🇩🇪
FD-IX
2026-09-05 22:13:23
(45 minutes ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
Anonymous
2026-09-05 21:32:50
(1 hour ago)
Banned by Fail2Ban on server
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 21:17:57
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.24.88.26 (26.88.24.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.24.88.26 (26.88.24.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 17:17:50.460838 2026] [security2:error] [pid 3916:tid 3916] [client 34.24.88.26:38246] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.wmionline.org"] [uri "/.env.bak"] [unique_id "apyG_nMZEvuNPLngflvJCAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-05 21:01:01
(1 hour ago)
...
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 20:43:19
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.24.88.26 (26.88.24.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.24.88.26 (26.88.24.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 16:43:14.940588 2026] [security2:error] [pid 31327:tid 31327] [client 34.24.88.26:50456] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "impostersyndromeunmasked.com"] [uri "/.env.production"] [unique_id "apx-4myKaZHCB4HhYzXKKAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇮🇹
VHosting
2026-09-05 20:40:03
(2 hours ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
🇫🇷
dynamix
2026-09-05 07:50:26
(15 hours ago)
Multiple WAF Violations
Web App Attack
🇺🇸
TPI-Abuse
2026-09-02 23:31:58
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.24.88.26 (26.88.24.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.24.88.26 (26.88.24.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 19:31:54.463743 2026] [security2:error] [pid 2188:tid 2188] [client 34.24.88.26:46926] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/config/config.yml" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.hamiltoncountyuca.org"] [uri "/app/config/config.yml"] [unique_id "apix6j0GuSXr2djZy8eLcQAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-02 07:13:46
(3 days ago)
34.24.88.26 - - [02/Sep/2026:09:13:40 +0200] "GET /alertmanager.yml HTTP/1.1" 403 7152 "-" "Mozilla/ ...
show more
34.24.88.26 - - [02/Sep/2026:09:13:40 +0200] "GET /alertmanager.yml HTTP/1.1" 403 7152 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0 Safari/537.36"
34.24.88.26 - - [02/Sep/2026:09:13:40 +0200] "GET /api/application.yml HTTP/1.1" 403 7152 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0 Safari/537.36"
34.24.88.26 - - [02/Sep/2026:09:13:40 +0200] "GET /access.log HTTP/1.1" 403 7152 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0 Safari/537.36"
34.24.88.26 - - [02/Sep/2026:09:13:40 +0200] "GET /api/config.yml HTTP/1.1" 403 559 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0 Safari/537.36"
34.24.88.26 - - [02/Sep/2026:09:13:40 +0200] "GET /api/database.yml HTTP/1.1" 403 559 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0 Safari/537.36"
34.24.88.26 - - [02/Sep/2026:09:13:40 +0200] "GET /a
...
show less
DDoS Attack
Anonymous
2026-09-01 11:30:29
(4 days ago)
Aggressive web scan
Web App Attack
🇬🇧
consul.to
2026-08-28 10:59:44
(1 week ago)
Web attack/malicious scanning detected
Web App Attack