๐ณ๐ฑ
Site.eu
2026-05-14 23:31:28
(4 months ago)
Excessive multi-domain requests
Brute-Force
๐บ๐ธ
octageeks.com
2026-05-14 04:07:37
(4 months ago)
Wordpress malicious attack:[octablocked]
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-13 15:40:42
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 5.255.99.100 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 5.255.99.100 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 13 11:40:35.797558 2026] [security2:error] [pid 25052:tid 25052] [client 5.255.99.100:43512] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "lakewyliehairsalon.com"] [uri "/.git/config"] [unique_id "agSbczpU3qNqKJUw8pJMgAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-13 15:20:54
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 5.255.99.100 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 5.255.99.100 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 13 11:20:50.365745 2026] [security2:error] [pid 13484:tid 13484] [client 5.255.99.100:44564] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "lakesideshelving.com"] [uri "/.git/config"] [unique_id "agSW0o1gWn4fPtQJEr-bUgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-05-13 15:05:22
(4 months ago)
(caddyscan) Scanner path probe from 5.255.99.100 (NL/The Netherlands/-): 5 in the last 3600 secs; Po ...
show more
(caddyscan) Scanner path probe from 5.255.99.100 (NL/The Netherlands/-): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 2627 5.255.99.100 - - [13/May/2026:15:05:16 +0000] "GET /.aws/credentials HTTP/1.1"
[REDACTED] 200 2627 5.255.99.100 - - [13/May/2026:15:05:17 +0000] "GET /.env.local HTTP/1.1"
[REDACTED] 200 2627 5.255.99.100 - - [13/May/2026:15:05:17 +0000] "GET /app/.env HTTP/1.1"
[REDACTED] 200 2627 5.255.99.100 - - [13/May/2026:15:05:17 +0000] "GET /backend/.env HTTP/1.1"
[REDACTED] 200 2627 5.255.99.100 - - [13/May/2026:15:05:17 +0000] "GET /.env.production HTTP/1.1"
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-05-13 14:19:08
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 5.255.99.100 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 5.255.99.100 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 13 10:19:01.470083 2026] [security2:error] [pid 28407:tid 28407] [client 5.255.99.100:57196] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "lajoyadelmar.net"] [uri "/.env.local"] [unique_id "agSIVbYAtah6M9XmSE1j-AAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ฆ
SSH-Admin
2026-05-13 14:00:05
(4 months ago)
Probing for Exploits on ns200
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-13 13:26:57
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 5.255.99.100 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 5.255.99.100 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 13 09:26:52.055830 2026] [security2:error] [pid 10024:tid 10024] [client 5.255.99.100:58352] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "lahaciendaolivia.com"] [uri "/.env.example"] [unique_id "agR8HGNny7VWC7msypyMOgAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ฆ
SSH-Admin
2026-05-13 13:25:03
(4 months ago)
Probing for Exploits on ns74
Exploited Host
Web App Attack
๐ฉ๐ช
LRob
2026-05-13 13:00:08
(4 months ago)
Repeated 403 errors, blocked by Fail2ban in custom-403 jail
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-05-13 12:50:01
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 5.255.99.100 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 5.255.99.100 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 13 08:49:58.130342 2026] [security2:error] [pid 20334:tid 20341] [client 5.255.99.100:60888] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "lagifthouse.com"] [uri "/public/.env"] [unique_id "agRzdjqtLp8R16gYV5rVEgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-05-13 11:37:18
(4 months ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-13 11:04:51
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 5.255.99.100 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 5.255.99.100 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 13 07:04:43.487598 2026] [security2:error] [pid 11339:tid 11339] [client 5.255.99.100:38398] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ladylilacfarm.com"] [uri "/.env.old"] [unique_id "agRay3HL34CWce6G8WpaHAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
wlt-blocker
2026-05-13 10:31:34
(4 months ago)
Unauthorized access to webpage admin
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-13 10:16:15
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 5.255.99.100 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 5.255.99.100 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 13 06:16:10.657530 2026] [security2:error] [pid 17689:tid 17689] [client 5.255.99.100:42528] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ladbc.club"] [uri "/.env.staging"] [unique_id "agRPalqqcnLb7iLqoHPoHgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack