Anonymous
2026-06-26 23:47:02
(2 days ago)
Attempted search for exploits and vulnerabilities detected by fail2ban
...
Port Scan
Brute-Force
๐ณ๐ฑ
e.fierstra
2026-06-26 18:47:55
(2 days ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐ณ๐ฟ
Antinson
2026-06-26 12:11:51
(2 days ago)
Scraping with a high error ratio and request rate
Bad Web Bot
๐น๐ท
Threat.live
2026-06-26 09:40:03
(2 days ago)
Suspicious Connection Attempts
Brute-Force
๐ฉ๐ช
ger-stg-sifi1
2026-06-25 15:18:58
(3 days ago)
(wordpress) Failed wordpress login using wp-login.php or xmlrpc.php
Web App Attack
๐ฉ๐ช
Vegascosmetics
2026-06-25 12:11:12
(3 days ago)
(Kingcopy.org-AI-IDS-Report):IP automatically blocked after suspicious activity. Vegas Security
DDoS Attack
Hacking
Exploited Host
๐บ๐ธ
TPI-Abuse
2026-06-25 10:54:28
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 65.110.40.49 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 65.110.40.49 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 25 06:54:24.024361 2026] [security2:error] [pid 20055:tid 20071] [client 65.110.40.49:25970] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "rosendalsateri.com"] [uri "/.env.local.backup"] [unique_id "aj0I4MK8mfuiEvGpAYGqYgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-25 10:20:38
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 65.110.40.49 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 65.110.40.49 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 25 06:20:34.613810 2026] [security2:error] [pid 5097:tid 5097] [client 65.110.40.49:46344] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.aemcmullin.com"] [uri "/.git/refs/heads/master"] [unique_id "aj0A8r-9CFcl1Xcl5uYy1AAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-06-25 10:08:29
(3 days ago)
URL file extension is restricted by policy. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ ...
show more
URL file extension is restricted by policy. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. (920440-131)
show less
Hacking
๐ฉ๐ช
LRob.fr
2026-06-25 10:00:12
(3 days ago)
Repeated 404 errors, blocked by Fail2ban in custom-404 jail
Bad Web Bot
Anonymous
2026-06-25 09:31:12
(3 days ago)
WordPress LiteSpeed Cache Plugin Information Disclosure (CVE-2024-44000).
Hacking
๐บ๐ธ
TPI-Abuse
2026-06-25 08:44:16
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 65.110.40.49 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 65.110.40.49 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 25 04:44:10.018539 2026] [security2:error] [pid 5368:tid 5368] [client 65.110.40.49:33516] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "test.tckgbookkeeping.biz"] [uri "/.env.local.save"] [unique_id "ajzqWl9nSMO_tZoSnjveywAAADA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฑ๐ป
garmtech.com
2026-06-25 08:15:52
(3 days ago)
Attempted access to sensitive endpoint (/.env.local) detected. Automated scan or unauthorized probin ...
show more
Attempted access to sensitive endpoint (/.env.local) detected. Automated scan or unauthorized probing.
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-25 07:26:39
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 65.110.40.49 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 65.110.40.49 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 25 03:26:32.715371 2026] [security2:error] [pid 30415:tid 30415] [client 65.110.40.49:36550] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "gmroyalties.soviaenterprises.com"] [uri "/.env.production.copy"] [unique_id "ajzYKIfyCuGC__tdfvVcUQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ธ๐ฎ
administrator
2026-06-25 06:17:39
(3 days ago)
2026-06-25 08:17:39,196 fail2ban.actions [1067]: NOTICE [apache-badbots] Ban 65.110.40.49
20 ...
show more
2026-06-25 08:17:39,196 fail2ban.actions [1067]: NOTICE [apache-badbots] Ban 65.110.40.49
2026-06-25 08:17:39,237 fail2ban.actions [1067]: NOTICE [apache-auth] Ban 65.110.40.49
2026-06-25 08:17:39,247 fail2ban.actions [1067]: NOTICE [apache-botsearch] Ban 65.110.40.49
...
show less
Bad Web Bot
Web Spam
Email Spam
Blog Spam
Port Scan
Brute-Force
Web App Attack