๐จ๐ญ
TheCoon
2026-07-18 05:00:02
(4 days ago)
Automated: Credential theft attempt - JSON bomb served
Web App Attack
Hacking
๐ณ๐ฑ
homeshowdomain.nl
2026-07-17 22:03:48
(5 days ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-07-16.
show less
Web App Attack
SSH
Hacking
๐บ๐ธ
TPI-Abuse
2026-07-17 00:44:27
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 47.76.90.44 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 47.76.90.44 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 16 20:44:23.409451 2026] [security2:error] [pid 1258:tid 1258] [client 47.76.90.44:64559] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "wokedreamer.com"] [uri "/.env.test"] [unique_id "all65wugdNOY5gbD8hP5zgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
findlab
2026-07-16 22:40:07
(6 days ago)
Backdrop CMS module - malicious activity detected
Bad Web Bot
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-07-16 22:03:10
(6 days ago)
Auto-ban: >3000 req/min op 2026-07-16
Web App Attack
SSH
Hacking
๐ฉ๐ช
todix
2026-07-16 21:35:51
(6 days ago)
Web App Attack Exploid from 47.76.90.44
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-16 20:56:03
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 47.76.90.44 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 47.76.90.44 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 16 16:55:58.492239 2026] [security2:error] [pid 7615:tid 7677] [client 47.76.90.44:31467] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.agrigrailtech.com"] [uri "/.env.backup"] [unique_id "allFXt15dZJOWSNZDvmxbwAAAgA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
Matthew Ping
2026-07-16 19:15:04
(6 days ago)
ModSecurity rule 949110 triggered on clearedge3d. Web application attack blocked by CSF/LFD.
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-07-16 18:51:03
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 47.76.90.44 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 47.76.90.44 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 16 14:48:00.239616 2026] [security2:error] [pid 20741:tid 20741] [client 47.76.90.44:62429] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.diary.kleens-uk.com"] [uri "/.env~"] [unique_id "alknYHmnuvFR8qrn8yPbOQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-07-16 18:09:27
(6 days ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-16 17:50:24
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 47.76.90.44 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 47.76.90.44 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 16 13:50:17.690709 2026] [security2:error] [pid 29052:tid 29052] [client 47.76.90.44:12957] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.restest.rayeliotschwartz.com"] [uri "/laravel/.env"] [unique_id "alkZ2XBuoouDTquN2CKcnAAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-16 17:26:48
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 47.76.90.44 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 47.76.90.44 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 16 13:26:38.120859 2026] [security2:error] [pid 28585:tid 28585] [client 47.76.90.44:10415] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "twangcaster.com"] [uri "/.env.test"] [unique_id "alkUTvgVP0G85PeKdEc8xgAAAD4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
VHosting
2026-07-16 17:20:04
(6 days ago)
Detected WordPress attack from 4 different servers
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-16 17:02:34
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 47.76.90.44 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 47.76.90.44 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 16 13:02:25.150643 2026] [security2:error] [pid 26178:tid 26178] [client 47.76.90.44:22783] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sabri.es"] [uri "/.env.sample"] [unique_id "alkOoU5eEXqGTW2u2QgwwwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฒ๐พ
Rizzy
2026-07-16 16:42:12
(6 days ago)
Multiple WAF Violations
Brute-Force
Web App Attack