๐จ๐ฆ
zXero
2026-09-02 01:36:59
(4 hours ago)
Fail2Ban automatic report - jail: no-wordpress
Brute-Force
SSH
DDoS Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 13:53:26
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.48.238.47 (47.238.48.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.48.238.47 (47.238.48.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 09:53:19.730785 2026] [security2:error] [pid 16258:tid 16258] [client 34.48.238.47:51792] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.dsjostrom.com"] [uri "/.env.bak"] [unique_id "apbYz7duGhc_91FKRVD0OwAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ฆ
zXero
2026-09-01 13:03:13
(17 hours ago)
Fail2Ban automatic report - jail: web-exploit
Brute-Force
SSH
DDoS Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 11:58:55
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.48.238.47 (47.238.48.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.48.238.47 (47.238.48.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 07:58:52.031709 2026] [security2:error] [pid 22242:tid 22334] [client 34.48.238.47:42982] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "dev.joeandlane.com"] [uri "/.env.save"] [unique_id "apa9_EJyANdOXl3YOOfuRAAAAQ8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Catalin Negru
2026-09-01 11:14:55
(19 hours ago)
Recidive ban by fail2ban on server.blackbit.ro
Brute-Force
Anonymous
2026-09-01 11:05:40
(19 hours ago)
(mod_security) mod_security triggered on hostname [redacted] 34.48.238.47 (US/United States/47.238.4 ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.48.238.47 (US/United States/47.238.48.34.bc.googleusercontent.com)
show less
SQL Injection
๐บ๐ธ
TPI-Abuse
2026-09-01 11:02:48
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.48.238.47 (47.238.48.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.48.238.47 (47.238.48.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 07:02:44.422655 2026] [security2:error] [pid 226453:tid 226511] [client 34.48.238.47:49188] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.geekmd.org"] [uri "/.env"] [unique_id "apaw1LXrnWkgbzFp5H4H5wAAAFY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
netclix.gr
2026-09-01 11:01:03
(19 hours ago)
(mod_security) mod_security triggered on hostname [redacted] 34.48.238.47 (US/United States/47.238.4 ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.48.238.47 (US/United States/47.238.48.34.bc.googleusercontent.com): (CF_ENABLE)
show less
SQL Injection
๐ฉ๐ช
Bedios GmbH
2026-09-01 10:22:42
(20 hours ago)
Login credentials theft attempt
Hacking
๐ฉ๐ช
raph
2026-09-01 10:21:05
(20 hours ago)
[DOT FILES] crawler *.env*, .git*, .config*, etc.
Bad Web Bot
Web App Attack
๐จ๐ญ
zynex
2026-09-01 10:19:04
(20 hours ago)
URL Probing: /.env
Web App Attack
๐ฎ๐ฉ
Burayot
2026-09-01 09:41:42
(20 hours ago)
LF_MODSEC: (mod_security) mod_security (id:949110) triggered by 34.48.238.47 (US/United States/47.23 ...
show more
LF_MODSEC: (mod_security) mod_security (id:949110) triggered by 34.48.238.47 (US/United States/47.238.48.34.bc.googleusercontent.com): 2 in the last 3600 secs
show less
Web App Attack
Anonymous
2026-09-01 09:37:38
(20 hours ago)
Web scanner: GET /wp-config.php.swp
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-01 09:17:05
(21 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.48.238.47 (47.238.48.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.48.238.47 (47.238.48.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 05:16:58.182338 2026] [security2:error] [pid 3330:tid 3330] [client 34.48.238.47:52156] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "stinkingpink.com"] [uri "/.env.bak"] [unique_id "apaYClSr1F7J0JpR2y7tNwAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 08:22:31
(22 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.48.238.47 (47.238.48.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.48.238.47 (47.238.48.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 04:22:25.612136 2026] [security2:error] [pid 25566:tid 25566] [client 34.48.238.47:60252] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||medicalexchangeasinc.com|F|2"] [data ".log"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "medicalexchangeasinc.com"] [uri "/storage/logs/laravel.log"] [unique_id "apaLQRJmO3cSXlSw2umw8AAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack