๐ฉ๐ช
Zydzy
2026-08-31 11:51:29
(22 hours ago)
Automated attack detected. Server: 95.140.154.181. Jail: nginx-exploit.
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-29 03:07:10
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 35.243.234.104 (104.234.243.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.243.234.104 (104.234.243.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 23:07:05.392518 2026] [security2:error] [pid 22690:tid 22690] [client 35.243.234.104:56324] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.crochetdoilies.com"] [uri "/wp-config.php~"] [unique_id "apJM2T4iUN2WV97iPGoljwAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Hary74656
2026-08-29 02:24:22
(3 days ago)
Fail2Ban on schani.hostmi.at: jail=apache-modsecurity, failures=3. No raw log data included.
Web App Attack
๐บ๐ธ
daveoctober
2026-08-29 02:10:29
(3 days ago)
October Sentinel: honeypot triggered
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-29 01:37:29
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 35.243.234.104 (104.234.243.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.243.234.104 (104.234.243.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 21:37:25.715891 2026] [security2:error] [pid 13302:tid 13302] [client 35.243.234.104:41766] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mnice.help"] [uri "/.env.old"] [unique_id "apI31U4uirnI31wI84e2UAAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
paulshipley.com.au
2026-08-29 01:36:00
(3 days ago)
[Sat Aug 29 11:35:59.445697 2026] [security2:error] [pid 717717] [client 35.243.234.104:37526] [clie ...
show more
[Sat Aug 29 11:35:59.445697 2026] [security2:error] [pid 717717] [client 35.243.234.104:37526] [client 35.243.234.104] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/modsecurity/crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "ccideas.com.au"] [uri "/wp-config.php.bak"] [unique_id "apI3f69Zd-Q1LW_UpjiSeQAAAAI"]
...
show less
Web App Attack
๐ฌ๐ง
andypiper
2026-08-29 01:01:35
(3 days ago)
CrowdSec ban for AbuseIPDB Top List
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-29 00:40:39
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 35.243.234.104 (104.234.243.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.243.234.104 (104.234.243.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 20:40:34.257098 2026] [security2:error] [pid 18135:tid 18135] [client 35.243.234.104:43928] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "rkstewart.com"] [uri "/.env.save"] [unique_id "apIqgtJ-RkCjiq_-lEaw2wAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
LRNP
2026-08-29 00:29:17
(3 days ago)
mc.lpoujol.fr:443 35.243.234.104 - - [29/Aug/2026:00:29:17 +0000] "GET /wp-config.php.swp HTTP/1.1" ...
show more
mc.lpoujol.fr:443 35.243.234.104 - - [29/Aug/2026:00:29:17 +0000] "GET /wp-config.php.swp HTTP/1.1" 403 146 "-" "crusader-worker/1.0"
mc.lpoujol.fr:443 35.243.234.104 - - [29/Aug/2026:00:29:17 +0000] "GET /wp-config.php~ HTTP/1.1" 403 146 "-" "crusader-worker/1.0"
mc.lpoujol.fr:443 35.243.234.104 - - [29/Aug/2026:00:29:17 +0000] "GET /actuator/env HTTP/1.1" 403 146 "-" "crusader-worker/1.0"
mc.lpoujol.fr:443 35.243.234.104 - - [29/Aug/2026:00:29:17 +0000] "GET /env HTTP/1.1" 403 146 "-" "crusader-worker/1.0"
mc.lpoujol.fr:443 35.243.234.104 - - [29/Aug/2026:00:29:17 +0000] "GET /.env.save HTTP/1.1" 403 146 "-" "crusader-worker/1.0"
mc.lpoujol.fr:443 35.243.234.104 - - [29/Aug/2026:00:29:17 +0000] "GET /.env.backup HTTP/1.1" 403 146 "-" "crusader-worker/1.0"
mc.lpoujol.fr:443 35.243.234.104 - - [29/Aug/2026:00:29:17 +0000] "GET /actuator/configprops HTTP/1.1" 403 146 "-" "crusader-worker/1.0"
mc.lpoujol.fr:443 35.243.234.104 - - [29/Aug/2026:00:29:17 +0000] "GET /.env.local HTTP/1.1" 40
...
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
Philister11
2026-08-29 00:13:51
(3 days ago)
CrowdSec: crowdsecurity/http-probing (US/AS396982)
Web App Attack
Hacking
๐ฉ๐ช
Zydzy
2026-08-28 23:32:05
(3 days ago)
Automated attack detected. Server: 95.140.154.181. Jail: nginx-exploit.
Web App Attack
Anonymous
2026-08-28 22:20:13
(3 days ago)
| Suspicious URL access.
Web App Attack
Hacking
SQL Injection
๐ณ๐ฑ
homeshowdomain.nl
2026-08-28 22:03:37
(3 days ago)
Auto-ban: >3000 req/min op 2026-08-28
Web App Attack
SSH
Hacking
๐ฉ๐ช
wpadm4
2026-08-28 21:51:10
(3 days ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
๐ช๐ธ
alferez
2026-08-28 21:33:09
(3 days ago)
Searching .(env|sql|zip|tar|rar) files
Hacking
Exploited Host
Web App Attack