๐บ๐ธ
TPI-Abuse
2026-09-15 11:58:37
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 2a02:4780:75:578c::1 (srv1591828.hstgr.cloud): ...
show more
(mod_security) mod_security (id:210492) triggered by 2a02:4780:75:578c::1 (srv1591828.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 07:58:28.355523 2026] [security2:error] [pid 28131:tid 28131] [client 2a02:4780:75:578c::1:42836] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.doorofhopechurch.org"] [uri "/.git/config"] [unique_id "aqky5FitpR8EuyFsePNi_AAAACg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-15 10:40:09
(17 hours ago)
[ti-05al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-05al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 2a02:4780:75:578c::1 - - [15/Sep/2026:12:39:49 +0200] "GET /.env.save HTTP/2.0" 301 144 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob
2026-09-15 09:38:50
(18 hours ago)
Asking over plain http and never following the redirect served โ a crawler that reads nothing it ask ...
show more
Asking over plain http and never following the redirect served โ a crawler that reads nothing it asks for | method: GET | path: / | 2026-09-15 09:38 UTC
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-15 09:04:49
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 2a02:4780:75:578c::1 (srv1591828.hstgr.cloud): ...
show more
(mod_security) mod_security (id:210492) triggered by 2a02:4780:75:578c::1 (srv1591828.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 05:04:45.380272 2026] [security2:error] [pid 8501:tid 8501] [client 2a02:4780:75:578c::1:45438] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "hierrosbernal.com"] [uri "/wp-config.php~"] [unique_id "aqkKLTU-lZ5r5x2f-qPQMgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 08:37:48
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 2a02:4780:75:578c::1 (srv1591828.hstgr.cloud): ...
show more
(mod_security) mod_security (id:210492) triggered by 2a02:4780:75:578c::1 (srv1591828.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 04:37:40.029568 2026] [security2:error] [pid 442:tid 544] [client 2a02:4780:75:578c::1:34012] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.rightnews.org"] [uri "/.env.txt"] [unique_id "aqkD1KGgLgjf3XROOlhzKwAAAVQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ต๐ฑ
Budyn
2026-09-15 08:32:48
(19 hours ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scan ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scanner. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: auth.goblinpot.space | URI: /.git/config | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36 | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
๐ซ๐ท
arsonist
2026-09-15 06:54:56
(21 hours ago)
[fail2ban]
2026-09-15T06:54:55.947271+00:00 arson caddy[1890453]: {"level":"info","ts":1789455295.94 ...
show more
[fail2ban]
2026-09-15T06:54:55.947271+00:00 arson caddy[1890453]: {"level":"info","ts":1789455295.947231,"logger":"http.log.access.default","msg":"handled request","request":{"remote_ip":"2a02:4780:75:578c::1","remote_port":"38000","client_ip":"2a02:4780:75:578c::1","proto":"HTTP/1.1","method":"GET","host":"ask.possum.city","uri":"/.git/config","headers":{"User-Agent":["Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"],"Accept-Encoding":["gzip"]},"tls":{"resumed":false,"version":772,"cipher_suite":4865,"proto":"","server_name":"ask.possum.city","ech":false}},"bytes_read":0,"user_id":"","duration":0.000086873,"size":7,"status":418,"resp_headers":{"Server":["Caddy"],"Alt-Svc":["h3=\":443\"; ma=2592000"],"Content-Type":["text/plain; charset=utf-8"]}}
...
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-15 06:07:54
(21 hours ago)
(mod_security) mod_security (id:210492) triggered by 2a02:4780:75:578c::1 (srv1591828.hstgr.cloud): ...
show more
(mod_security) mod_security (id:210492) triggered by 2a02:4780:75:578c::1 (srv1591828.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 02:07:44.904851 2026] [security2:error] [pid 22645:tid 22645] [client 2a02:4780:75:578c::1:32900] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.canelli.net"] [uri "/.env.txt"] [unique_id "aqjgsKNizLAA8AJ9Gd60_gAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 04:47:15
(23 hours ago)
(mod_security) mod_security (id:210492) triggered by 2a02:4780:75:578c::1 (srv1591828.hstgr.cloud): ...
show more
(mod_security) mod_security (id:210492) triggered by 2a02:4780:75:578c::1 (srv1591828.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 00:47:07.248622 2026] [security2:error] [pid 16910:tid 16910] [client 2a02:4780:75:578c::1:46396] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "arofish.us"] [uri "/.git/config"] [unique_id "aqjNywHZ52eLSh6AtlGjgwAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 02:37:36
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 2a02:4780:75:578c::1 (srv1591828.hstgr.cloud): ...
show more
(mod_security) mod_security (id:210492) triggered by 2a02:4780:75:578c::1 (srv1591828.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 14 22:37:29.392040 2026] [security2:error] [pid 18591:tid 18591] [client 2a02:4780:75:578c::1:55608] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "asdfwordpro.com"] [uri "/.env.save"] [unique_id "aqivabWsXbKR0YgoFTBwqAAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-14 23:34:46
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 2a02:4780:75:578c::1 (srv1591828.hstgr.cloud): ...
show more
(mod_security) mod_security (id:210492) triggered by 2a02:4780:75:578c::1 (srv1591828.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 14 19:34:41.948585 2026] [security2:error] [pid 1788:tid 1788] [client 2a02:4780:75:578c::1:51902] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "arkansasbest.com"] [uri "/.env.txt"] [unique_id "aqiEkV2PTSYvINE_S7uMcAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-14 23:04:50
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 2a02:4780:75:578c::1 (srv1591828.hstgr.cloud): ...
show more
(mod_security) mod_security (id:210492) triggered by 2a02:4780:75:578c::1 (srv1591828.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 14 19:04:43.956346 2026] [security2:error] [pid 30284:tid 30284] [client 2a02:4780:75:578c::1:37248] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "angeltarrac.com"] [uri "/.git/config"] [unique_id "aqh9i_kKqRz_TT0Am6rC6gAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ฆ
Vianpyro
2026-09-14 22:42:59
(1 day ago)
Honeypot: 6 request(s) in 0 min. Paths: /.env.bak, /.env.dev, /.env.local, /.env.save, /.env.staging ...
show more
Honeypot: 6 request(s) in 0 min. Paths: /.env.bak, /.env.dev, /.env.local, /.env.save, /.env.staging. Method(s): GET. UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko). ASN: 47583 (Hostinger International Limited).
show less
Hacking
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-14 21:05:42
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 2a02:4780:75:578c::1 (srv1591828.hstgr.cloud): ...
show more
(mod_security) mod_security (id:210492) triggered by 2a02:4780:75:578c::1 (srv1591828.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 14 17:05:33.872807 2026] [security2:error] [pid 28893:tid 28893] [client 2a02:4780:75:578c::1:38970] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.splashstation.org"] [uri "/wp-config.php.txt"] [unique_id "aqhhnZRRtKfbx21HIL4tSQAAADI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-14 09:08:34
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 2a02:4780:75:578c::1 (srv1591828.hstgr.cloud): ...
show more
(mod_security) mod_security (id:210492) triggered by 2a02:4780:75:578c::1 (srv1591828.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 14 05:08:29.767800 2026] [security2:error] [pid 19340:tid 19340] [client 2a02:4780:75:578c::1:52660] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.doreenkimura.com.misscharlottemusic.com"] [uri "/wp-config.php.txt"] [unique_id "aqe5jW4M2s0TToEffkAdmAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack