๐ณ๐ฑ
Site.eu
2025-11-16 11:52:40
(9 months ago)
Excessive 404/403 errors
Brute-Force
๐บ๐ธ
TPI-Abuse
2025-11-16 07:03:07
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 18.237.142.89 (ec2-18-237-142-89.us-west-2.comp ...
show more
(mod_security) mod_security (id:210492) triggered by 18.237.142.89 (ec2-18-237-142-89.us-west-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Nov 16 02:03:02.942434 2025] [security2:error] [pid 10486:tid 10486] [client 18.237.142.89:46856] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cerrovictoria.com"] [uri "/.env"] [unique_id "aRl3Jg8pRn7f02mDQQwpbAAAAC0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-16 06:35:04
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 18.237.142.89 (ec2-18-237-142-89.us-west-2.comp ...
show more
(mod_security) mod_security (id:210492) triggered by 18.237.142.89 (ec2-18-237-142-89.us-west-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Nov 16 01:34:56.548497 2025] [security2:error] [pid 2376:tid 2435] [client 18.237.142.89:55794] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ceresfund.com"] [uri "/.env.local"] [unique_id "aRlwkIcetQoM5u4u2zfm8QAAARQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Savvii
2025-11-16 06:34:22
(9 months ago)
32 attempts against mh-misbehave-ban on ceres
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2025-11-15 23:04:44
(9 months ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2025-11-14.
show less
Hacking
Web App Attack
SSH
๐ณ๐ด
Bots.go.to.hell
2025-11-15 20:22:23
(9 months ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Hacking
Web App Attack
Anonymous
2025-11-15 16:30:44
(9 months ago)
Failed login attempt detected by Fail2Ban in plesk-modsecurity jail
Exploited Host
๐บ๐ธ
TPI-Abuse
2025-11-15 14:24:13
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 18.237.142.89 (ec2-18-237-142-89.us-west-2.comp ...
show more
(mod_security) mod_security (id:210492) triggered by 18.237.142.89 (ec2-18-237-142-89.us-west-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Nov 15 09:24:05.640114 2025] [security2:error] [pid 3770:tid 3770] [client 18.237.142.89:52746] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "celebratethesemoments.taltonfamily.com"] [uri "/.env.backup"] [unique_id "aRiNBavRWtDDTb7WOviYXAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-14 19:49:42
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 18.237.142.89 (ec2-18-237-142-89.us-west-2.comp ...
show more
(mod_security) mod_security (id:210492) triggered by 18.237.142.89 (ec2-18-237-142-89.us-west-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Nov 14 14:49:35.214880 2025] [security2:error] [pid 16506:tid 16506] [client 18.237.142.89:54338] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "debbieweibler.com"] [uri "/.git/config"] [unique_id "aReHz49MjdfJUaX0N4_bAwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
waltn3mtj
2025-11-14 19:09:00
(9 months ago)
Attempts to access server root and cPanel.
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-14 17:04:17
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 18.237.142.89 (ec2-18-237-142-89.us-west-2.comp ...
show more
(mod_security) mod_security (id:210492) triggered by 18.237.142.89 (ec2-18-237-142-89.us-west-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Nov 14 12:04:09.927725 2025] [security2:error] [pid 2068149:tid 2068149] [client 18.237.142.89:44470] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "copierscharlotte.com"] [uri "/.git/config"] [unique_id "aRdhCWeS--KCiR3btEUuBwAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-14 16:05:03
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 18.237.142.89 (ec2-18-237-142-89.us-west-2.comp ...
show more
(mod_security) mod_security (id:210492) triggered by 18.237.142.89 (ec2-18-237-142-89.us-west-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Nov 14 11:04:55.501564 2025] [security2:error] [pid 11175:tid 11175] [client 18.237.142.89:56044] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "constructiondomex.com"] [uri "/.git/config"] [unique_id "aRdTJ4TC0XPdbaKzfVRDoQAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack