|
Anonymous
|
|
Failed login attempt detected by Fail2Ban in plesk-modsecurity jail
|
Exploited Host
|
|
|
๐ฟ๐ฆ
conure
|
|
csagent: score 20.5: secrets grab x2, 404 noise floor x2; 1 domain(s) in 0s
|
Web App Attack
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:210492) triggered by 47.245.114.12 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 47.245.114.12 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 13 01:16:55.801986 2026] [security2:error] [pid 24094:tid 24094] [client 47.245.114.12:56886] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.beach98.com"] [uri "/.git/config"] [unique_id "alR0x9o4cKwvvcWheFiZKwAAAAk"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:210492) triggered by 47.245.114.12 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 47.245.114.12 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 13 00:41:34.378134 2026] [security2:error] [pid 17612:tid 17612] [client 47.245.114.12:42272] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "rdj.us"] [uri "/.git/config"] [unique_id "alRsfjSxLSDRohVY6L0WjwAAAAk"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:210492) triggered by 47.245.114.12 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 47.245.114.12 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 13 00:10:43.978329 2026] [security2:error] [pid 7197:tid 7197] [client 47.245.114.12:54296] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "micro-analisis.com"] [uri "/.env"] [unique_id "alRlQzK_3tba6kbIyjqBgQAAAA0"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
Anonymous
|
|
Blocked: Reason='Suspicious traffic score=60 (review-based detection)'; Requests=4
|
Hacking
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:210492) triggered by 47.245.114.12 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 47.245.114.12 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 12 23:41:32.073960 2026] [security2:error] [pid 19664:tid 19664] [client 47.245.114.12:46506] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "indiahouseportland.com"] [uri "/.env"] [unique_id "alRebKjYzG7hWXjJrXffPAAAABg"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐ฟ๐ฆ
conure
|
|
csagent: score 17.5: 404 noise floor x2, secrets grab x2; 1 domain(s) in 1m0s
|
Web App Attack
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:210492) triggered by 47.245.114.12 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 47.245.114.12 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 12 23:22:39.815498 2026] [security2:error] [pid 4802:tid 4802] [client 47.245.114.12:35554] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "galvez.cc"] [uri "/.env"] [unique_id "alRZ_xXjRpUePfSsvsfCrgAAAA8"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐ซ๐ท
masterguru
|
|
Restricted File Access Attempt. Matched phrase ".env" at REQUEST_FILENAME. (930130-193)
|
Hacking
Web App Attack
|
|
|
๐ณ๐ฑ
BlueWire Hosting
|
|
Probing websites for vulnerabilities
|
Web App Attack
|
|
|
๐ซ๐ท
โจ
|
|
Domain : redirect.netenergy.uk
Rule : env
2026-07-13 02:44:36 217.194.210.152 GET /.env - 443 - 47.2 ...
show more
Domain : redirect.netenergy.uk
Rule : env
2026-07-13 02:44:36 217.194.210.152 GET /.env - 443 - 47.245.114.12 HTTP/1.1 Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.2.1 Safari/605.1.1 - budehouse.co.uk 404 0 2 1552 242 199 - -
show less
|
Hacking
SQL Injection
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:210492) triggered by 47.245.114.12 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 47.245.114.12 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 12 22:46:54.912020 2026] [security2:error] [pid 5494:tid 5494] [client 47.245.114.12:51636] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cartiologyfilms.com"] [uri "/.env"] [unique_id "alRRnvMoLLMoqIE-qW6YaQAAAAE"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:210492) triggered by 47.245.114.12 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 47.245.114.12 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 12 22:30:12.862448 2026] [security2:error] [pid 22994:tid 22994] [client 47.245.114.12:57626] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "anniversaryweddingfavors.com"] [uri "/.git/config"] [unique_id "alRNtFralmo38Dv1deA6EAAAAAI"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
Anonymous
|
|
suspicious request in access.log
|
Web App Attack
|
|