๐ต๐ฑ
wHosts
2026-08-26 18:54:39
(5 hours ago)
Blocked by Fail2Ban
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-26 18:16:26
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.16.138.77 (77.138.16.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.16.138.77 (77.138.16.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 14:16:18.172108 2026] [security2:error] [pid 5217:tid 5217] [client 34.16.138.77:50310] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "restlesseye.com"] [uri "/static../.env"] [unique_id "ao8tcowSxc2t9avXZyzkAwAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-26 16:25:13
(8 hours ago)
Bot / seems abusive / Apache connections: 71
DDoS Attack
Web Spam
Bad Web Bot
Web App Attack
๐ท๐บ
DZBOT
2026-08-26 16:24:04
(8 hours ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
๐ฉ๐ช
LRob
2026-08-26 14:36:07
(9 hours ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /@fs/proc/self/environ (+13 more) | 2026-08-26 14:36 UTC
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-26 13:52:37
(10 hours ago)
(mod_security) mod_security (id:211190) triggered by 34.16.138.77 (77.138.16.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:211190) triggered by 34.16.138.77 (77.138.16.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 09:52:29.969171 2026] [security2:error] [pid 13332:tid 13332] [client 34.16.138.77:17812] ModSecurity: Access denied with code 403 (phase 2). Match of "contains cpanel" against "REQUEST_URI" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "55"] [id "211190"] [rev "9"] [msg "COMODO WAF: Remote File Access Attempt||igolfallday.com|F|2"] [data "Matched Data: /etc/ found within REQUEST_URI: /download?file=../../../../etc/passwd"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "igolfallday.com"] [uri "/download"] [unique_id "ao7vnadDX2Do-riMII4cFgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
CoreTech srl
2026-08-26 13:18:57
(11 hours ago)
cloudlinux2 fail2ban: 2026-08-26 15:13:56,588 fail2ban.filter [1775]: INFO [plesk-wordpre ...
show more
cloudlinux2 fail2ban: 2026-08-26 15:13:56,588 fail2ban.filter [1775]: INFO [plesk-wordpress] Found 162.55.183.140 - 2026-08-26 15:13:56cloudlinux2 fail2ban: 2026-08-26 15:14:38,439 fail2ban.filter [1775]: INFO [plesk-wordpress] Found 141.95.105.136 - 2026-08-26 15:14:38cloudlinux2 fail2ban: 2026-08-26 15:15:44,095 fail2ban.filter [1775]: INFO [plesk-modsecurity] Found 34.16.138.77 - 2026-08-26 15:15:43cloudlinux2 fail2ban: 2026-08-26 15:15:44,085 fail2ban.filter [1775]: INFO [plesk-modsecurity] Found 34.16.138.77 - 2026-08-26 15:15:43cloudlinux2 fail2ban: 2026-08-26 15:15:44,119 fail2ban.filter [1775]: INFO [plesk-modsecurity] Found 34.16.138.77 - 2026-08-26 15:15:43cloudlinux2 fail2ban: 2026-08-26 15:15:44,107 fail2ban.filter [1775]: INFO [plesk-modsecurity] Found 34.16.138.77 - 2026-08-26 15:15:43cloudlinux2 fail2ban: 2026-08-26 15:15:44,143 fail2ban.filter [1775]: INFO [plesk-modsecurity] Found 34.16.138.77 - 2026-08-26 15:15:43cl
show less
Web App Attack
๐ณ๐ฑ
BlueWire Hosting
2026-08-26 13:05:10
(11 hours ago)
High-confidence malicious configuration/VCS probe
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-08-26 12:42:55
(11 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 1247
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-26 12:24:27
(12 hours ago)
(mod_security) mod_security (id:210580) triggered by 34.16.138.77 (77.138.16.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210580) triggered by 34.16.138.77 (77.138.16.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 08:24:22.382026 2026] [security2:error] [pid 28781:tid 28781] [client 34.16.138.77:10092] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "proc/self/environ" at ARGS:url. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/08_Global_Other.conf"] [line "57"] [id "210580"] [rev "2"] [msg "COMODO WAF: OS File Access Attempt||rambleandprose.com|F|2"] [data "Matched Data: proc/self/environ found within ARGS:url: file:/proc/self/environ"] [severity "CRITICAL"] [tag "CWAF"] [tag "Other"] [hostname "rambleandprose.com"] [uri "/read"] [unique_id "ao7a9hsKf8wv6vgpSnd2zAAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-08-26 11:33:59
(13 hours ago)
Excessive multi-domain requests
Brute-Force
๐ฎ๐น
CoreTech srl
2026-08-26 11:18:57
(13 hours ago)
cloudlinux2 fail2ban: 2026-08-26 13:14:13,523 fail2ban.filter [1775]: INFO [plesk-modsecu ...
show more
cloudlinux2 fail2ban: 2026-08-26 13:14:13,523 fail2ban.filter [1775]: INFO [plesk-modsecurity] Found 34.16.138.77 - 2026-08-26 13:14:13cloudlinux2 fail2ban: 2026-08-26 13:14:13,718 fail2ban.filter [1775]: INFO [recidive] Found 34.16.138.77 - 2026-08-26 13:14:13cloudlinux2 fail2ban: 2026-08-26 13:14:13,537 fail2ban.filter [1775]: INFO [plesk-modsecurity] Found 34.16.138.77 - 2026-08-26 13:14:13cloudlinux2 fail2ban: 2026-08-26 13:14:13,571 fail2ban.filter [1775]: INFO [plesk-modsecurity] Found 34.16.138.77 - 2026-08-26 13:14:13cloudlinux2 fail2ban: 2026-08-26 13:14:13,712 fail2ban.actions [1775]: NOTICE [plesk-modsecurity] Ban 34.16.138.77cloudlinux2 fail2ban: 2026-08-26 13:14:19,666 fail2ban.filter [1775]: INFO [plesk-modsecurity] Found 223.181.13.192 - 2026-08-26 13:14:19cloudlinux2 fail2ban: 2026-08-26 13:14:31,114 fail2ban.filter [1775]: INFO [recidive] Found 223.181.13.192 - 2026-08-26 13:14:30cloudlinux2 fail2ban: 2026-08-26 13:14:3
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-26 11:17:23
(13 hours ago)
(mod_security) mod_security (id:211190) triggered by 34.16.138.77 (77.138.16.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:211190) triggered by 34.16.138.77 (77.138.16.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 07:17:16.218362 2026] [security2:error] [pid 32043:tid 32043] [client 34.16.138.77:50956] ModSecurity: Access denied with code 403 (phase 2). Match of "contains cpanel" against "REQUEST_URI" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "55"] [id "211190"] [rev "9"] [msg "COMODO WAF: Remote File Access Attempt||fundingangelinvestors.com|F|2"] [data "Matched Data: /etc/ found within REQUEST_URI: /download?file=../../../../etc/passwd"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "fundingangelinvestors.com"] [uri "/download"] [unique_id "ao7LPMJpJSkfZMU3_senJgAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Hazzard
2026-08-26 10:46:36
(13 hours ago)
(mod_security) mod_security triggered on hostname [redacted]): (CF_ENABLE)
SQL Injection
๐บ๐ธ
mnsf
2026-08-26 10:05:01
(14 hours ago)
Abuse Detected (4)
Brute-Force
Web App Attack