Anonymous
2026-07-01 04:37:43
(2 months ago)
Failed login attempt detected by Fail2Ban in plesk-modsecurity jail
Exploited Host
π³π±
homeshowdomain.nl
2026-06-16 22:03:34
(2 months ago)
Auto-ban: >3000 req/min op 2026-06-16
Web App Attack
SSH
Hacking
πΊπΈ
TPI-Abuse
2026-06-16 16:07:57
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 51.15.26.43 (51-15-26-43.rev.poneytelecom.eu): ...
show more
(mod_security) mod_security (id:210492) triggered by 51.15.26.43 (51-15-26-43.rev.poneytelecom.eu): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 16 12:07:53.632046 2026] [security2:error] [pid 29577:tid 29577] [client 51.15.26.43:54578] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.lozzy.net"] [uri "/.env"] [unique_id "ajF02VhEXXxVtHJctRoRtAAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-16 15:38:29
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 51.15.26.43 (51-15-26-43.rev.poneytelecom.eu): ...
show more
(mod_security) mod_security (id:210492) triggered by 51.15.26.43 (51-15-26-43.rev.poneytelecom.eu): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 16 11:38:22.861154 2026] [security2:error] [pid 20404:tid 20404] [client 51.15.26.43:39878] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.lorendata.net"] [uri "/.env"] [unique_id "ajFt7jSlsE1MRGCLpqfTdwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
e.fierstra
2026-06-16 14:21:54
(2 months ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
π©πͺ
BlueWire Hosting
2026-06-16 13:59:54
(2 months ago)
Probing websites for vulnerabilities
Web App Attack
SQL Injection
π©πͺ
big-cloud.nl
2026-06-16 13:28:32
(2 months ago)
Try to access /.env
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-16 02:18:58
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 51.15.26.43 (51-15-26-43.rev.poneytelecom.eu): ...
show more
(mod_security) mod_security (id:210492) triggered by 51.15.26.43 (51-15-26-43.rev.poneytelecom.eu): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 15 22:18:51.598941 2026] [security2:error] [pid 27325:tid 27325] [client 51.15.26.43:48404] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.tecnoconce.cl"] [uri "/.env"] [unique_id "ajCyi7KXj5LydFm83pNXowAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³πΏ
Antinson
2026-06-15 18:55:13
(2 months ago)
Scraping with a high error ratio and request rate
Bad Web Bot
π«π·
dynamix
2026-06-14 19:05:17
(2 months ago)
Multiple WAF Violations
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-14 19:05:03
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 51.15.26.43 (51-15-26-43.rev.poneytelecom.eu): ...
show more
(mod_security) mod_security (id:210492) triggered by 51.15.26.43 (51-15-26-43.rev.poneytelecom.eu): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 15:04:56.893542 2026] [security2:error] [pid 21580:tid 21580] [client 51.15.26.43:56040] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.carterslawncare.net"] [uri "/.env"] [unique_id "ai77WEtwwEMmhvk1GKU0tgAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
Viveronese
2026-06-14 17:58:56
(2 months ago)
HTTP vulnerability scanning
Web App Attack
Anonymous
2026-06-14 12:55:01
(2 months ago)
suspicious request in access.log
Web App Attack
π¦πΊ
2000cn.com.au
2026-06-14 12:00:17
(2 months ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
πΊπΈ
TPI-Abuse
2026-06-14 05:41:07
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 51.15.26.43 (51-15-26-43.rev.poneytelecom.eu): ...
show more
(mod_security) mod_security (id:210492) triggered by 51.15.26.43 (51-15-26-43.rev.poneytelecom.eu): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 01:41:02.525764 2026] [security2:error] [pid 28024:tid 28024] [client 51.15.26.43:33282] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.starrmail.net"] [uri "/.env"] [unique_id "ai4-7jAgJCWMqlRPfw-G5gAAAG4"]
show less
Brute-Force
Bad Web Bot
Web App Attack