38:12
(18 hours ago)
[redacted] 149.102.233.173 - - [09/Oct/2026:00:38:11 +0100] "GET /.[redacted] HTTP/1.1" 302 6773 0/5 ...
show more
[redacted] 149.102.233.173 - - [09/Oct/2026:00:38:11 +0100] "GET /.[redacted] HTTP/1.1" 302 6773 0/51487 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36" 443 [redacted] 149.102.233.173 - - [09/Oct/2026:00:38:11 +0100] "GET /.[redacted] HTTP/1.1" 302 6773 0/45831 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36" 443 [redacted] 149.102.233.173 - - [09/Oct/2026:00:38:11 +0100] "GET /.[redacted] HTTP/1.1" 302 6773 0/65620 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36" 443
show less
Bad Web Bot
Web App Attack
Anonymous
2026-10-08 23:35:21
(18 hours ago)
Failed login attempt detected by Fail2Ban in plesk-modsecurity jail
Exploited Host
๐บ๐ธ
TPI-Abuse
2026-10-08 23:23:33
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 149.102.233.173 (unn-149-102-233-173.datapacket ...
show more
(mod_security) mod_security (id:210492) triggered by 149.102.233.173 (unn-149-102-233-173.datapacket.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 19:23:26.514324 2026] [security2:error] [pid 17338:tid 17338] [client 149.102.233.173:50525] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "abogadoparticular.com"] [uri "/.env.backup"] [unique_id "asgl7jVKk6ddQno41rfLNwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
kosada.com
2026-10-08 22:58:28
(18 hours ago)
Repeated exploit attempts, for example: /.env.save /.env (HTTP/1.1 port 443, user agent: "Mozilla/5. ...
show more
Repeated exploit attempts, for example: /.env.save /.env (HTTP/1.1 port 443, user agent: "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36")
show less
Web App Attack
Anonymous
2026-10-08 22:53:23
(18 hours ago)
(caddyscan) Scanner path probe from 149.102.233.173 (BR/Brazil/unn-149-102-233-173.datapacket.com): ...
show more
(caddyscan) Scanner path probe from 149.102.233.173 (BR/Brazil/unn-149-102-233-173.datapacket.com): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 2627 149.102.233.173 - - [08/Oct/2026:22:53:20 +0000] "GET /.env HTTP/1.1"
[REDACTED] 200 2627 149.102.233.173 - - [08/Oct/2026:22:53:20 +0000] "GET /.env.local HTTP/1.1"
[REDACTED] 200 2627 149.102.233.173 - - [08/Oct/2026:22:53:20 +0000] "GET /.env.prod HTTP/1.1"
[REDACTED] 200 2627 149.102.233.173 - - [08/Oct/2026:22:53:20 +0000] "GET /.env.backup HTTP/1.1"
[REDACTED] 200 2627 149.102.233.173 - - [08/Oct/2026:22:53:20 +0000] "GET /.env.production HTTP/1.1"
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-10-08 22:41:42
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 149.102.233.173 (unn-149-102-233-173.datapacket ...
show more
(mod_security) mod_security (id:210492) triggered by 149.102.233.173 (unn-149-102-233-173.datapacket.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 18:41:35.239945 2026] [security2:error] [pid 32681:tid 32681] [client 149.102.233.173:64390] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "abilityengraving.com"] [uri "/.env"] [unique_id "asgcH0z5JCKof1-HqEY4vAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-10-08 21:59:34
(19 hours ago)
Auto-ban: >3000 req/min op 2026-10-08
Web App Attack
SSH
Hacking
๐บ๐ธ
TPI-Abuse
2026-10-08 21:48:21
(20 hours ago)
(mod_security) mod_security (id:210492) triggered by 149.102.233.173 (unn-149-102-233-173.datapacket ...
show more
(mod_security) mod_security (id:210492) triggered by 149.102.233.173 (unn-149-102-233-173.datapacket.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 17:48:18.468127 2026] [security2:error] [pid 17738:tid 17738] [client 149.102.233.173:56884] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "abecasis.com"] [uri "/.env.save"] [unique_id "asgPotQm-XEFWGc-xX5mzgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 21:18:43
(20 hours ago)
(mod_security) mod_security (id:210492) triggered by 149.102.233.173 (unn-149-102-233-173.datapacket ...
show more
(mod_security) mod_security (id:210492) triggered by 149.102.233.173 (unn-149-102-233-173.datapacket.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 17:18:39.838999 2026] [security2:error] [pid 18282:tid 18282] [client 149.102.233.173:54189] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "abchessboards.com"] [uri "/.env"] [unique_id "asgIr05uSSgqm70VTcyfhgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 21:03:21
(20 hours ago)
(mod_security) mod_security (id:210492) triggered by 149.102.233.173 (unn-149-102-233-173.datapacket ...
show more
(mod_security) mod_security (id:210492) triggered by 149.102.233.173 (unn-149-102-233-173.datapacket.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 17:03:15.630731 2026] [security2:error] [pid 24471:tid 24471] [client 149.102.233.173:51320] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "abbysue.com"] [uri "/.env.save"] [unique_id "asgFEzWpmcI43a8zccF7NwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 20:35:19
(21 hours ago)
(mod_security) mod_security (id:210492) triggered by 149.102.233.173 (unn-149-102-233-173.datapacket ...
show more
(mod_security) mod_security (id:210492) triggered by 149.102.233.173 (unn-149-102-233-173.datapacket.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 16:35:15.531947 2026] [security2:error] [pid 30760:tid 30760] [client 149.102.233.173:55774] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "abaracadavara.com"] [uri "/.env.backup"] [unique_id "asf-g6oi3QKHbXIo1A7ZpQAAACg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
elcruzado.es
2026-10-08 20:24:09
(21 hours ago)
(mod_security) mod_security triggered on hostname [redacted] 149.102.233.173 (BR/Brazil/unn-149-102- ...
show more
(mod_security) mod_security triggered on hostname [redacted] 149.102.233.173 (BR/Brazil/unn-149-102-233-173.datapacket.com)
show less
SQL Injection
๐บ๐ธ
TPI-Abuse
2026-10-08 20:04:26
(21 hours ago)
(mod_security) mod_security (id:210492) triggered by 149.102.233.173 (unn-149-102-233-173.datapacket ...
show more
(mod_security) mod_security (id:210492) triggered by 149.102.233.173 (unn-149-102-233-173.datapacket.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 16:04:19.273270 2026] [security2:error] [pid 21768:tid 21768] [client 149.102.233.173:51564] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "aavondalervstorage.com"] [uri "/.env.production"] [unique_id "asf3Q8MUnT0OsuxZkaaVLgAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 19:45:25
(22 hours ago)
(mod_security) mod_security (id:210492) triggered by 149.102.233.173 (unn-149-102-233-173.datapacket ...
show more
(mod_security) mod_security (id:210492) triggered by 149.102.233.173 (unn-149-102-233-173.datapacket.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 15:45:20.036604 2026] [security2:error] [pid 32164:tid 32164] [client 149.102.233.173:57008] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "aarts.com"] [uri "/.env.local"] [unique_id "asfy0JjRKpVy5lZfcEpkGAAAACQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
IndigoRidge
2026-10-08 19:15:01
(22 hours ago)
[08/Oct/2026:15:15:01.036268 --0400] asfrtdOmv2g3S6@MTPG34gAAAw0 149.102.233.173 43098 205.233.18.17 ...
show more
[08/Oct/2026:15:15:01.036268 --0400] asfrtdOmv2g3S6@MTPG34gAAAw0 149.102.233.173 43098 205.233.18.17 7080
[08/Oct/2026:15:15:01.044427 --0400] asfrtRYp079zzLcB1SR2pAAAAEk 149.102.233.173 43100 205.233.18.17 7080
[08/Oct/2026:15:15:01.044768 --0400] asfrtRYp079zzLcB1SR2pQAAAFU 149.102.233.173 43104 205.233.18.17 7080
[08/Oct/2026:15:15:01.045025 --0400] asfrtRYp079zzLcB1SR2pgAAAEA 149.102.233.173 43108 205.233.18.17 7080
[08/Oct/2026:15:15:01.047656 --0400] asfrtZV8eoDq9QoxQI0KrgAAAYw 149.102.233.173 43122 205.233.18.17 7080
...
show less
Hacking