Anonymous
2026-09-21 11:35:20
(3 days ago)
Failed login attempt detected by Fail2Ban in plesk-modsecurity jail
Exploited Host
๐บ๐ธ
TPI-Abuse
2026-09-21 05:05:41
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.80.123.120 (120.123.80.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.80.123.120 (120.123.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 01:05:34.690977 2026] [security2:error] [pid 13727:tid 13727] [client 34.80.123.120:57490] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.csme-eprr.com"] [uri "/.git/HEAD"] [unique_id "arC7HlKnATLA5eX30QPngQAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 04:19:41
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.80.123.120 (120.123.80.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.80.123.120 (120.123.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 00:19:34.301010 2026] [security2:error] [pid 11036:tid 11036] [client 34.80.123.120:35866] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.donutlocations.com"] [uri "/.git/HEAD"] [unique_id "arCwVluSjFCAkxXLLQVaOgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 03:43:53
(3 days ago)
(mod_security) mod_security (id:210730) triggered by 34.80.123.120 (120.123.80.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.80.123.120 (120.123.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 23:43:47.277189 2026] [security2:error] [pid 12412:tid 12412] [client 34.80.123.120:39068] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.drbolen.com|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.drbolen.com"] [uri "/rclone.conf"] [unique_id "arCn89ikt9Pk_886as_o-gAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-21 03:43:47
(3 days ago)
Web App Attack
Brute-Force
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 03:24:44
(3 days ago)
(mod_security) mod_security (id:949110) triggered by 34.80.123.120 (120.123.80.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:949110) triggered by 34.80.123.120 (120.123.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 23:24:40.736502 2026] [security2:error] [pid 22995:tid 22995] [client 34.80.123.120:43238] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "mail.boraborapearlbookings.com"] [uri "/@fs/app/.env"] [unique_id "arCjeGaP_iB-sEx5SiOOkgAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
ELYAZ
2026-09-21 02:41:09
(3 days ago)
(y3) Failed access -byebye- from 34.80.123.120 (TW/Taiwan/120.123.80.34.bc.googleusercontent.com): ...
show more
(y3) Failed access -byebye- from 34.80.123.120 (TW/Taiwan/120.123.80.34.bc.googleusercontent.com): (CF_ENABLE)
show less
Hacking
๐ฒ๐พ
Rizzy
2026-09-21 01:59:37
(3 days ago)
Multiple WAF Violations
Brute-Force
Web App Attack
๐ซ๐ท
Octopuce
2026-09-21 01:30:49
(3 days ago)
Aggressive web search of vulnerable pages: /server/.env /.env /app/.env /web/.env /scripts/.env ...
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 01:04:10
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.80.123.120 (120.123.80.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.80.123.120 (120.123.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 21:04:04.880220 2026] [security2:error] [pid 20145:tid 20145] [client 34.80.123.120:33938] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.be4ventures.com"] [uri "/.git/HEAD"] [unique_id "arCChOtaGPTfobskztsntwAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 00:39:06
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.80.123.120 (120.123.80.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.80.123.120 (120.123.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 20:39:01.449203 2026] [security2:error] [pid 29422:tid 29422] [client 34.80.123.120:44568] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.flugstad.com"] [uri "/.env.example"] [unique_id "arB8pdwdqRktLo5jQBB8RQAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
boxed-it
2026-09-21 00:14:24
(3 days ago)
GET /.env (Tarpitted for 26m18s, wasted 92.58kB)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 00:03:29
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.80.123.120 (120.123.80.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.80.123.120 (120.123.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 20:03:25.051696 2026] [security2:error] [pid 9045:tid 9045] [client 34.80.123.120:47308] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.edelbaumarchitect.com"] [uri "/.env.backup"] [unique_id "arB0TQm9dYMRbu62UUbSHgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 23:07:19
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.80.123.120 (120.123.80.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.80.123.120 (120.123.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 19:07:12.262357 2026] [security2:error] [pid 1838:tid 1838] [client 34.80.123.120:51580] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.comobarbershop.com"] [uri "/apps/.env"] [unique_id "arBnIOWOiZE2p199eyBTpwAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 22:37:44
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.80.123.120 (120.123.80.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.80.123.120 (120.123.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 18:37:37.137605 2026] [security2:error] [pid 2644:tid 2644] [client 34.80.123.120:54246] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.chrismoratz.com"] [uri "/.env"] [unique_id "arBgMSA-C-IcYUNbKpuALwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack