Anonymous
2026-07-01 04:32:49
(2 months ago)
Failed login attempt detected by Fail2Ban in plesk-modsecurity jail
Exploited Host
๐ฌ๐ง
openstrike.co.uk
2026-06-03 05:14:19
(3 months ago)
12 attacks on VC URLs, Laravel URLs, PHP URLs, env grabbing URLs:
GET /.git/config HTTP/1.1
GET /_ig ...
show more
12 attacks on VC URLs, Laravel URLs, PHP URLs, env grabbing URLs:
GET /.git/config HTTP/1.1
GET /_ignition/execute-solution HTTP/1.1
POST /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
GET /.env HTTP/1.1
show less
Hacking
Web App Attack
๐ฉ๐ช
enjoyably
2026-06-02 17:01:20
(3 months ago)
This IP was detected by CrowdSec triggering crowdsecurity/CVE-2017-9841
Web App Attack
๐บ๐ธ
deskpass.com
2026-06-02 14:57:10
(3 months ago)
POST /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php
Web App Attack
๐ฉ๐ช
filstal.org
2026-06-02 14:39:52
(3 months ago)
Web exploit or injection attempt blocked by ModSecurity WAF (Fail2Ban)
SQL Injection
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-02 13:04:24
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 2604:a00:101:11:41ef:c842:11de:9c12 (Unknown): ...
show more
(mod_security) mod_security (id:210492) triggered by 2604:a00:101:11:41ef:c842:11de:9c12 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 02 09:04:20.512710 2026] [security2:error] [pid 11036:tid 11036] [client 2604:a00:101:11:41ef:c842:11de:9c12:56956] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "dansplans.com"] [uri "/.env"] [unique_id "ah7U1MATvqmubINd0t4ACwAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
dklueh79
2026-06-02 12:11:21
(3 months ago)
Probe for vulnerabilities. Path attempted: /.env
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-02 12:01:49
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 2604:a00:101:11:41ef:c842:11de:9c12 (Unknown): ...
show more
(mod_security) mod_security (id:210492) triggered by 2604:a00:101:11:41ef:c842:11de:9c12 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 02 08:01:45.669280 2026] [security2:error] [pid 7523:tid 7523] [client 2604:a00:101:11:41ef:c842:11de:9c12:46426] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "danged.com"] [uri "/.env"] [unique_id "ah7GKa9pNHQo3kMQvnCd1gAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-06-02 10:08:37
(3 months ago)
Excessive multi-domain requests
Brute-Force
๐ฉ๐ช
BlueWire Hosting
2026-06-02 09:29:27
(3 months ago)
Probing websites for vulnerabilities
Web App Attack
SQL Injection
๐บ๐ธ
TPI-Abuse
2026-06-02 09:19:23
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 2604:a00:101:11:41ef:c842:11de:9c12 (Unknown): ...
show more
(mod_security) mod_security (id:210492) triggered by 2604:a00:101:11:41ef:c842:11de:9c12 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 02 05:19:15.660725 2026] [security2:error] [pid 23507:tid 23507] [client 2604:a00:101:11:41ef:c842:11de:9c12:22244] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "daikin.cloudex.link"] [uri "/.env"] [unique_id "ah6gE2ZXETuIM0gxbPOG_AAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
filstal.org
2026-06-02 08:51:02
(3 months ago)
CrowdSec: crowdsecurity/http-cve-probing
Port Scan
Hacking
๐บ๐ธ
TPI-Abuse
2026-06-02 08:35:45
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 2604:a00:101:11:41ef:c842:11de:9c12 (Unknown): ...
show more
(mod_security) mod_security (id:210492) triggered by 2604:a00:101:11:41ef:c842:11de:9c12 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 02 04:35:37.529260 2026] [security2:error] [pid 890:tid 890] [client 2604:a00:101:11:41ef:c842:11de:9c12:55356] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "daddysmilkclub.com"] [uri "/.env"] [unique_id "ah6V2eljcOdf98G9K_21oQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-02 06:03:54
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 2604:a00:101:11:41ef:c842:11de:9c12 (Unknown): ...
show more
(mod_security) mod_security (id:210492) triggered by 2604:a00:101:11:41ef:c842:11de:9c12 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 02 02:03:46.358284 2026] [security2:error] [pid 19733:tid 19733] [client 2604:a00:101:11:41ef:c842:11de:9c12:52946] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cygnetsilks.com"] [uri "/.env"] [unique_id "ah5yQmQrbuBWtvsh6TOnxQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Roderic
2026-06-02 05:50:49
(3 months ago)
(apache-scanners) Failed apache-scanners trigger with match [redacted])
Port Scan