π©πͺ
LRob.fr
2026-05-14 23:15:16
(1 month ago)
Repeated 404 errors, blocked by Fail2ban in custom-404 jail
Bad Web Bot
π³π±
homeshowdomain.nl
2026-05-14 22:01:17
(1 month ago)
Auto-ban: 203 malicious requests on 2026-05-13 (e.g., env/backup probes, brute-force, or error burst ...
show more
Auto-ban: 203 malicious requests on 2026-05-13 (e.g., env/backup probes, brute-force, or error bursts).
show less
Web App Attack
SSH
Hacking
πΊπΈ
mnsf
2026-05-14 21:06:01
(1 month ago)
Too many Status 40X (17)
Scanning/Probing (11)
Brute-Force
Web App Attack
Anonymous
2026-05-14 15:09:11
(1 month ago)
(caddyscan) Scanner path probe from 34.146.46.249 (JP/Japan/249.46.146.34.bc.googleusercontent.com): ...
show more
(caddyscan) Scanner path probe from 34.146.46.249 (JP/Japan/249.46.146.34.bc.googleusercontent.com): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 2627 34.146.46.249 - - [14/May/2026:15:09:05 +0000] "GET /.env.zip HTTP/1.1"
[REDACTED] 200 2627 34.146.46.249 - - [14/May/2026:15:09:06 +0000] "GET /.env.tar.gz HTTP/1.1"
[REDACTED] 200 2627 34.146.46.249 - - [14/May/2026:15:09:07 +0000] "GET /.env.tgz HTTP/1.1"
[REDACTED] 200 2627 34.146.46.249 - - [14/May/2026:15:09:08 +0000] "GET /.env.tar HTTP/1.1"
[REDACTED] 200 2627 34.146.46.249 - - [14/May/2026:15:09:09 +0000] "GET /.env.tar.bz2 HTTP/1.1"
show less
Port Scan
Anonymous
2026-05-14 12:33:30
(1 month ago)
(caddyscan) Scanner path probe from 34.146.46.249 (JP/Japan/249.46.146.34.bc.googleusercontent.com): ...
show more
(caddyscan) Scanner path probe from 34.146.46.249 (JP/Japan/249.46.146.34.bc.googleusercontent.com): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 2627 34.146.46.249 - - [14/May/2026:12:33:23 +0000] "GET /.env.zip HTTP/1.1"
[REDACTED] 200 2627 34.146.46.249 - - [14/May/2026:12:33:24 +0000] "GET /.env.tar.gz HTTP/1.1"
[REDACTED] 200 2627 34.146.46.249 - - [14/May/2026:12:33:25 +0000] "GET /.env.tgz HTTP/1.1"
[REDACTED] 200 2627 34.146.46.249 - - [14/May/2026:12:33:27 +0000] "GET /.env.tar HTTP/1.1"
[REDACTED] 200 2627 34.146.46.249 - - [14/May/2026:12:33:28 +0000] "GET /.env.tar.bz2 HTTP/1.1"
show less
Port Scan
πΊπΈ
TPI-Abuse
2026-05-14 09:00:07
(1 month ago)
(mod_security) mod_security (id:210730) triggered by 34.146.46.249 (249.46.146.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.146.46.249 (249.46.146.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 14 05:00:01.454595 2026] [security2:error] [pid 8757:tid 8757] [client 34.146.46.249:36170] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||www.jussetcotradinglimited.co|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.jussetcotradinglimited.co"] [uri "/api.sql"] [unique_id "agWPEbljumuTc1cxEajF2AAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-05-14 08:25:43
(1 month ago)
(caddyscan) Scanner path probe from 34.146.46.249 (JP/Japan/249.46.146.34.bc.googleusercontent.com): ...
show more
(caddyscan) Scanner path probe from 34.146.46.249 (JP/Japan/249.46.146.34.bc.googleusercontent.com): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 2627 34.146.46.249 - - [14/May/2026:08:25:36 +0000] "GET /.env.zip HTTP/1.1"
[REDACTED] 200 2627 34.146.46.249 - - [14/May/2026:08:25:36 +0000] "GET /.env.tar.gz HTTP/1.1"
[REDACTED] 200 2627 34.146.46.249 - - [14/May/2026:08:25:37 +0000] "GET /.env.tgz HTTP/1.1"
[REDACTED] 200 2627 34.146.46.249 - - [14/May/2026:08:25:38 +0000] "GET /.env.tar HTTP/1.1"
[REDACTED] 200 2627 34.146.46.249 - - [14/May/2026:08:25:38 +0000] "GET /.env.tar.bz2 HTTP/1.1"
show less
Port Scan
πΊπΈ
TPI-Abuse
2026-05-14 08:18:28
(1 month ago)
(mod_security) mod_security (id:210730) triggered by 34.146.46.249 (249.46.146.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.146.46.249 (249.46.146.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 14 04:18:22.743085 2026] [security2:error] [pid 1692:tid 1692] [client 34.146.46.249:40306] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||uniquetreasuresshops.com.uniquetreasuresshoppes.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "uniquetreasuresshops.com.uniquetreasuresshoppes.com"] [uri "/api.sql"] [unique_id "agWFTrfI5g3cPCuSx3Pw0wAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π«π·
dynamix
2026-05-14 05:19:28
(1 month ago)
Multiple WAF Violations
Web App Attack
Anonymous
2026-05-14 04:53:00
(1 month ago)
Multiple web server 400 error codes from same source ip
Web App Attack
Anonymous
2026-05-14 04:32:00
(1 month ago)
Failed login attempt detected by Fail2Ban in plesk-modsecurity jail
Exploited Host
π³π±
homeshowdomain.nl
2026-05-13 21:59:33
(1 month ago)
Auto-ban: >3000 req/min op 2026-05-13
Web App Attack
SSH
Hacking
π¨π
horusenergy
2026-05-13 21:29:00
(1 month ago)
GET /client.sql.gz
Hacking
Anonymous
2026-05-13 09:32:38
(1 month ago)
(caddyscan) Scanner path probe from 34.146.46.249 (JP/Japan/249.46.146.34.bc.googleusercontent.com): ...
show more
(caddyscan) Scanner path probe from 34.146.46.249 (JP/Japan/249.46.146.34.bc.googleusercontent.com): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 2627 34.146.46.249 - - [13/May/2026:09:32:29 +0000] "GET /.env.zip HTTP/1.1"
[REDACTED] 200 2627 34.146.46.249 - - [13/May/2026:09:32:30 +0000] "GET /.env.tar.gz HTTP/1.1"
[REDACTED] 200 2627 34.146.46.249 - - [13/May/2026:09:32:31 +0000] "GET /.env.tgz HTTP/1.1"
[REDACTED] 200 2627 34.146.46.249 - - [13/May/2026:09:32:32 +0000] "GET /.env.tar HTTP/1.1"
[REDACTED] 200 2627 34.146.46.249 - - [13/May/2026:09:32:33 +0000] "GET /.env.tar.bz2 HTTP/1.1"
show less
Port Scan
Anonymous
2026-05-13 08:08:36
(1 month ago)
(mod_security) mod_security triggered on hostname [redacted] 34.146.46.249 (JP/Japan/249.46.146.34.b ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.146.46.249 (JP/Japan/249.46.146.34.bc.googleusercontent.com)
show less
SQL Injection