🇮🇹
CoreTech srl
2026-09-16 06:43:57
(3 days ago)
cloudlinux2 fail2ban: 2026-09-16 08:39:39,973 fail2ban.filter [1818]: INFO [plesk-modsecu ...
show more
cloudlinux2 fail2ban: 2026-09-16 08:39:39,973 fail2ban.filter [1818]: INFO [plesk-modsecurity] Found 152.59.144.98 - 2026-09-16 08:39:39cloudlinux2 fail2ban: 2026-09-16 08:39:47,524 fail2ban.actions [1818]: NOTICE [plesk-modsecurity] Unban 35.202.49.146cloudlinux2 fail2ban: 2026-09-16 08:40:48,327 fail2ban.filter [1818]: INFO [plesk-modsecurity] Found 152.59.144.98 - 2026-09-16 08:40:48cloudlinux2 fail2ban: 2026-09-16 08:40:47,332 fail2ban.filter [1818]: INFO [plesk-modsecurity] Found 45.138.12.11 - 2026-09-16 08:40:47cloudlinux2 fail2ban: 2026-09-16 08:40:48,824 fail2ban.filter [1818]: INFO [recidive] Found 152.59.144.98 - 2026-09-16 08:40:48cloudlinux2 fail2ban: 2026-09-16 08:40:48,818 fail2ban.actions [1818]: NOTICE [plesk-modsecurity] Ban 152.59.144.98cloudlinux2 fail2ban: 2026-09-16 08:41:00,656 fail2ban.filter [1818]: INFO [plesk-modsecurity] Found 49.36.235.121 - 2026-09-16 08:41:00cloudlinux2 fail2ban: 2026-09-16 08:41:36,397 fail2
show less
Brute-Force
🇫🇷
LoneRider
2026-09-16 06:35:06
(3 days ago)
[16/Sep/2026:08:35:05.548649 +0200] aqo4mbW0YAAWj_OCgkjz2AAAAAc 34.31.5.196 49534 127.0.0.1 7081
[16 ...
show more
[16/Sep/2026:08:35:05.548649 +0200] aqo4mbW0YAAWj_OCgkjz2AAAAAc 34.31.5.196 49534 127.0.0.1 7081
[16/Sep/2026:08:35:05.554741 +0200] aqo4mUZgJBZAPLJrzl9sHQAAAAU 34.31.5.196 49520 127.0.0.1 7081
[16/Sep/2026:08:35:05.567770 +0200] aqo4mQl50rC42khAuO01GgAAAAg 34.31.5.196 49544 127.0.0.1 7081
...
show less
Hacking
🇳🇱
MyGlobalFlowers
2026-09-16 06:23:17
(3 days ago)
Multiple WAF Violations
Web App Attack
🇨🇭
sternwart
2026-09-16 06:22:00
(3 days ago)
Automatisch erkannt: Zugriff auf /@fs/app/.env?raw?? (my-coach.ch)
Web App Attack
Bad Web Bot
🇳🇿
realstuffie
2026-09-16 06:16:39
(3 days ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
🇦🇺
paulshipley.com.au
2026-09-16 05:58:56
(3 days ago)
[Wed Sep 16 15:58:55.955460 2026] [security2:error] [pid 335989] [client 34.31.5.196:43766] [client ...
show more
[Wed Sep 16 15:58:55.955460 2026] [security2:error] [pid 335989] [client 34.31.5.196:43766] [client 34.31.5.196] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/modsecurity/crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "mareeshefford.com"] [uri "/z9x8c7v6b5-debug-trigger-mareeshefford.com"] [unique_id "aqowH6IS0Qb1HMUdflYW4gAAABA"]
...
show less
Web App Attack
🇧🇾
lns.bz
2026-09-16 05:55:52
(3 days ago)
.env scanning [BY]
Web App Attack
🇳🇱
e.fierstra
2026-09-16 05:48:28
(3 days ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
Anonymous
2026-09-16 05:46:48
(3 days ago)
IP matched detection query more than 2 hosts and only bad rq long ban.
Brute-Force
Web App Attack
Hacking
🇩🇪
findlab
2026-09-16 05:30:02
(3 days ago)
Backdrop CMS module - malicious activity detected
Bad Web Bot
Web App Attack
Anonymous
2026-09-16 04:04:39
(3 days ago)
Aggressive web scan
Web App Attack
🇺🇸
TPI-Abuse
2026-09-16 04:00:49
(3 days ago)
(mod_security) mod_security (id:210730) triggered by 34.31.5.196 (196.5.31.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 34.31.5.196 (196.5.31.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 00:00:41.507172 2026] [security2:error] [pid 4215:tid 4215] [client 34.31.5.196:53926] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||gabosoftware.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "gabosoftware.com"] [uri "/z9x8c7v6b5-debug-trigger-gabosoftware.com"] [unique_id "aqoUaXOrSNeeJy5RYMZ4ygAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-16 03:00:09
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.31.5.196 (196.5.31.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.31.5.196 (196.5.31.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 22:59:56.899043 2026] [security2:error] [pid 30911:tid 30911] [client 34.31.5.196:45354] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "englishmagic.us"] [uri "/.git/config"] [unique_id "aqoGLBCkRG30hameVrCzXgAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
raph
2026-09-16 02:09:52
(3 days ago)
[DOT FILES] crawler *.env*, .git*, .config*, etc.
Bad Web Bot
Web App Attack
🇳🇱
debestelapp
2026-09-16 01:05:13
(3 days ago)
Web App Attack