Anonymous
2026-07-21 00:00:00
(3 days ago)
"Security violation, excess traffic against library/education infrastructure"
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-07-06 07:31:15
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 185.248.184.161 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 185.248.184.161 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 06 03:31:07.193765 2026] [security2:error] [pid 22631:tid 22631] [client 185.248.184.161:2602] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "hazardvillefire.org"] [uri "/.env.local"] [unique_id "aktZu-Mr6jt9LEEn1JO0QQAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-05 12:48:03
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 185.248.184.161 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 185.248.184.161 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 05 08:47:56.324954 2026] [security2:error] [pid 28163:tid 28163] [client 185.248.184.161:6024] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "glassicannex.org"] [uri "/.env.development"] [unique_id "akpSfM5x-LRaosnmxWLkpAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-05 09:49:47
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 185.248.184.161 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 185.248.184.161 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 05 05:49:41.592720 2026] [security2:error] [pid 25189:tid 25214] [client 185.248.184.161:64746] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "georgementz.org"] [uri "/.env.local"] [unique_id "akoote5qPt5emN9aPKdm7AAAARc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
mediarama.com
2026-07-05 04:10:19
(2 weeks ago)
Banned by Fail2Ban
Web App Attack
๐ฉ๐ช
ghostwarriors
2026-07-04 10:20:07
(2 weeks ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-04 01:46:17
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 185.248.184.161 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 185.248.184.161 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 03 21:46:12.643897 2026] [security2:error] [pid 6109:tid 6109] [client 185.248.184.161:29746] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "elderlyassociation.org"] [uri "/.env.local"] [unique_id "akhl5NLTTDemqlYYxeF8lgAAAB8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-03 20:22:25
(2 weeks ago)
Fuzzing/Looking for credentials files.
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-02 20:06:47
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 185.248.184.161 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 185.248.184.161 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 02 16:06:39.615903 2026] [security2:error] [pid 17717:tid 17717] [client 185.248.184.161:10796] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "corinthianscruise.org"] [uri "/.env"] [unique_id "akbEz4_WBxApXtGfRN7isQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-01 16:50:23
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 185.248.184.161 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 185.248.184.161 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 01 12:50:19.132586 2026] [security2:error] [pid 10574:tid 10574] [client 185.248.184.161:27910] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "c2cdisasterresponse.org"] [uri "/.env.local"] [unique_id "akVFS7rSgyyvGOv8j30EzQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-01 05:06:35
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 185.248.184.161 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 185.248.184.161 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 01 01:06:31.537581 2026] [security2:error] [pid 27080:tid 27168] [client 185.248.184.161:51180] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "behaviorhealth.org"] [uri "/.env"] [unique_id "akSgVyp8JmkAOkQBWqZszgAAAFM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-28 13:58:51
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 185.248.184.161 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 185.248.184.161 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 28 09:58:42.660238 2026] [security2:error] [pid 20422:tid 20422] [client 185.248.184.161:61412] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "matteozacchino.dev"] [uri "/.env.production"] [unique_id "akEokpaiB0R9Bvqz7aUirgAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-28 08:05:07
(3 weeks ago)
WAF repeated trigger detected by Fail2Ban
Web App Attack
๐ฌ๐ง
thetomtaylor.co.uk
2026-06-26 21:09:01
(3 weeks ago)
Fail2Ban - [NGINX]WordPress Logins Sniffings on nginx-wordpress-sniffer ... [ice01,ice02,mx01,mx02,m ...
show more
Fail2Ban - [NGINX]WordPress Logins Sniffings on nginx-wordpress-sniffer ... [ice01,ice02,mx01,mx02,mx03,wa02]
show less
Bad Web Bot
Web App Attack
๐ฌ๐ง
thetomtaylor.co.uk
2026-06-26 19:05:03
(3 weeks ago)
Fail2Ban - [WEB]Custom exploit pattern detected on customexploits ... [wa01]
Hacking
Brute-Force
Bad Web Bot
Web App Attack