๐ฎ๐ช
AutosOnShow
2026-09-27 17:52:05
(22 hours ago)
blocked for webapp attack | path requested: /.env | seen at 2026-09-27 17:51:20.840 |
Web App Attack
๐ฎ๐ช
AutosOnShow
2026-09-27 17:27:04
(23 hours ago)
blocked for webapp attack | path requested: /.env | seen at 2026-09-27 17:26:28.135 |
Web App Attack
๐ฎ๐ช
AutosOnShow
2026-09-27 09:54:05
(1 day ago)
blocked for webapp attack | path requested: /.env | seen at 2026-09-27 09:53:08.886 |
Web App Attack
๐ฎ๐ช
AutosOnShow
2026-09-27 02:24:05
(1 day ago)
blocked for webapp attack | path requested: /.env | seen at 2026-09-27 02:23:14.615 |
Web App Attack
๐ฎ๐ช
AutosOnShow
2026-09-26 10:41:05
(2 days ago)
blocked for webapp attack | path requested: /.env | seen at 2026-09-26 10:40:10.716 |
Web App Attack
๐ฎ๐ช
AutosOnShow
2026-09-24 16:36:05
(4 days ago)
blocked for webapp attack | path requested: /.env | seen at 2026-09-24 16:35:33.984 |
Web App Attack
๐บ๐ธ
alsmanifesto
2026-09-24 16:26:30
(4 days ago)
Sent POST requests to a static site with no handler to receive them against fluentops.org. 1 request ...
show more
Sent POST requests to a static site with no handler to receive them against fluentops.org. 1 request, 2026-09-24 16:26:29 UTC. Blocked at our edge.
show less
Web App Attack
Hacking
๐ฎ๐ช
AutosOnShow
2026-09-23 11:15:07
(5 days ago)
blocked for webapp attack | path requested: /.env | seen at 2026-09-23 11:14:11.337 |
Web App Attack
๐ฉ๐ช
findlab
2026-09-21 10:30:02
(1 week ago)
Backdrop CMS module - malicious activity detected
Bad Web Bot
Web App Attack
๐ฉ๐ช
psauxit
2026-07-13 07:51:07
(2 months ago)
Fail2Ban - NGINX heavily bad-bot, possible vulnerability scanning and excessive crawling/scraping
Bad Web Bot
Web App Attack
Hacking
Web Spam
๐บ๐ธ
TPI-Abuse
2026-03-14 11:05:14
(6 months ago)
(mod_security) mod_security (id:210350) triggered by 217.181.87.21 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 217.181.87.21 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Mar 14 07:05:09.634626 2026] [security2:error] [pid 28161:tid 28161] [client 217.181.87.21:12208] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||www.thomasgardner.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.thomasgardner.com"] [uri "/wp-login.php"] [unique_id "abVA5QmOVHBowVqItzkt3gAAAAc"], referer: http://thomasgardner.com/wp-login.php
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-11 18:18:45
(6 months ago)
(mod_security) mod_security (id:225170) triggered by 217.181.87.21 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 217.181.87.21 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Mar 11 14:18:40.617127 2026] [security2:error] [pid 2918:tid 2918] [client 217.181.87.21:42638] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||ecomim.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "ecomim.com"] [uri "/wp-json/wp/v2/users"] [unique_id "abGyAEcTv2vgqGWed3NdogAAAAs"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-11 15:52:58
(6 months ago)
(mod_security) mod_security (id:210350) triggered by 217.181.87.21 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 217.181.87.21 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Mar 11 11:52:49.323991 2026] [security2:error] [pid 3913:tid 3913] [client 217.181.87.21:35966] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||texaslawman.net|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "texaslawman.net"] [uri "/wp-login.php"] [unique_id "abGP0Q43Gy_ebfkym86RpQAAAAI"], referer: http://texaslawman.net/wp-login.php
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-11 13:10:26
(6 months ago)
(mod_security) mod_security (id:225170) triggered by 217.181.87.21 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 217.181.87.21 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Mar 11 09:10:19.089645 2026] [security2:error] [pid 27687:tid 27687] [client 217.181.87.21:32718] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||wardellbrown.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "wardellbrown.com"] [uri "/wp-json/wp/v2/users"] [unique_id "abFpuzmxNgsQIqy0tDG5iAAAAAk"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack