๐บ๐ธ
TPI-Abuse
2026-05-30 10:52:30
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 157.254.221.198 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 157.254.221.198 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 30 06:52:24.928120 2026] [security2:error] [pid 4968:tid 5042] [client 157.254.221.198:46932] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "saltflowlogistics.com"] [uri "/.env.bak"] [unique_id "ahrBaJ9LZhVv3ErWtd2XvwAAAEU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-05-30 10:18:09
(4 days ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-30 07:04:22
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 157.254.221.198 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 157.254.221.198 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 30 03:04:17.093402 2026] [security2:error] [pid 13791:tid 13791] [client 157.254.221.198:43584] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sailsara.com"] [uri "/.git/config"] [unique_id "ahqL8bin3-j-0NQN8hAu8wAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Savvii
2026-05-30 06:57:26
(4 days ago)
20 attempts against mh-misbehave-ban on redirect
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
consul.to
2026-05-30 05:58:56
(4 days ago)
Web attack/malicious scanning detected
Web App Attack
๐ช๐ธ
pipeline.es
2026-05-30 00:47:35
(4 days ago)
Web scanning / probing for vulnerable paths | URL: /.well-known/openid-configuration | Evidence: 157 ...
show more
Web scanning / probing for vulnerable paths | URL: /.well-known/openid-configuration | Evidence: 157.254.221.198 - - [30/May/2026:02:47:15 +0200] \"GET /.well-known/openid-configuration HTTP/1.1\" 404 119592 \"-\" \"Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/129.0.0.0 Safari/537.36\" GEOIP_COUNTRY_CODE=US | ASN: 1GSERVERS | Country: US
show less
Port Scan
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-29 20:33:41
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 157.254.221.198 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 157.254.221.198 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 29 16:33:33.657032 2026] [security2:error] [pid 32529:tid 32529] [client 157.254.221.198:44946] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "title36.com"] [uri "/.env.local"] [unique_id "ahn4HaDm64Q3TYmy8RpNxgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-29 19:59:00
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 157.254.221.198 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 157.254.221.198 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 29 15:58:54.687035 2026] [security2:error] [pid 7634:tid 7634] [client 157.254.221.198:53168] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jessicabaer.com"] [uri "/.git/config"] [unique_id "ahnv_pZm5El4QboQ7oSblgAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-05-29 19:05:16
(5 days ago)
Too many Status 40X (16)
Scanning/Probing (24)
Brute-Force
Web App Attack
๐ง๐ช
cmbplf
2026-05-29 18:29:53
(5 days ago)
288 requests with url.path *.env
147 requests with url.path *config.json
Brute-Force
Bad Web Bot
Anonymous
2026-05-29 16:33:22
(5 days ago)
Failed login attempt detected by Fail2Ban in plesk-modsecurity jail
Exploited Host
๐บ๐ธ
TPI-Abuse
2026-05-29 09:15:14
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 157.254.221.198 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 157.254.221.198 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 29 05:15:11.935277 2026] [security2:error] [pid 24937:tid 24955] [client 157.254.221.198:40480] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "12am.com"] [uri "/app/.env"] [unique_id "ahlZH3epIjNiqEqaXjAmqQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-29 08:59:37
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 157.254.221.198 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 157.254.221.198 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 29 04:59:33.626443 2026] [security2:error] [pid 9724:tid 9724] [client 157.254.221.198:49642] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "124projects.com"] [uri "/.env.development"] [unique_id "ahlVdejpPrp1q8y-SmWOmwAAAB8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-05-29 08:24:55
(5 days ago)
Multiple WAF Violations
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-05-28 22:02:49
(6 days ago)
Auto-ban: >3000 req/min op 2026-05-28
Web App Attack
SSH
Hacking