๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-08-01 10:37:20
(13 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
๐ฉ๐ช
XICTRON
2026-08-01 00:10:06
(1 day ago)
ModSecurity rule violation detected by Fail2Ban
Web App Attack
๐ฉ๐ช
Dennis
2026-07-27 12:23:44
(5 days ago)
2a09:bac5:9442:3af::5e:58 has been banned for triggering http-probing (11 events over 382.319693ms).
Brute-Force
Web App Attack
๐ฌ๐ง
Aetherweb Ark
2026-07-27 11:43:15
(5 days ago)
(mod_security) mod_security (id:949110) triggered by 2a09:bac5:9442:3af::5e:58 (Unknown): N in the l ...
show more
(mod_security) mod_security (id:949110) triggered by 2a09:bac5:9442:3af::5e:58 (Unknown): N in the last X secs
show less
Web App Attack
Anonymous
2026-07-25 16:32:26
(1 week ago)
Failed login attempt detected by Fail2Ban in plesk-modsecurity jail
Exploited Host
๐บ๐ธ
TPI-Abuse
2026-07-25 03:49:52
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 2a09:bac5:9442:3af::5e:58 (Unknown): 1 in the l ...
show more
(mod_security) mod_security (id:210492) triggered by 2a09:bac5:9442:3af::5e:58 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 23:49:46.654785 2026] [security2:error] [pid 3818229:tid 3818229] [client 2a09:bac5:9442:3af::5e:58:22448] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.alltrashremoval.com"] [uri "/.env"] [unique_id "amQyWh8wG7FuMY8TwIJgIAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
maxpower
2026-07-24 12:55:14
(1 week ago)
(nginx_hardened) REGOLA 3 - Nginx Hardening Triggered 2a09:bac5:9442:3af::5e:58 (US/United States/-) ...
show more
(nginx_hardened) REGOLA 3 - Nginx Hardening Triggered 2a09:bac5:9442:3af::5e:58 (US/United States/-): 3 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 2026/07/24 14:55:08 [error] 2173931#2173931: *498724 access forbidden by rule, client: 2a09:bac5:9442:3af::5e:58, server: spacehosting.ovh, request: "GET /wp-config.php~ HTTP/1.1", host: "spacehosting.ovh"
2026/07/24 14:55:09 [error] 2173927#2173927: *498769 access forbidden by rule, client: 2a09:bac5:9442:3af::5e:58, server: spacehosting.ovh, request: "GET /wp-config.php HTTP/1.1", host: "spacehosting.ovh"
2026/07/24 14:55:09 [error] 2173931#2173931: *498770 access forbidden by rule, client: 2a09:bac5:9442:3af::5e:58, server: spacehosting.ovh, request: "GET /wp-config.php.old HTTP/1.1", host: "spacehosting.ovh"
show less
Port Scan
๐ฉ๐ช
dbmwebdesign
2026-07-23 06:00:10
(1 week ago)
WAF repeated trigger detected by Fail2Ban in plesk-modsecurity jail
Web App Attack
๐ช๐ธ
alferez
2026-07-23 05:45:20
(1 week ago)
Searching .(env|sql|zip|tar|rar) files
Hacking
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-23 05:42:57
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 2a09:bac5:9442:3af::5e:58 (Unknown): 1 in the l ...
show more
(mod_security) mod_security (id:210492) triggered by 2a09:bac5:9442:3af::5e:58 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 23 01:42:52.255391 2026] [security2:error] [pid 1940334:tid 1940334] [client 2a09:bac5:9442:3af::5e:58:58422] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.miszewski.com"] [uri "/.env"] [unique_id "amGp3FB56tQKn3_IRgqyrAAAACY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-23 03:12:59
(1 week ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-23 01:55:16
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 2a09:bac5:9442:3af::5e:58 (Unknown): 1 in the l ...
show more
(mod_security) mod_security (id:210492) triggered by 2a09:bac5:9442:3af::5e:58 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 22 21:55:11.179258 2026] [security2:error] [pid 2985462:tid 2985462] [client 2a09:bac5:9442:3af::5e:58:48284] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.tekbit.com"] [uri "/.env"] [unique_id "amF0f7VWXfrOV4eF_EGLFgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-23 00:33:57
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 2a09:bac5:9442:3af::5e:58 (Unknown): 1 in the l ...
show more
(mod_security) mod_security (id:210492) triggered by 2a09:bac5:9442:3af::5e:58 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 22 20:33:54.291586 2026] [security2:error] [pid 2762246:tid 2762246] [client 2a09:bac5:9442:3af::5e:58:26346] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.fiyaplatform.com"] [uri "/.env"] [unique_id "amFhcmYQbcrnhU5cNhT3vwAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
ecs.ge
2026-07-23 00:31:45
(1 week ago)
Automatic Fail2Ban report from jail plesk-modsecurity: multiple matching events detected.
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-07-22 23:37:05
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 2a09:bac5:9442:3af::5e:58 (Unknown): 1 in the l ...
show more
(mod_security) mod_security (id:210492) triggered by 2a09:bac5:9442:3af::5e:58 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 22 19:36:59.700164 2026] [security2:error] [pid 2131497:tid 2131519] [client 2a09:bac5:9442:3af::5e:58:54798] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.mecconsultant.com"] [uri "/.env"] [unique_id "amFUG5mPZsGfgwZ7rrRQdAAAAJQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack