๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-08-01 16:55:48
(2 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
Anonymous
2026-07-27 18:11:07
(5 days ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-27 17:49:21
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 2a09:bac1:76c0:460::5e:7b (Unknown): 1 in the l ...
show more
(mod_security) mod_security (id:210492) triggered by 2a09:bac1:76c0:460::5e:7b (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 13:49:17.145290 2026] [security2:error] [pid 4184217:tid 4184217] [client 2a09:bac1:76c0:460::5e:7b:43072] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.blackhorrormovie.fractalsky.com"] [uri "/.env"] [unique_id "ameaHaWueCKB4O_Ru0PLjgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-27 17:19:49
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 2a09:bac1:76c0:460::5e:7b (Unknown): 1 in the l ...
show more
(mod_security) mod_security (id:210492) triggered by 2a09:bac1:76c0:460::5e:7b (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 13:19:42.154048 2026] [security2:error] [pid 568163:tid 568163] [client 2a09:bac1:76c0:460::5e:7b:51518] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.weddings.jamesallenwalker.com"] [uri "/.env"] [unique_id "ameTLl5UfdGXul1hAtlXlgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
filstal.org
2026-07-25 21:38:37
(6 days ago)
Web reconnaissance detected: automated probing for sensitive files, backup archives, admin panels an ...
show more
Web reconnaissance detected: automated probing for sensitive files, backup archives, admin panels and known vulnerability paths.
show less
Hacking
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-25 20:40:20
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 2a09:bac1:76c0:460::5e:7b (Unknown): 1 in the l ...
show more
(mod_security) mod_security (id:210492) triggered by 2a09:bac1:76c0:460::5e:7b (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 25 16:40:13.241911 2026] [security2:error] [pid 667292:tid 667292] [client 2a09:bac1:76c0:460::5e:7b:23700] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ipv6.onlineteacher.info"] [uri "/.env"] [unique_id "amUfLRnHY_BPuP9xLy1OzgAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-25 20:06:33
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 2a09:bac1:76c0:460::5e:7b (Unknown): 1 in the l ...
show more
(mod_security) mod_security (id:210492) triggered by 2a09:bac1:76c0:460::5e:7b (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 25 16:06:26.815357 2026] [security2:error] [pid 3278367:tid 3278367] [client 2a09:bac1:76c0:460::5e:7b:13100] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cubbylure.com"] [uri "/wp-config.php.bak"] [unique_id "amUXQq7bCSRG2E_XzH2-YAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-23 01:50:32
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 2a09:bac1:76c0:460::5e:7b (Unknown): 1 in the l ...
show more
(mod_security) mod_security (id:210492) triggered by 2a09:bac1:76c0:460::5e:7b (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 22 21:50:26.457635 2026] [security2:error] [pid 1599730:tid 1599730] [client 2a09:bac1:76c0:460::5e:7b:27070] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.495metro.com"] [uri "/.env"] [unique_id "amFzYpE3y-yueBtyqH7YuAAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-07-22 23:06:44
(1 week ago)
Multiple WAF Violations
Web App Attack
๐ฌ๐ง
Marten Mark
2026-07-19 06:06:46
(1 week ago)
2a09:bac1:76c0:460::5e:7b - - [19/Jul/2026:06:06:45 +0000] "GET /.aws/credentials HTTP/2.0" 500 174 ...
show more
2a09:bac1:76c0:460::5e:7b - - [19/Jul/2026:06:06:45 +0000] "GET /.aws/credentials HTTP/2.0" 500 174 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:149.0) Gecko/20100101 Firefox/149.0"
...
show less
Web App Attack
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-07-19 05:56:01
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 2a09:bac1:76c0:460::5e:7b (Unknown): 1 in the l ...
show more
(mod_security) mod_security (id:210492) triggered by 2a09:bac1:76c0:460::5e:7b (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 19 01:55:54.544539 2026] [security2:error] [pid 8594:tid 8600] [client 2a09:bac1:76c0:460::5e:7b:40408] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.philacentric.com"] [uri "/.env"] [unique_id "alxm6tWJrwWFJ1Fc7VgpbgAAAEE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-19 05:30:41
(1 week ago)
(mod_security) mod_security (id:949110) triggered by 2a09:bac1:76c0:460::5e:7b (Unknown): 1 in the l ...
show more
(mod_security) mod_security (id:949110) triggered by 2a09:bac1:76c0:460::5e:7b (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 19 01:30:37.659399 2026] [security2:error] [pid 1376542:tid 1376542] [client 2a09:bac1:76c0:460::5e:7b:11190] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "mail.captaincookfj.com"] [uri "/.env"] [unique_id "alxg_ZMhyMuRXctdNNUDCgAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-16 21:20:03
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 2a09:bac1:76c0:460::5e:7b (Unknown): 1 in the l ...
show more
(mod_security) mod_security (id:210492) triggered by 2a09:bac1:76c0:460::5e:7b (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 16 17:19:57.801404 2026] [security2:error] [pid 12756:tid 12756] [client 2a09:bac1:76c0:460::5e:7b:39772] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.yevid.com"] [uri "/.env"] [unique_id "allK_VVoSTB1VpiBMMtVaAAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-07-16 09:06:01
(2 weeks ago)
Multiple WAF Violations
Web App Attack
๐ฉ๐ฐ
HostingGroup
2026-07-15 20:47:17
(2 weeks ago)
Automated malicious activity (Honeypot Trap) detected and blocked at the CDN edge by NordicCDN Shiel ...
show more
Automated malicious activity (Honeypot Trap) detected and blocked at the CDN edge by NordicCDN Shield. Offenses: 6. First blocked: 2026-07-15.
show less
Bad Web Bot
Web App Attack