🇮🇹
mediarama.com
2026-08-26 17:37:30
(3 days ago)
Banned by Fail2Ban
Web App Attack
🇮🇩
Burayot
2026-08-26 17:36:45
(3 days ago)
LF_MODSEC: (mod_security) mod_security (id:949110) triggered by 34.125.48.123 (US/United States/123. ...
show more
LF_MODSEC: (mod_security) mod_security (id:949110) triggered by 34.125.48.123 (US/United States/123.48.125.34.bc.googleusercontent.com): 1 in the last 3600 secs
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-08-26 16:44:38
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.125.48.123 (123.48.125.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.125.48.123 (123.48.125.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 12:44:31.478997 2026] [security2:error] [pid 3939:tid 3939] [client 34.125.48.123:47010] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "nowell.net"] [uri "/static../.env"] [unique_id "ao8X78lxJ8mEZ21jEVCUywAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇸🇪
vaia.cloud
2026-08-26 15:20:02
(3 days ago)
crowdsecurity/http-wordpress_wpconfig
Brute-Force
Web App Attack
🇳🇱
Site.eu
2026-08-26 13:05:43
(3 days ago)
Excessive multi-domain requests
Brute-Force
🇩🇪
maxpower
2026-08-26 12:53:07
(3 days ago)
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 34.125.48.123 (US/United States/123.48.1 ...
show more
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 34.125.48.123 (US/United States/123.48.125.34.bc.googleusercontent.com): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 34.125.48.123 - - [26/Aug/2026:14:53:04 +0200] "GET /aws/credentials HTTP/2.0" 403 207 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.7069.191 Safari/537.36; compatible; Amzn-SearchBot/1.0; +https://developer.amazon.com/support/amazonbot" "34.125.48.123" host=conapipescara.it
show less
Port Scan
🇮🇹
VHosting
2026-08-26 12:50:08
(3 days ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-08-26 12:47:52
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.125.48.123 (123.48.125.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.125.48.123 (123.48.125.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 08:47:46.146095 2026] [security2:error] [pid 2785:tid 2785] [client 34.125.48.123:19918] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "7livesahead.com"] [uri "/static../.env"] [unique_id "ao7gcmBPLpK_Q-3KCemO9gAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇮🇹
CoreTech srl
2026-08-26 12:28:57
(3 days ago)
cloudlinux2 fail2ban: 2026-08-26 14:24:05,872 fail2ban.filter [1775]: INFO [plesk-modsecu ...
show more
cloudlinux2 fail2ban: 2026-08-26 14:24:05,872 fail2ban.filter [1775]: INFO [plesk-modsecurity] Found 223.181.25.20 - 2026-08-26 14:24:05cloudlinux2 fail2ban: 2026-08-26 14:24:06,069 fail2ban.actions [1775]: NOTICE [plesk-modsecurity] Ban 223.181.25.20cloudlinux2 fail2ban: 2026-08-26 14:24:06,077 fail2ban.filter [1775]: INFO [recidive] Found 223.181.25.20 - 2026-08-26 14:24:06cloudlinux2 fail2ban: 2026-08-26 14:24:14,995 fail2ban.filter [1775]: INFO [plesk-modsecurity] Found 153.117.36.102 - 2026-08-26 14:24:14cloudlinux2 fail2ban: 2026-08-26 14:25:07,880 fail2ban.filter [1775]: INFO [plesk-modsecurity] Found 153.117.36.102 - 2026-08-26 14:25:07cloudlinux2 fail2ban: 2026-08-26 14:25:18,782 fail2ban.filter [1775]: INFO [recidive] Found 153.117.36.102 - 2026-08-26 14:25:18cloudlinux2 fail2ban: 2026-08-26 14:25:18,775 fail2ban.actions [1775]: NOTICE [plesk-modsecurity] Ban 153.117.36.102cloudlinux2 fail2ban: 2026-08-26 14:25:18,441 fail2ban.fi
show less
Brute-Force
🇺🇸
TPI-Abuse
2026-08-26 11:15:57
(3 days ago)
(mod_security) mod_security (id:211190) triggered by 34.125.48.123 (123.48.125.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:211190) triggered by 34.125.48.123 (123.48.125.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 07:15:52.580154 2026] [security2:error] [pid 19290:tid 19290] [client 34.125.48.123:16842] ModSecurity: Access denied with code 403 (phase 2). Match of "contains cpanel" against "REQUEST_URI" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "55"] [id "211190"] [rev "9"] [msg "COMODO WAF: Remote File Access Attempt||mail.wailthelifeofbudpowell.com|F|2"] [data "Matched Data: /etc/ found within REQUEST_URI: /download?file=../../../../etc/passwd"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.wailthelifeofbudpowell.com"] [uri "/download"] [unique_id "ao7K6KXertcVOb6z-AA_oAAAAI0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-26 10:04:22
(3 days ago)
(mod_security) mod_security (id:211190) triggered by 34.125.48.123 (123.48.125.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:211190) triggered by 34.125.48.123 (123.48.125.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 06:04:18.139645 2026] [security2:error] [pid 3721634:tid 3722142] [client 34.125.48.123:49726] ModSecurity: Access denied with code 403 (phase 2). Match of "contains cpanel" against "REQUEST_URI" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "55"] [id "211190"] [rev "9"] [msg "COMODO WAF: Remote File Access Attempt||jpdesign.us|F|2"] [data "Matched Data: /etc/ found within REQUEST_URI: /?file=../../../../etc/passwd"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jpdesign.us"] [uri "/"] [unique_id "ao66Ilg18Sa8safm3op65QAAAko"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇯🇵
ki3
2026-08-26 09:34:21
(3 days ago)
Fail2Ban: Web App Attacks and Forum Spam 34.125.48.123 1787736860.0(JST)
Web Spam
Bad Web Bot
Web App Attack
🇫🇷
Octopuce
2026-08-26 08:51:47
(3 days ago)
Aggressive web search of vulnerable pages: /.env /app/.env /static../.env /media../.env /.env.local ...
show more
Aggressive web search of vulnerable pages: /.env /app/.env /static../.env /media../.env /.env.local ...
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-08-26 07:21:41
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.125.48.123 (123.48.125.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.125.48.123 (123.48.125.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 03:21:33.425900 2026] [security2:error] [pid 25375:tid 25375] [client 34.125.48.123:43606] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.graphiccraftswoman.com"] [uri "/media../.env"] [unique_id "ao6T_Xxbk9XuWbRjKgfDAAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
consul.to
2026-08-26 06:32:29
(3 days ago)
Web attack/malicious scanning detected
Web App Attack