๐ณ๐ฑ
jjnxpct
2026-04-29 03:47:32
(5 months ago)
Automated security incident from hosting server. ModSecurity blocked suspicious request targeting UR ...
show more
Automated security incident from hosting server. ModSecurity blocked suspicious request targeting URI: /package.json (Rule ID: 930130) - Restricted File Access Attempt
show less
Web App Attack
Hacking
๐ซ๐ท
dynamix
2026-04-29 02:29:19
(5 months ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-29 02:25:33
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 45.45.237.139 (hosted-by.infraly.co): 1 in the ...
show more
(mod_security) mod_security (id:210492) triggered by 45.45.237.139 (hosted-by.infraly.co): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Apr 28 22:25:29.544430 2026] [security2:error] [pid 24525:tid 24525] [client 45.45.237.139:38544] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.asaint.net"] [uri "/.env"] [unique_id "afFsGYp4m43An37GAxFIcwAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
EGP Abuse Dept
2026-04-29 00:30:06
(5 months ago)
Unsolicited connection to port 27017
Port Scan
Hacking
๐บ๐ธ
TPI-Abuse
2026-04-29 00:04:51
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 45.45.237.139 (hosted-by.infraly.co): 1 in the ...
show more
(mod_security) mod_security (id:210492) triggered by 45.45.237.139 (hosted-by.infraly.co): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Apr 28 20:04:45.775365 2026] [security2:error] [pid 21479:tid 21479] [client 45.45.237.139:55824] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.aokatheists.org"] [uri "/.env"] [unique_id "afFLHcyQBTLOqmN84htZIAAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-28 22:32:21
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 45.45.237.139 (hosted-by.infraly.co): 1 in the ...
show more
(mod_security) mod_security (id:210492) triggered by 45.45.237.139 (hosted-by.infraly.co): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Apr 28 18:32:10.735019 2026] [security2:error] [pid 8496:tid 8496] [client 45.45.237.139:40896] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.franklincountyquilters.org"] [uri "/.env"] [unique_id "afE1agjnFGldNdEhKnhmZgAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-28 21:25:39
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 45.45.237.139 (hosted-by.infraly.co): 1 in the ...
show more
(mod_security) mod_security (id:210492) triggered by 45.45.237.139 (hosted-by.infraly.co): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Apr 28 17:25:33.985211 2026] [security2:error] [pid 26404:tid 26404] [client 45.45.237.139:42304] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.sprek.net"] [uri "/.env"] [unique_id "afElzZvFdafMZFOoFw4xbgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-04-28 20:50:10
(5 months ago)
Multiple web server 400 error codes from same source ip
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-28 17:42:31
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 45.45.237.139 (hosted-by.infraly.co): 1 in the ...
show more
(mod_security) mod_security (id:210492) triggered by 45.45.237.139 (hosted-by.infraly.co): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Apr 28 13:42:23.942033 2026] [security2:error] [pid 12548:tid 12670] [client 45.45.237.139:37964] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "rosicrucian.net"] [uri "/.env"] [unique_id "afDxfxRYczACsmvlDFQyUwAAAZI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-04-28 15:04:33
(5 months ago)
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 45.45.237.139 (US/United States/hoste ...
show more
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 45.45.237.139 (US/United States/hosted-by.infraly.co): 1 in the last 3600 secs (0-195)
show less
Hacking
๐บ๐ธ
TPI-Abuse
2026-04-28 13:49:04
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 45.45.237.139 (hosted-by.infraly.co): 1 in the ...
show more
(mod_security) mod_security (id:210492) triggered by 45.45.237.139 (hosted-by.infraly.co): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Apr 28 09:49:00.505237 2026] [security2:error] [pid 25718:tid 25718] [client 45.45.237.139:35740] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "2-c.me.fydelity.net"] [uri "/.env"] [unique_id "afC6zOxijB_wE382TAhxRQAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-28 13:05:19
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 45.45.237.139 (hosted-by.infraly.co): 1 in the ...
show more
(mod_security) mod_security (id:210492) triggered by 45.45.237.139 (hosted-by.infraly.co): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Apr 28 09:05:14.049806 2026] [security2:error] [pid 368:tid 368] [client 45.45.237.139:44428] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.moonfest.net"] [uri "/.env"] [unique_id "afCwildVxMBvfOxeQLMPOgAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-28 11:49:37
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 45.45.237.139 (hosted-by.infraly.co): 1 in the ...
show more
(mod_security) mod_security (id:210492) triggered by 45.45.237.139 (hosted-by.infraly.co): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Apr 28 07:49:32.010373 2026] [security2:error] [pid 32692:tid 32692] [client 45.45.237.139:59782] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "my-pitch.org"] [uri "/.env"] [unique_id "afCezCh2tph-o5Sypt55PgAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-28 09:22:24
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 45.45.237.139 (hosted-by.infraly.co): 1 in the ...
show more
(mod_security) mod_security (id:210492) triggered by 45.45.237.139 (hosted-by.infraly.co): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Apr 28 05:22:20.848218 2026] [security2:error] [pid 3790:tid 3790] [client 45.45.237.139:51074] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "scienceandpoetrywithgrandpa.xyz"] [uri "/.env"] [unique_id "afB8TFz3pLFpb3jfiwnkYQAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
4server
2026-04-28 07:51:13
(5 months ago)
[TueApr2809:51:07.3727152026][security2:error][pid370588:tid370633][client45.45.237.139:0]ModSecurit ...
show more
[TueApr2809:51:07.3727152026][security2:error][pid370588:tid370633][client45.45.237.139:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:5\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.9\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"aaaa6877.org\"][uri\"/\"][unique_id\"afBm65mNP8D9wx-GQR3bDwAAAEY\"]
show less
Port Scan
Brute-Force
Web App Attack