๐บ๐ธ
TPI-Abuse
2026-08-31 04:23:37
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 31.44.189.198 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 31.44.189.198 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 00:23:31.422857 2026] [security2:error] [pid 24953:tid 24953] [client 31.44.189.198:35765] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "longhandmedia.com"] [uri "/.env"] [unique_id "apUBw0phDavkRQI7mFvc8QAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ฐ
HostingGroup
2026-08-20 03:16:53
(1 week ago)
Automated malicious activity (Honeypot Trap) detected and blocked at the CDN edge by NordicCDN Shiel ...
show more
Automated malicious activity (Honeypot Trap) detected and blocked at the CDN edge by NordicCDN Shield. Offenses: 1. First blocked: 2026-08-20.
show less
Bad Web Bot
Web App Attack
๐ฎ๐น
CoreTech srl
2026-08-15 14:33:57
(2 weeks ago)
cloudlinux2 fail2ban: 2026-08-15 16:29:18,015 fail2ban.filter [1695]: INFO [plesk-wordpre ...
show more
cloudlinux2 fail2ban: 2026-08-15 16:29:18,015 fail2ban.filter [1695]: INFO [plesk-wordpress] Found 209.42.21.22 - 2026-08-15 16:29:17cloudlinux2 fail2ban: 2026-08-15 16:30:01,211 fail2ban.filter [1695]: INFO [plesk-wordpress] Found 216.24.219.145 - 2026-08-15 16:29:59cloudlinux2 fail2ban: 2026-08-15 16:31:16,662 fail2ban.filter [1695]: INFO [plesk-wordpress] Found 91.193.232.14 - 2026-08-15 16:31:16cloudlinux2 fail2ban: 2026-08-15 16:31:12,380 fail2ban.filter [1695]: INFO [plesk-wordpress] Found 91.193.232.14 - 2026-08-15 16:31:11cloudlinux2 fail2ban: 2026-08-15 16:31:23,601 fail2ban.actions [1695]: NOTICE [plesk-modsecurity] Unban 212.81.36.165cloudlinux2 fail2ban: 2026-08-15 16:31:21,586 fail2ban.actions [1695]: NOTICE [plesk-modsecurity] Unban 88.218.73.115cloudlinux2 fail2ban: 2026-08-15 16:31:28,218 fail2ban.actions [1695]: NOTICE [plesk-modsecurity] Unban 193.31.102.115cloudlinux2 fail2ban: 2026-08-15 16:31:56,652 fail2ban.filter
show less
Web App Attack
๐ฎ๐ฑ
spd.co.il
2026-08-12 17:01:54
(2 weeks ago)
Web application attack detected
Hacking
Web App Attack
๐บ๐ธ
kosada.com
2026-08-01 20:44:17
(4 weeks ago)
Web vulnerability probing: /.env.development
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-21 16:54:26
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 31.44.189.198 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 31.44.189.198 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 21 12:54:20.792246 2026] [security2:error] [pid 22497:tid 22507] [client 31.44.189.198:51486] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "paversealservices.com"] [uri "/.env.swp"] [unique_id "ajgXPMllVdugM446C3whvgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-06-19 21:59:07
(2 months ago)
Auto-ban: >3000 req/min op 2026-06-19
Web App Attack
SSH
Hacking
๐บ๐ธ
mnsf
2026-06-17 00:06:38
(2 months ago)
Abuse Detected (21)
Brute-Force
Web App Attack
๐ฑ๐ป
garmtech.com
2026-06-12 08:54:12
(2 months ago)
IM360 WAF: Direct access to sensitive file or dotfile MV:/.env
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-05 23:29:53
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 31.44.189.198 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 31.44.189.198 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 05 19:29:50.196829 2026] [security2:error] [pid 23033:tid 23033] [client 31.44.189.198:59579] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ohioprocleaners.com"] [uri "/.env"] [unique_id "aiNb7poU0OPT47laJwV2RAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ธ๐ฌ
securejdprop
2026-06-05 04:00:31
(2 months ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files. Ip 31.44.189.198 per ...
show more
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files. Ip 31.44.189.198 performed 'crowdsecurity/http-sensitive-files' (5 events over 1.704470444s) at 2026-06-05 04:00:29.882881946 +0000 UTC
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-09 04:25:54
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 31.44.189.198 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 31.44.189.198 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 09 00:25:50.730406 2026] [security2:error] [pid 26028:tid 26028] [client 31.44.189.198:41116] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "tribeconnect.info"] [uri "/.env"] [unique_id "af63Tq9Bu1-4pCnTkdhV5QAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-04-05 02:52:22
(4 months ago)
BAD BOT - Detected and Blocked.. Matched phrase "python" at REQUEST_HEADERS:User-Agent. (1100000-201 ...
show more
BAD BOT - Detected and Blocked.. Matched phrase "python" at REQUEST_HEADERS:User-Agent. (1100000-201)
show less
Bad Web Bot
๐ฌ๐ง
consul.to
2026-03-28 16:10:57
(5 months ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ธ
mnsf
2026-03-12 15:06:36
(5 months ago)
Scanning/Probing (30)
Brute-Force
Web App Attack