๐ฉ๐ช
FD-IX
2026-08-29 11:47:51
(1 month ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
๐ฉ๐ช
XICTRON
2026-08-26 13:55:04
(1 month ago)
ModSecurity rule violation detected by Fail2Ban
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-29 14:45:44
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 2a09:bac1:76c0:480::501:10 (Unknown): 1 in the ...
show more
(mod_security) mod_security (id:210492) triggered by 2a09:bac1:76c0:480::501:10 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 29 10:45:39.480587 2026] [security2:error] [pid 3308301:tid 3308301] [client 2a09:bac1:76c0:480::501:10:49024] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.bhsp.nashes.net"] [uri "/.env"] [unique_id "amoSEyA_kctB9ezS3CdcgAAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-29 14:18:19
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 2a09:bac1:76c0:480::501:10 (Unknown): 1 in the ...
show more
(mod_security) mod_security (id:210492) triggered by 2a09:bac1:76c0:480::501:10 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 29 10:18:11.676427 2026] [security2:error] [pid 669563:tid 669563] [client 2a09:bac1:76c0:480::501:10:31216] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.app.wholesalelivelobsters.com"] [uri "/.env"] [unique_id "amoLo1cyQ3NtOShYP03v5QAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-29 13:26:18
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 2a09:bac1:76c0:480::501:10 (Unknown): 1 in the ...
show more
(mod_security) mod_security (id:210492) triggered by 2a09:bac1:76c0:480::501:10 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 29 09:26:09.296919 2026] [security2:error] [pid 2963457:tid 2963457] [client 2a09:bac1:76c0:480::501:10:18344] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.brooklyntrademarklawyers.karenbernsteinlaw.net"] [uri "/wp-config.php"] [unique_id "amn_cWGiV69RvC9aX0XIpQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-07-29 13:16:10
(2 months ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-29 13:08:56
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 2a09:bac1:76c0:480::501:10 (Unknown): 1 in the ...
show more
(mod_security) mod_security (id:210492) triggered by 2a09:bac1:76c0:480::501:10 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 29 09:08:51.691956 2026] [security2:error] [pid 1306760:tid 1306760] [client 2a09:bac1:76c0:480::501:10:40770] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.positivesingleconnections.banis-associates.com"] [uri "/.env"] [unique_id "amn7Yx4ws0oJQ7DdBCPrzQAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-07-27 23:51:17
(2 months ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐บ๐ธ
WellSpring
2026-07-20 09:23:04
(2 months ago)
good bot honeypot on 928.today/.openclaw/.env โ WellSpr.ing/NetSentinel civic-AI security layer
Bad Web Bot
๐ณ๐ฑ
homeshowdomain.nl
2026-07-19 22:03:07
(2 months ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-07-18.
show less
Web App Attack
SSH
Hacking
๐ณ๐ฑ
Site.eu
2026-07-16 04:34:26
(2 months ago)
Excessive 404/403 errors
Brute-Force
๐ณ๐ฑ
Site.eu
2026-07-14 14:47:44
(2 months ago)
Excessive 404/403 errors
Brute-Force
๐ณ๐ฑ
Savvii
2026-07-11 04:32:51
(2 months ago)
20 attempts against mh-misbehave-ban on burne
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
arthome.info
2026-07-09 21:41:00
(2 months ago)
404 /terraform.tfstate "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; GPTBot/1.2; ...
show more
404 /terraform.tfstate "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; GPTBot/1.2; +https://openai.com/gptbot"
404 /.s3cfg "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
404 /.ssh/id_dsa "Mozilla/5.0 (compatible; Google-Extended/1.0; +http://www.google.com/bot.html)"
and 40 other 404's
show less
Port Scan
๐ฉ๐ช
XICTRON
2026-07-09 13:50:05
(2 months ago)
ModSecurity rule violation detected by Fail2Ban
Web App Attack