Anonymous
2026-09-09 13:35:17
(1 hour ago)
Failed login attempt detected by Fail2Ban in plesk-modsecurity jail
Exploited Host
🇺🇦
URAN Publishing Service
2026-09-09 13:09:03
(1 hour ago)
[09/Sep/2026:16:09:01 +0300] -- 34.12.239.86 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET /@ ...
show more
[09/Sep/2026:16:09:01 +0300] -- 34.12.239.86 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET /@fs/root/.env?raw?? HTTP/1.1
show less
Bad Web Bot
Web App Attack
🇬🇧
thetomtaylor.co.uk
2026-09-09 13:08:01
(1 hour ago)
Fail2Ban - [WAF]ModSecurity OWASP CRS rule violation on nginx-modsecurity ... [ice01,ice02,wa01,wa02 ...
show more
Fail2Ban - [WAF]ModSecurity OWASP CRS rule violation on nginx-modsecurity ... [ice01,ice02,wa01,wa02]
show less
Hacking
SQL Injection
Web App Attack
🇩🇪
BlueWire Hosting
2026-09-09 12:50:53
(2 hours ago)
High-confidence malicious configuration/VCS probe
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 12:25:32
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.12.239.86 (86.239.12.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.12.239.86 (86.239.12.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 08:25:28.500866 2026] [security2:error] [pid 7509:tid 7509] [client 34.12.239.86:21548] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.kurikka.net"] [uri "/@fs/.env"] [unique_id "aqFQONqU-5EBI5CHHLK8kQAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
pscriptos
2026-09-09 12:20:30
(2 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-09 11:58:17
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.12.239.86 (86.239.12.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.12.239.86 (86.239.12.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 07:58:11.556141 2026] [security2:error] [pid 907:tid 907] [client 34.12.239.86:17282] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "natesupport.com"] [uri "/@fs/.env"] [unique_id "aqFJ04Q9HY8JHZc4AYRZPwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 11:40:55
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.12.239.86 (86.239.12.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.12.239.86 (86.239.12.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 07:40:51.574389 2026] [security2:error] [pid 29237:tid 29237] [client 34.12.239.86:48418] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.whiteweddinginvitations.net"] [uri "/@fs/root/.env"] [unique_id "aqFFw0-ndMHz6AIKBq0x5gAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇧🇾
lns.bz
2026-09-09 10:58:59
(3 hours ago)
Too many 404 requests [BY]
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 10:35:36
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.12.239.86 (86.239.12.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.12.239.86 (86.239.12.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 06:35:32.725427 2026] [security2:error] [pid 22636:tid 22636] [client 34.12.239.86:37126] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.clarktec.com"] [uri "/@fs/app/.env"] [unique_id "aqE2dENsLEnOKcbYI2s1XgAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
masterguru
2026-09-09 09:59:48
(4 hours ago)
Restricted File Access Attempt. Matched phrase "/@fs/" at REQUEST_FILENAME. (930130-193)
Hacking
Web App Attack
🇩🇪
bescared
2026-09-09 09:47:38
(5 hours ago)
F2B - Malicious activity detected. URL Probing. -8ff06ede-
Hacking
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 09:15:03
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.12.239.86 (86.239.12.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.12.239.86 (86.239.12.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 05:14:57.549860 2026] [security2:error] [pid 25376:tid 25376] [client 34.12.239.86:28672] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.kmp.net"] [uri "/@fs/src/.env"] [unique_id "aqEjkRHVlBAYvQfEwY-sIAAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
venus.launch.bz
2026-09-09 09:13:35
(5 hours ago)
(mod_security) mod_security triggered on hostname [redacted] 34.12.239.86 (86.239.12.34.bc.googleuse ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.12.239.86 (86.239.12.34.bc.googleusercontent.com)
show less
SQL Injection
🇺🇸
TPI-Abuse
2026-09-09 08:33:07
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.12.239.86 (86.239.12.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.12.239.86 (86.239.12.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 04:33:04.213263 2026] [security2:error] [pid 1288:tid 1288] [client 34.12.239.86:28296] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.patrickconklin.com"] [uri "/@fs/.env"] [unique_id "aqEZwN6PhtaFJk4zDgbB0gAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack