Anonymous
2026-08-28 04:35:28
(3 hours ago)
Failed login attempt detected by Fail2Ban in plesk-modsecurity jail
Exploited Host
๐ฌ๐ง
kie
2026-08-27 21:28:56
(10 hours ago)
27-08-2026:21:28:34UTC [Nginx Web Server] Suspicious web request: path:/.env path:/actuator/ path:/w ...
show more
27-08-2026:21:28:34UTC [Nginx Web Server] Suspicious web request: path:/.env path:/actuator/ path:/wp-config (15 request(s)).
show less
Bad Web Bot
Web App Attack
๐ณ๐ฑ
oisecnet
2026-08-27 21:03:50
(11 hours ago)
Automated report: Unauthorized vulnerability scanning detected on 2026-08-27. 762 requests from this ...
show more
Automated report: Unauthorized vulnerability scanning detected on 2026-08-27. 762 requests from this IP.
show less
Port Scan
Hacking
Web App Attack
๐ฉ๐ช
neckaralb-admin.de
2026-08-27 19:09:24
(13 hours ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
Anonymous
2026-08-27 18:13:08
(14 hours ago)
(mod_security) mod_security triggered on hostname [redacted])
SQL Injection
๐บ๐ธ
Rocky Mountain Bioengineering Symposium
2026-08-27 17:36:32
(14 hours ago)
[Thu Aug 27 11:36:31.335919 2026] [authz_core:error] [pid 1028068:tid 139833137628736] [client 34.12 ...
show more
[Thu Aug 27 11:36:31.335919 2026] [authz_core:error] [pid 1028068:tid 139833137628736] [client 34.12.8.212:54952] AH01630: client denied by server configuration: /var/www/horde/wp-config.php.bak
[Thu Aug 27 11:36:31.339224 2026] [authz_core:error] [pid 1028068:tid 139832927811136] [client 34.12.8.212:55028] AH01630: client denied by server configuration: /var/www/horde/wp-config.php.swp
[Thu Aug 27 11:36:31.344754 2026] [authz_core:error] [pid 1028068:tid 139832768349760] [client 34.12.8.212:55076] AH01630: client denied by server configuration: /var/www/horde/.env.bak
...
show less
Bad Web Bot
๐ท๐บ
DZBOT
2026-08-27 16:23:53
(15 hours ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 13:52:12
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.12.8.212 (212.8.12.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.12.8.212 (212.8.12.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 09:52:07.906106 2026] [security2:error] [pid 4941:tid 4941] [client 34.12.8.212:48614] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "erinakhan-design.org"] [uri "/.env.save"] [unique_id "apBBB4ZBrRFlJ-YHhSgrNwAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 13:16:03
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.12.8.212 (212.8.12.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.12.8.212 (212.8.12.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 09:15:57.284071 2026] [security2:error] [pid 14224:tid 14224] [client 34.12.8.212:55060] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.saveourstats.com"] [uri "/.env.prod"] [unique_id "apA4jZJxNt7QIe-oCpG1oAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
maxpower
2026-08-27 13:08:04
(19 hours ago)
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 34.12.8.212 (212.8.12.34.bc.googleuserco ...
show more
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 34.12.8.212 (212.8.12.34.bc.googleusercontent.com): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 34.12.8.212 - - [27/Aug/2026:15:07:59 +0200] "GET /wp-config.php.bak HTTP/1.1" 200 11890 "-" "crusader-worker/1.0" "-" host=dolibarrtest.checkall.cloud
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-08-27 12:53:11
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.12.8.212 (212.8.12.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.12.8.212 (212.8.12.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 08:53:03.839252 2026] [security2:error] [pid 20661:tid 20661] [client 34.12.8.212:49632] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "stantontownship.org"] [uri "/wp-config.php.bak"] [unique_id "apAzL7BVz4J4KeKQw8uC2QAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 11:05:13
(21 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.12.8.212 (212.8.12.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.12.8.212 (212.8.12.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 07:05:05.080197 2026] [security2:error] [pid 1163:tid 1163] [client 34.12.8.212:49744] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.newlifeaccommodation.intnlc.org"] [uri "/.env.prod"] [unique_id "apAZ4RH98C2MpJ3Jf2aqaAAAACA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 09:34:36
(22 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.12.8.212 (212.8.12.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.12.8.212 (212.8.12.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 05:34:28.406922 2026] [security2:error] [pid 17917:tid 17917] [client 34.12.8.212:33446] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "timelord2067.com"] [uri "/wp-config.php.bak"] [unique_id "apAEpKeCOLtK5doRb-GwOAAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-27 09:05:02
(23 hours ago)
suspicious request in access.log
Web App Attack
๐ซ๐ฎ
paissangroup
2026-08-27 08:33:31
(23 hours ago)
Multiple WAF Violations
Web App Attack