🇺🇸
TPI-Abuse
2026-09-11 02:05:37
(2 minutes ago)
(mod_security) mod_security (id:210492) triggered by 66.163.115.174 (174-115-163-66.clients.gthost.c ...
show more
(mod_security) mod_security (id:210492) triggered by 66.163.115.174 (174-115-163-66.clients.gthost.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 10 22:05:29.316471 2026] [security2:error] [pid 6536:tid 6536] [client 66.163.115.174:58886] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.204"] [uri "/.env"] [unique_id "aqNh6UC0obFGmfKjB6L0dwAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
factor1
2026-09-11 02:03:47
(4 minutes ago)
CrowdSec at thor Reports Abuse
Web App Attack
🇩🇪
Philister11
2026-09-11 02:01:29
(7 minutes ago)
CrowdSec: crowdsecurity/http-cve-2021-41773 (US/AS63023)
Web App Attack
Hacking
🇩🇪
SwinT
2026-09-11 02:00:04
(8 minutes ago)
WAF repeated trigger detected by Fail2Ban in plesk-modsecurity jail
Web App Attack
🇺🇸
legionMCCXV
2026-09-11 01:57:32
(11 minutes ago)
Non-HTTP protocol data (e.g. MQTT/TLS handshake bytes) sent to HTTP(S) port.
Port Scan
Hacking
🇹🇭
MWA SOC
2026-09-11 01:52:23
(16 minutes ago)
Hacking
🇩🇪
Holger
2026-09-11 01:49:39
(18 minutes ago)
URL probing: GET /config.json
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 01:41:36
(26 minutes ago)
(mod_security) mod_security (id:210492) triggered by 66.163.115.174 (174-115-163-66.clients.gthost.c ...
show more
(mod_security) mod_security (id:210492) triggered by 66.163.115.174 (174-115-163-66.clients.gthost.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 10 21:41:28.401638 2026] [security2:error] [pid 31038:tid 31038] [client 66.163.115.174:52374] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.107"] [uri "/.env.staging"] [unique_id "aqNcSAdhLiC40u9HG2GzngAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
AetherFox
2026-09-11 01:37:56
(30 minutes ago)
AetherFox VoidGuard detected: [Fri Sep 11 01:37:48.370273 2026] [authz_core:error] [pid 1741898:tid ...
show more
AetherFox VoidGuard detected: [Fri Sep 11 01:37:48.370273 2026] [authz_core:error] [pid 1741898:tid 1741936] [client 66.163.115.174:40010] AH01630: client denied by server configuration: proxy:http://[MASKED]/
[Fri Sep 11 01:37:48.370367 2026] [authz_core:error] [pid 1741898:tid 1741936] [client 66.163.115.174:40010] AH01630: client denied by server configuration: /var/www/html/ERRORpages/403.html
[Fri Sep 11 01:37:55.878731 2026] [authz_core:error] [pid 1741898:tid 1741931] [client 66.163.115.174:50116] AH01630: client denied by server configuration: proxy:http://[MASKED]/.DS_Store
[Fri Sep 11 01:37:55.878806 2026] [authz_core:error] [pid 1741898:tid 1741931] [client 66.163.115.174:50116] AH01630: client denied by server configuration: /var/www/html/ERRORpages/403.html
[Fri Sep 11 01:37:56.085226 2026] [authz_core:error] [pid 1741898:tid 1741930] [client 66.163.115.174:50132] AH01630: client denied by server configuration: proxy:http://[MASKED]/app.json
...
show less
Bad Web Bot
Web App Attack
Anonymous
2026-09-11 01:27:06
(41 minutes ago)
[Fri Sep 11 03:26:55.647833 2026] [access_compat:error] [pid 4037847:tid 131380692379328] [client 66 ...
show more
[Fri Sep 11 03:26:55.647833 2026] [access_compat:error] [pid 4037847:tid 131380692379328] [client 66.163.115.174:59924] AH01797: client denied by server configuration: /var/www/html/
[Fri Sep 11 03:27:03.556075 2026] [access_compat:error] [pid 4037847:tid 131380314871488] [client 66.163.115.174:59948] AH01797: client denied by server configuration: /var/www/html/.DS_Store
[Fri Sep 11 03:27:03.838920 2026] [access_compat:error] [pid 4037846:tid 131380683986624] [client 66.163.115.174:59956] AH01797: client denied by server configuration: /var/www/html/info.php
[Fri Sep 11 03:27:04.113568 2026] [access_compat:error] [pid 4037847:tid 131380700772032] [client 66.163.115.174:59966] AH01797: client denied by server configuration: /var/www/html/.json
[Fri Sep 11 03:27:04.385667 2026] [access_compat:error] [pid 4037846:tid 131380925155008] [client 66.163.115.174:59974] AH01797: client denied by server configuration: /var/www/html/.env.save
[Fri Sep 11 03:27:04.655586 2026] [access_compat:error
...
show less
Brute-Force
Web App Attack
🇬🇧
Don Felip
2026-09-11 01:23:15
(45 minutes ago)
Web Exploiter - Banned by Fail2Ban
Hacking
Web App Attack
🇹🇷
oalver
2026-09-11 01:20:07
(48 minutes ago)
Detected by SiberKapan threat intelligence platform (siberkapan.org). Attack types: honeypot_http. S ...
show more
Detected by SiberKapan threat intelligence platform (siberkapan.org). Attack types: honeypot_http. Sources: honeypot. First seen: 2026-09-10. Risk score: 90/100.
show less
Web App Attack
🇩🇪
XYCoderXY
2026-09-11 01:20:06
(48 minutes ago)
SSH/web brute-force & exploit scanning against lumerux.com (automated report).
Brute-Force
SSH
🇳🇱
WeCloudit-Anti-Abuse
2026-09-11 01:19:37
(48 minutes ago)
This IP was detected by CrowdSec triggering crowdsecurity/jira_cve-2021-26086
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-11 01:14:17
(54 minutes ago)
(mod_security) mod_security (id:210492) triggered by 66.163.115.174 (174-115-163-66.clients.gthost.c ...
show more
(mod_security) mod_security (id:210492) triggered by 66.163.115.174 (174-115-163-66.clients.gthost.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 10 21:14:13.856523 2026] [security2:error] [pid 21773:tid 21773] [client 66.163.115.174:46084] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.220"] [uri "/.env.local"] [unique_id "aqNV5eF9wN2vTrddJ7uvMwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack