๐ณ๐ฑ
Savvii
2026-08-24 16:59:11
(17 minutes ago)
20 attempts against mh-misbehave-ban on lunar
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐พ
lns.bz
2026-08-24 13:21:01
(3 hours ago)
Too many 404 requests [BY]
Web App Attack
๐ซ๐ท
Octopuce
2026-08-24 12:57:52
(4 hours ago)
Aggressive web search of vulnerable pages: /admin/.env /server/.env /web/.env /laravel/.env /.env . ...
show more
Aggressive web search of vulnerable pages: /admin/.env /server/.env /web/.env /laravel/.env /.env ...
show less
Web App Attack
๐ซ๐ท
dynamix
2026-08-24 06:23:29
(10 hours ago)
Multiple WAF Violations
Web App Attack
๐ง๐ช
cmbplf
2026-08-24 04:35:37
(12 hours ago)
275 requests with url.path *.env
Brute-Force
Bad Web Bot
๐ณ๐ฑ
Site.eu
2026-08-24 03:33:06
(13 hours ago)
Excessive 404/403 errors
Brute-Force
๐ธ๐ช
vaia.cloud
2026-08-23 22:35:01
(18 hours ago)
crowdsecurity/http-probing
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-23 20:20:52
(20 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.156.25.103 (103.25.156.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.156.25.103 (103.25.156.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 23 16:20:44.955972 2026] [security2:error] [pid 15325:tid 15325] [client 34.156.25.103:39790] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "villamarehiltonhead.com"] [uri "/.env.compose"] [unique_id "aotWHMM8c0n4nD_05F0W5QAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
VHosting
2026-08-23 19:35:08
(21 hours ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-23 19:32:27
(21 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.156.25.103 (103.25.156.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.156.25.103 (103.25.156.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 23 15:32:19.312121 2026] [security2:error] [pid 27413:tid 27413] [client 34.156.25.103:52710] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.gulftelecom.com"] [uri "/.env.compose"] [unique_id "aotKwz08rtODTd-2A9I2qwAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-23 14:29:25
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.156.25.103 (103.25.156.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.156.25.103 (103.25.156.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 23 10:29:17.936833 2026] [security2:error] [pid 24521:tid 24521] [client 34.156.25.103:34594] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.starfrontiers.com"] [uri "/.env.compose"] [unique_id "aosDvTZK-9VCa4EzMnFhaAAAAD4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
pscriptos
2026-08-23 14:21:05
(1 day ago)
This IP was detected by CrowdSec triggering crowdsecurity/appsec-vpatch
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-23 14:11:38
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.156.25.103 (103.25.156.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.156.25.103 (103.25.156.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 23 10:11:33.064301 2026] [security2:error] [pid 30583:tid 30583] [client 34.156.25.103:53406] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.flanav1.yankeetownfishing.com"] [uri "/.env.compose"] [unique_id "aor_lRseYvHDl_kNWjIk5QAAAG8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-23 11:00:16
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.156.25.103 (103.25.156.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.156.25.103 (103.25.156.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 23 07:00:09.235587 2026] [security2:error] [pid 16859:tid 16859] [client 34.156.25.103:34986] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.playerpianosupplies.com.player-care.com"] [uri "/.env.compose"] [unique_id "aorSuZGpdkIz5h_HesY3hwAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
CoreTech srl
2026-08-23 05:13:56
(1 day ago)
cloudlinux2 fail2ban: 2026-08-23 07:09:06,612 fail2ban.filter [1496]: INFO [plesk-wordpre ...
show more
cloudlinux2 fail2ban: 2026-08-23 07:09:06,612 fail2ban.filter [1496]: INFO [plesk-wordpress] Found 91.193.232.5 - 2026-08-23 07:09:06cloudlinux2 fail2ban: 2026-08-23 07:09:29,463 fail2ban.filter [1496]: INFO [plesk-wordpress] Found 23.94.155.64 - 2026-08-23 07:09:27cloudlinux2 fail2ban: 2026-08-23 07:09:29,084 fail2ban.filter [1496]: INFO [plesk-wordpress] Found 23.94.155.54 - 2026-08-23 07:09:27cloudlinux2 fail2ban: 2026-08-23 07:09:29,582 fail2ban.filter [1496]: INFO [plesk-wordpress] Found 23.94.155.58 - 2026-08-23 07:09:27cloudlinux2 fail2ban: 2026-08-23 07:09:29,128 fail2ban.filter [1496]: INFO [plesk-wordpress] Found 23.94.155.56 - 2026-08-23 07:09:27cloudlinux2 fail2ban: 2026-08-23 07:09:55,668 fail2ban.filter [1496]: INFO [plesk-modsecurity] Found 123.180.198.119 - 2026-08-23 07:09:55cloudlinux2 fail2ban: 2026-08-23 07:10:31,054 fail2ban.filter [1496]: INFO [plesk-modsecurity] Found 170.64.178.60 - 2026-08-23 07:10:31cloudlin
show less
Web App Attack