🇺🇸
billyw0nka
2026-09-06 02:47:06
(9 hours ago)
pattern: admindev
Hacking
🇩🇪
Hazzard
2026-09-06 02:36:40
(9 hours ago)
(mod_security) mod_security triggered on hostname [redacted]): (CF_ENABLE)
SQL Injection
Anonymous
2026-09-06 00:21:30
(11 hours ago)
[ns31.kdns.gr] httpd-config-scan: sites=www.amarilis.gr; logs=/var/log/httpd/domains/amarilis.gr.log ...
show more
[ns31.kdns.gr] httpd-config-scan: sites=www.amarilis.gr; logs=/var/log/httpd/domains/amarilis.gr.log; samples=/.env | /.env.local | /wp-config.php.bak
show less
Hacking
Web App Attack
🇳🇱
e.fierstra
2026-09-06 00:00:40
(12 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
🇩🇪
webanyone
2026-09-05 23:31:41
(12 hours ago)
WAF repeated trigger detected by Fail2Ban in plesk-modsecurity jail
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 23:26:52
(12 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.189.173.35 (35.173.189.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.189.173.35 (35.173.189.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 19:26:43.092390 2026] [security2:error] [pid 16810:tid 16810] [client 35.189.173.35:38830] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||kimpitchellandassociatesinc.com|F|2"] [data ".log"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "kimpitchellandassociatesinc.com"] [uri "/storage/logs/laravel.log"] [unique_id "apylM2uLUJ0jsTPJlU8bYAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 21:37:26
(14 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.189.173.35 (35.173.189.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.189.173.35 (35.173.189.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 17:37:19.705240 2026] [security2:error] [pid 32745:tid 32745] [client 35.189.173.35:34358] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mail.domainexecs.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mail.domainexecs.com"] [uri "/database.sql"] [unique_id "apyLjxlGfUue9FhCqzoXsAAAAIA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
Hary74656
2026-09-05 21:25:36
(14 hours ago)
Fail2Ban on schani.hostmi.at: jail=apache-modsecurity, failures=3. No raw log data included.
Web App Attack
🇩🇪
Jochen Pretli
2026-09-05 21:03:34
(15 hours ago)
connection to honeypot
Email Spam
Port Scan
🇺🇸
TPI-Abuse
2026-09-05 20:28:34
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.189.173.35 (35.173.189.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.189.173.35 (35.173.189.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 16:28:25.574474 2026] [security2:error] [pid 30927:tid 30927] [client 35.189.173.35:38372] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bergopro.co.uk"] [uri "/.env.production"] [unique_id "apx7aWY6kAEhjPILulp2KAAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
homeshowdomain.nl
2026-09-04 21:59:22
(1 day ago)
Auto-ban: >3000 req/min op 2026-09-04
Web App Attack
SSH
Hacking
🇺🇸
TPI-Abuse
2026-09-04 15:16:56
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.189.173.35 (35.173.189.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.189.173.35 (35.173.189.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 11:16:52.137495 2026] [security2:error] [pid 11182:tid 11182] [client 35.189.173.35:59236] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.intrinsicdiscovery.com"] [uri "/.env"] [unique_id "aprg5P2bNCcwrAX3PpYAUQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
big-cloud.nl
2026-09-04 14:37:42
(1 day ago)
Try to access /.env
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 14:11:34
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.189.173.35 (35.173.189.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.189.173.35 (35.173.189.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 10:11:29.154101 2026] [security2:error] [pid 30026:tid 30026] [client 35.189.173.35:48960] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.bendergloves.com"] [uri "/wp-config.php~"] [unique_id "aprRkSALJs8f9_rTdPC5pQAAAGE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 13:25:03
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.189.173.35 (35.173.189.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.189.173.35 (35.173.189.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 09:24:54.760305 2026] [security2:error] [pid 3074850:tid 3074912] [client 35.189.173.35:53798] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "slingshotpro.credit-card-cap.com"] [uri "/.env.dev"] [unique_id "aprGpgDE4i4QbWxJxPwjtAAAAFg"]
show less
Brute-Force
Bad Web Bot
Web App Attack