🇺🇸
TPI-Abuse
2026-09-13 02:44:18
(5 minutes ago)
(mod_security) mod_security (id:210492) triggered by 185.226.156.1 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 185.226.156.1 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 22:44:12.358678 2026] [security2:error] [pid 1726:tid 1726] [client 185.226.156.1:41368] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "10mostwantedfugitives.com"] [uri "/.env"] [unique_id "aqYN_D3-reCAs4zt0t9YVgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-13 02:10:02
(39 minutes ago)
suspicious request in access.log
Web App Attack
🇺🇸
dot.mg
2026-09-13 02:02:01
(47 minutes ago)
Bad behaviour
Web Spam
🇩🇪
onlyops.app
2026-09-13 02:00:09
(49 minutes ago)
Web application firewall (ModSecurity) detected malicious traffic | detected by Fail2Ban (plesk-mods ...
show more
Web application firewall (ModSecurity) detected malicious traffic | detected by Fail2Ban (plesk-modsecurity jail) | onlyops.app
show less
Exploited Host
🇨🇭
4server
2026-09-13 01:41:04
(1 hour ago)
[SunSep1303:41:00.9550062026][security2:error][pid2073909:tid2074213][client185.226.156.1:0]ModSecur ...
show more
[SunSep1303:41:00.9550062026][security2:error][pid2073909:tid2074213][client185.226.156.1:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\".env\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"610\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"brusmann.ch\"][uri\"/.env\"][unique_id\"aqX_LORMBSmwN2fGrhPg1QAAAUc\"]
show less
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-13 01:30:53
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 185.226.156.1 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 185.226.156.1 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 21:30:50.034221 2026] [security2:error] [pid 18582:tid 18582] [client 185.226.156.1:32848] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.apnetworkingexamprep.com"] [uri "/wp-config.php"] [unique_id "aqX8yopvUryEpibyp-_3gAAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
Site.eu
2026-09-13 00:53:09
(1 hour ago)
Excessive multi-domain requests
Brute-Force
🇨🇭
backslash
2026-09-12 22:03:00
(4 hours ago)
block ruleset bad bot: misc bad content F608233CC4C86EE814CE8DDDA9C4A0D3C79882F6
Bad Web Bot
🇳🇱
homeshowdomain.nl
2026-09-12 21:59:47
(4 hours ago)
Auto-ban: >3000 req/min op 2026-09-12
Web App Attack
SSH
Hacking
🇺🇸
TPI-Abuse
2026-09-12 21:56:15
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 185.226.156.1 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 185.226.156.1 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 17:56:07.902093 2026] [security2:error] [pid 30585:tid 30663] [client 185.226.156.1:36704] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "biblewriter.com"] [uri "/.git/reconx-f65dafccfa75"] [unique_id "aqXKd-UkpOFld0lYWmfc4AAAAIA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
WeCloudit-Anti-Abuse
2026-09-12 21:54:36
(4 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-12 21:19:54
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 185.226.156.1 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 185.226.156.1 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 17:19:47.283624 2026] [security2:error] [pid 21986:tid 21986] [client 185.226.156.1:33328] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bgraph.com"] [uri "/.git/reconx-5584fe79c8e4"] [unique_id "aqXB80DnhRpBTj6-Ny2UVQAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇦🇺
neilwal
2026-09-12 20:46:14
(6 hours ago)
Web Probe (443): beyondzugzwang.myvnc.com:443 185.226.156.1 - - [13/Sep/2026:06:46:14 +1000] "GET /. ...
show more
Web Probe (443): beyondzugzwang.myvnc.com:443 185.226.156.1 - - [13/Sep/2026:06:46:14 +1000] "GET /.git/reconx-f804d4abf893 HTTP/2.0" 401 563 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.0.0 Safari/537.36 Edg/124.0.0.0"
beyondzugzwang.myvnc.com:443 185.226.156.1 - - [13/Sep/2026:06:46:14 +1000] "GET /.env HTTP/2.0" 401 540 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.0.0 Safari/537.36"
beyondzugzwang.myvnc.com:443 185.226.156.1 - - [13/Sep/2026:06:46:14 +1000] "GET /wp-config.php HTTP/2.0" 401 540 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.0.0 Safari/537.36"
show less
Web App Attack
🇮🇹
VHosting
2026-09-12 20:35:03
(6 hours ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
🇩🇪
filstal.org
2026-09-12 20:33:45
(6 hours ago)
Web exploit or injection attempt blocked by ModSecurity WAF.
SQL Injection
Web App Attack