๐ฉ๐ช
FD-IX
2026-07-22 02:19:06
(1 month ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-20 05:55:16
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 2a09:bac5:9447:3af::5e:75 (Unknown): 1 in the l ...
show more
(mod_security) mod_security (id:210492) triggered by 2a09:bac5:9447:3af::5e:75 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 20 01:55:08.694521 2026] [security2:error] [pid 30462:tid 30462] [client 2a09:bac5:9447:3af::5e:75:31434] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.vittariadesign.com"] [uri "/.env"] [unique_id "al24POzPCEruTHQS5Jfm1AAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-20 05:17:39
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 2a09:bac5:9447:3af::5e:75 (Unknown): 1 in the l ...
show more
(mod_security) mod_security (id:210492) triggered by 2a09:bac5:9447:3af::5e:75 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 20 01:17:34.956107 2026] [security2:error] [pid 367:tid 367] [client 2a09:bac5:9447:3af::5e:75:40828] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.vitess.com"] [uri "/.env.staging"] [unique_id "al2vbov4-SLnQiU-g_LZrAAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Mangelot Hosting
2026-07-19 21:39:42
(2 months ago)
(modsecurity) srv102 ModSecurity 2a09:bac5:9447:3af::5e:75 (US/United States/-): 10 in the last 3600 ...
show more
(modsecurity) srv102 ModSecurity 2a09:bac5:9447:3af::5e:75 (US/United States/-): 10 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs:
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-19 19:29:04
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 2a09:bac5:9447:3af::5e:75 (Unknown): 1 in the l ...
show more
(mod_security) mod_security (id:210492) triggered by 2a09:bac5:9447:3af::5e:75 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 19 15:29:00.223037 2026] [security2:error] [pid 18843:tid 18843] [client 2a09:bac5:9447:3af::5e:75:51516] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.normsrotorservice.com.rotorservice.com"] [uri "/.env"] [unique_id "al0lfEZ-7E4TierEWkijKwAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-07-19 11:46:44
(2 months ago)
Multiple WAF Violations
Web App Attack
๐ฉ๐ช
Magnytu2
2026-07-19 09:31:09
(2 months ago)
tee-17 : Block hidden directories=>/.env(/)
Hacking
๐ฉ๐ช
LRob
2026-07-14 17:03:26
(2 months ago)
CrowdSec: crowdsecurity/http-probing | req: /z9x8c7v6b5-debug-trigger-desfeesenor.fr | 11 distinct p ...
show more
CrowdSec: crowdsecurity/http-probing | req: /z9x8c7v6b5-debug-trigger-desfeesenor.fr | 11 distinct paths | UA: Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)
show less
Port Scan
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-14 17:00:48
(2 months ago)
(mod_security) mod_security (id:949110) triggered by 2a09:bac5:9447:3af::5e:75 (Unknown): 1 in the l ...
show more
(mod_security) mod_security (id:949110) triggered by 2a09:bac5:9447:3af::5e:75 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 14 13:00:36.280193 2026] [security2:error] [pid 16151:tid 16151] [client 2a09:bac5:9447:3af::5e:75:45230] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "desertviewgroupllc.com"] [uri "/.git/HEAD"] [unique_id "alZrNL00Gs0MhKYTGqifRgAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-14 04:21:57
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 2a09:bac5:9447:3af::5e:75 (Unknown): 1 in the l ...
show more
(mod_security) mod_security (id:210492) triggered by 2a09:bac5:9447:3af::5e:75 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 14 00:21:50.569655 2026] [security2:error] [pid 2906:tid 2906] [client 2a09:bac5:9447:3af::5e:75:51640] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.hilarysaundersmusic.tremulant.com"] [uri "/.env"] [unique_id "alW5XiRoGpYdtLRYsGpTGgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-07-14 03:00:20
(2 months ago)
Multiple WAF Violations
Web App Attack
๐ฌ๐ง
Aetherweb Ark
2026-07-14 02:47:45
(2 months ago)
(mod_security) mod_security (id:949110) triggered by 2a09:bac5:9447:3af::5e:75 (Unknown): N in the l ...
show more
(mod_security) mod_security (id:949110) triggered by 2a09:bac5:9447:3af::5e:75 (Unknown): N in the last X secs
show less
Web App Attack
๐ฉ๐ช
filstal.org
2026-07-11 16:49:30
(2 months ago)
Web reconnaissance detected: automated probing for sensitive files, backup archives, admin panels an ...
show more
Web reconnaissance detected: automated probing for sensitive files, backup archives, admin panels and known vulnerability paths.
show less
Hacking
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-11 16:24:11
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 2a09:bac5:9447:3af::5e:75 (Unknown): 1 in the l ...
show more
(mod_security) mod_security (id:210492) triggered by 2a09:bac5:9447:3af::5e:75 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 11 12:24:04.948020 2026] [security2:error] [pid 13580:tid 13580] [client 2a09:bac5:9447:3af::5e:75:49936] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.googhoo.com"] [uri "/.env"] [unique_id "alJuJFYXx8rTHfhWbxSTZAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-11 16:09:08
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 2a09:bac5:9447:3af::5e:75 (Unknown): 1 in the l ...
show more
(mod_security) mod_security (id:210492) triggered by 2a09:bac5:9447:3af::5e:75 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 11 12:09:00.790349 2026] [security2:error] [pid 7256:tid 7256] [client 2a09:bac5:9447:3af::5e:75:12190] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.pjv.us"] [uri "/.env"] [unique_id "alJqnIyzIv9ybS5EOCAiYAAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack