🇺🇸
TPI-Abuse
2026-09-08 03:26:36
(13 minutes ago)
(mod_security) mod_security (id:210492) triggered by 34.80.66.123 (123.66.80.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.80.66.123 (123.66.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 23:26:30.879517 2026] [security2:error] [pid 6325:tid 6325] [client 34.80.66.123:61310] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.jambmaster.com"] [uri "/@fs/.env"] [unique_id "ap-AZkQJ7tIDBXJsP0l2qgAAAI0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
Savvii
2026-09-08 03:24:28
(15 minutes ago)
20 attempts against mh-misbehave-ban on redirect
Brute-Force
Bad Web Bot
Web App Attack
🇦🇹
penguin-solutions.at
2026-09-08 03:15:56
(24 minutes ago)
Excessive 403/404 errors
...
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 02:44:01
(56 minutes ago)
(mod_security) mod_security (id:210492) triggered by 34.80.66.123 (123.66.80.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.80.66.123 (123.66.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 22:43:56.355978 2026] [security2:error] [pid 3197:tid 3197] [client 34.80.66.123:6272] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.oxyveg.com"] [uri "/@fs/root/.env"] [unique_id "ap92bKbRMGpWMPFoDdbnsgAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
consul.to
2026-09-08 02:28:54
(1 hour ago)
Web attack/malicious scanning detected
Web App Attack
🇫🇷
LRob
2026-09-08 02:19:41
(1 hour ago)
Malicious web request: probing for secrets, traversal or a known exploit path | method: GET | path: ...
show more
Malicious web request: probing for secrets, traversal or a known exploit path | method: GET | path: /@fs/.env | 2026-09-08 02:19 UTC
show less
Hacking
Web App Attack
🇮🇹
CoreTech srl
2026-09-08 01:58:57
(1 hour ago)
cloudlinux2 fail2ban: 2026-09-08 03:53:50,617 fail2ban.filter [1794]: INFO [plesk-wordpre ...
show more
cloudlinux2 fail2ban: 2026-09-08 03:53:50,617 fail2ban.filter [1794]: INFO [plesk-wordpress] Found 216.24.219.236 - 2026-09-08 03:53:49cloudlinux2 fail2ban: 2026-09-08 03:54:00,367 fail2ban.filter [1794]: INFO [plesk-wordpress] Found 185.30.144.114 - 2026-09-08 03:53:59cloudlinux2 fail2ban: 2026-09-08 03:54:14,313 fail2ban.actions [1794]: NOTICE [plesk-modsecurity] Unban 34.125.223.14cloudlinux2 fail2ban: 2026-09-08 03:55:09,895 fail2ban.filter [1794]: INFO [plesk-modsecurity] Found 160.187.221.31 - 2026-09-08 03:55:09cloudlinux2 fail2ban: 2026-09-08 03:55:56,439 fail2ban.actions [1794]: NOTICE [plesk-modsecurity] Unban 34.20.170.185cloudlinux2 fail2ban: 2026-09-08 03:56:12,711 fail2ban.filter [1794]: INFO [plesk-modsecurity] Found 160.187.221.31 - 2026-09-08 03:56:12cloudlinux2 fail2ban: 2026-09-08 03:56:38,593 fail2ban.filter [1794]: INFO [plesk-modsecurity] Found 34.80.66.123 - 2026-09-08 03:56:38cloudlinux2 fail2ban: 2026-09-08 03:56:3
show less
Web App Attack
🇧🇪
cmbplf
2026-09-08 01:41:46
(1 hour ago)
282 requests with url.path *.ssh/*
Brute-Force
Bad Web Bot
🇩🇪
dbmwebdesign
2026-09-08 01:35:13
(2 hours ago)
WAF repeated trigger detected by Fail2Ban in plesk-modsecurity jail
Web App Attack
🇫🇷
Octopuce
2026-09-08 00:41:22
(2 hours ago)
Aggressive web search of vulnerable pages: /img../.env /app/.env /v1/.env /uploads../.env /admin/.en ...
show more
Aggressive web search of vulnerable pages: /img../.env /app/.env /v1/.env /uploads../.env /admin/.env ...
show less
Web App Attack
🇸🇪
vaia.cloud
2026-09-08 00:40:02
(3 hours ago)
crowdsecurity/http-probing
Brute-Force
Web App Attack
🇮🇹
CoreTech srl
2026-09-08 00:38:12
(3 hours ago)
cloudlinux2 fail2ban: 2026-09-08 02:19:28,915 fail2ban.filter [1794]: INFO [plesk-wordpre ...
show more
cloudlinux2 fail2ban: 2026-09-08 02:19:28,915 fail2ban.filter [1794]: INFO [plesk-wordpress] Found 216.24.219.233 - 2026-09-08 02:19:27cloudlinux2 fail2ban: 2026-09-08 02:19:29,091 fail2ban.filter [1794]: INFO [plesk-wordpress] Found 216.24.219.239 - 2026-09-08 02:19:27cloudlinux2 fail2ban: 2026-09-08 02:19:32,513 fail2ban.filter [1794]: INFO [plesk-wordpress] Found 216.24.219.233 - 2026-09-08 02:19:31cloudlinux2 fail2ban: 2026-09-08 02:20:44,924 fail2ban.filter [1794]: INFO [plesk-wordpress] Found 155.2.215.25 - 2026-09-08 02:20:44cloudlinux2 fail2ban: 2026-09-08 02:20:40,970 fail2ban.filter [1794]: INFO [plesk-wordpress] Found 155.2.215.25 - 2026-09-08 02:20:40cloudlinux2 fail2ban: 2026-09-08 02:21:29,342 fail2ban.actions [1794]: NOTICE [plesk-modsecurity] Unban 34.19.71.219cloudlinux2 fail2ban: 2026-09-08 02:22:08,771 fail2ban.filter [1794]: INFO [plesk-modsecurity] Found 183.1.253.219 - 2026-09-08 02:22:08cloudlinux2 fail2ban: 2026-
show less
Web App Attack
🇩🇪
updown.io
2026-09-08 00:28:19
(3 hours ago)
{"level":"info","ts":1788827238.5124652,"logger":"http.log.access.log1","msg":"handled request","req ...
show more
{"level":"info","ts":1788827238.5124652,"logger":"http.log.access.log1","msg":"handled request","request":{"remote_ip":"34.80.66.123","remote_port":"58590","client_ip":"34.80.66.123","proto":"HTTP/1.1","method":"GET","host":"status.dridger.com","uri":"/","headers":{"User-Agent":["Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:133.0) Gecko/20100101 Firefox/133.0"],"Accept":["*/*"],"Accept-Encoding":["gzip"]}},"bytes_read":0,"user_id":"","duration":0.00009967,"size":0,"status":308,"resp_headers":{"Server":["Caddy"],"Connection":["close"],"Location":["https://status.dridger.com/"],"Content-Type":[]}}
{"level":"info","ts":1788827246.821378,"logger":"http.log.access.log1","msg":"handled request","request":{"remote_ip":"34.80.66.123","remote_port":"37076","client_ip":"34.80.66.123","proto":"HTTP/1.1","method":"GET","host":"status.dridger.com","uri":"/@fs/.env.local?raw??","headers":{"User-Agent":["Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:150.18) Gecko/20100101 Firefox/150.18; compatible; Gro
...
show less
DDoS Attack
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 23:26:16
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.80.66.123 (123.66.80.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.80.66.123 (123.66.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 19:26:09.747897 2026] [security2:error] [pid 588316:tid 588352] [client 34.80.66.123:55048] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.npaccountants.org"] [uri "/@fs/src/.env"] [unique_id "ap9IEbK6im_k6s5C8zEyTwAAAVU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
Site.eu
2026-09-07 23:04:55
(4 hours ago)
Excessive 404/403 errors
Brute-Force