๐ซ๐ท
ingroscart.it
2026-10-09 13:16:37
(2 days ago)
(mod_security) mod_security triggered on hostname [redacted])
SQL Injection
๐บ๐ธ
TPI-Abuse
2026-10-09 13:08:05
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 74.208.68.217 (ip74-208-68-217.pbiaas.com): 1 i ...
show more
(mod_security) mod_security (id:210492) triggered by 74.208.68.217 (ip74-208-68-217.pbiaas.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 09:08:00.453156 2026] [security2:error] [pid 20097:tid 20124] [client 74.208.68.217:20248] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "leadingedgesupply.com"] [uri "/.env"] [unique_id "asjnMDstw9vSSdByD8lFBwAAAVQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-10-09 10:50:01
(2 days ago)
suspicious request in access.log
Web App Attack
๐ฉ๐ช
altenglaner
2026-10-09 07:33:32
(2 days ago)
Web scanner probing for sensitive files (.env, .git, backups) or path traversal. Reported by fail2ba ...
show more
Web scanner probing for sensitive files (.env, .git, backups) or path traversal. Reported by fail2ban.
show less
Hacking
Web App Attack
Anonymous
2026-10-09 06:45:00
(2 days ago)
Phishing aimed at stealing email credentials
Phishing
Anonymous
2026-10-09 06:43:29
(2 days ago)
Sensitive Configuration File Disclosure.
Hacking
Anonymous
2026-10-09 06:34:11
(2 days ago)
Web App Attack
Brute-Force
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-09 04:12:28
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 74.208.68.217 (ip74-208-68-217.pbiaas.com): 1 i ...
show more
(mod_security) mod_security (id:210492) triggered by 74.208.68.217 (ip74-208-68-217.pbiaas.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 00:12:24.012372 2026] [security2:error] [pid 3017:tid 3017] [client 74.208.68.217:12513] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "hardemancountyjournal.com"] [uri "/.env"] [unique_id "ashpqKjpr-Dsnh_ORk5e6wAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
foff
2026-10-09 02:44:53
(2 days ago)
Source IP: 74.208.68.217 (US/IONOS SE). Web application attack detected by OWASP CRS (local file inc ...
show more
Source IP: 74.208.68.217 (US/IONOS SE). Web application attack detected by OWASP CRS (local file inclusion). Attack observed 2026-10-09T13:44:53+11:00.
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-09 02:06:47
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 74.208.68.217 (ip74-208-68-217.pbiaas.com): 1 i ...
show more
(mod_security) mod_security (id:210492) triggered by 74.208.68.217 (ip74-208-68-217.pbiaas.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 22:06:41.379365 2026] [security2:error] [pid 32193:tid 32193] [client 74.208.68.217:7573] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "intersession.net"] [uri "/.env"] [unique_id "ashMMYKpoMjDPyKkK9Vx2AAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-09 01:23:16
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 74.208.68.217 (ip74-208-68-217.pbiaas.com): 1 i ...
show more
(mod_security) mod_security (id:210492) triggered by 74.208.68.217 (ip74-208-68-217.pbiaas.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 21:23:11.908653 2026] [security2:error] [pid 29880:tid 29880] [client 74.208.68.217:33787] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mdivietnam.com"] [uri "/.env"] [unique_id "ashB_2b4Jlk_jfROVlM9KQAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
Lee Daniel
2026-10-09 01:05:47
(2 days ago)
74.208.68.217 - - [08/Oct/2026:21:05:47 -0400] "GET /.env HTTP/1.1" 403 6297 "-" "Mozilla/5.0 (X11; ...
show more
74.208.68.217 - - [08/Oct/2026:21:05:47 -0400] "GET /.env HTTP/1.1" 403 6297 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36"
...
show less
DDoS Attack
Web Spam
Email Spam
Port Scan
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-09 00:13:03
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 74.208.68.217 (ip74-208-68-217.pbiaas.com): 1 i ...
show more
(mod_security) mod_security (id:210492) triggered by 74.208.68.217 (ip74-208-68-217.pbiaas.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 20:12:57.639793 2026] [security2:error] [pid 6918:tid 6918] [client 74.208.68.217:52353] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "adonamusic.com"] [uri "/.env"] [unique_id "asgxib0Q-rdRuZk8MM_FfgAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 23:48:52
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 74.208.68.217 (ip74-208-68-217.pbiaas.com): 1 i ...
show more
(mod_security) mod_security (id:210492) triggered by 74.208.68.217 (ip74-208-68-217.pbiaas.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 19:48:45.938099 2026] [security2:error] [pid 26443:tid 26443] [client 74.208.68.217:15884] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mchen-arch.com"] [uri "/.env"] [unique_id "asgr3btmAN_18Vrxi4UVYgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 23:11:57
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 74.208.68.217 (ip74-208-68-217.pbiaas.com): 1 i ...
show more
(mod_security) mod_security (id:210492) triggered by 74.208.68.217 (ip74-208-68-217.pbiaas.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 19:11:50.180164 2026] [security2:error] [pid 25004:tid 25004] [client 74.208.68.217:21458] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "morninginc.com"] [uri "/.env"] [unique_id "asgjNuU5ouTXIAJ_iGopbQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack