๐ฆ๐น
Tobias Gion
2026-09-07 01:08:42
(2 weeks ago)
Bad Web Bot
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-09-06 21:59:11
(2 weeks ago)
Auto-ban: >3000 req/min op 2026-09-06
Web App Attack
SSH
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-06 03:54:53
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 8.228.246.53 (53.246.228.8.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 8.228.246.53 (53.246.228.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 23:54:44.962521 2026] [security2:error] [pid 17720:tid 17720] [client 8.228.246.53:57790] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.pa-ksa.com"] [uri "/.env.save"] [unique_id "apzkBHJxfI_0bJkSBJ40CgAAAEE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ด
jad-abuse
2026-09-06 03:37:17
(2 weeks ago)
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: env_probe ...
show more
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: env_probe, scanner_ua, source_backup, config_backup, actuator, ignition_debug. Observed by 1 sensor(s); 26 hits.
show less
Hacking
Web App Attack
๐ฉ๐ช
4server
2026-09-06 03:00:49
(2 weeks ago)
[SunSep0605:00:44.5301492026][security2:error][pid2368088:tid2368146][client8.228.246.53:0]ModSecuri ...
show more
[SunSep0605:00:44.5301492026][security2:error][pid2368088:tid2368146][client8.228.246.53:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Patternmatch\"\(\?i\)\(\?:/\(\?:\^\|/\)\\\\\\\\.\(env\|git\|svn\|hg\|DS_Store\)\|/\(\?:wp-config\|\\\\\\\\.htaccess\|\\\\\\\\.htpasswd\)\|\\\\\\\\.\(\?:sql\|bak\|old\|log\)\$\)\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"156\"][id\"960720\"][msg\"Forbiddenfileaccessattempt\"][severity\"CRITICAL\"][hostname\"webdisk.formet.ch\"][uri\"/.env.old\"][unique_id\"apzXXITnmYYhGadfbXfsuAAAAFQ\"]
show less
Port Scan
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-06 01:23:08
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 8.228.246.53 (53.246.228.8.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 8.228.246.53 (53.246.228.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 21:23:01.552526 2026] [security2:error] [pid 2092:tid 2092] [client 8.228.246.53:54006] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "hydrogenplus.rejuvenationsystems.com"] [uri "/.env.backup"] [unique_id "apzAdWgeb166z2AIlucOCQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-06 00:28:10
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 8.228.246.53 (53.246.228.8.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 8.228.246.53 (53.246.228.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 20:28:07.083059 2026] [security2:error] [pid 4282:tid 4282] [client 8.228.246.53:46018] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "videos.mathewyoung.com"] [uri "/.env.prod"] [unique_id "apyzl88TxQkenbil3zdykQAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-06 00:12:23
(2 weeks ago)
8.228.246.53 - - [06/Sep/2026:02:12:18 +0200] "GET /wp-config.php.swp HTTP/1.1" 403 164 "-" "crusade ...
show more
8.228.246.53 - - [06/Sep/2026:02:12:18 +0200] "GET /wp-config.php.swp HTTP/1.1" 403 164 "-" "crusader-worker/1.0"
8.228.246.53 - - [06/Sep/2026:02:12:18 +0200] "GET /.env.save HTTP/1.1" 403 164 "-" "crusader-worker/1.0"
8.228.246.53 - - [06/Sep/2026:02:12:18 +0200] "GET /crusader-404-probe HTTP/1.1" 404 164 "-" "crusader-worker/1.0"
8.228.246.53 - - [06/Sep/2026:02:12:18 +0200] "GET /.env HTTP/1.1" 403 164 "-" "crusader-worker/1.0"
8.228.246.53 - - [06/Sep/2026:02:12:18 +0200] "GET /_ignition/health-check HTTP/1.1" 404 164 "-" "crusader-worker/1.0"
8.228.246.53 - - [06/Sep/2026:02:12:18 +0200] "GET /.env.dev HTTP/1.1" 403 164 "-" "crusader-worker/1.0"
8.228.246.53 - - [06/Sep/2026:02:12:18 +0200] "GET /.env.prod HTTP/1.1" 403 164 "-" "crusader-worker/1.0"
8.228.246.53 - - [06/Sep/2026:02:12:18 +0200] "GET /.env.local HTTP/1.1" 403 164 "-" "crusader-worker/1.0"
8.228.246.53 - - [06/Sep/2026:02:12:18 +0200] "GET /actuator/configprops HTTP/1.1" 404 164 "-" "crusader-worker/1.0"
8.228.246.
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-05 23:55:17
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 8.228.246.53 (53.246.228.8.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 8.228.246.53 (53.246.228.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 19:55:13.478603 2026] [security2:error] [pid 7939:tid 7939] [client 8.228.246.53:36880] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.jinkokyudojo.com"] [uri "/.env.bak"] [unique_id "apyr4WG9_BdZYjHby6zrCAAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-09-05 23:31:12
(2 weeks ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐ฉ๐ช
getdk
2026-09-05 22:50:11
(2 weeks ago)
[Sat Sep 05 22:50:10.637668 2026] [security2:error] [pid 1232770] [client 8.228.246.53:36720] [clien ...
show more
[Sat Sep 05 22:50:10.637668 2026] [security2:error] [pid 1232770] [client 8.228.246.53:36720] [client 8.228.246.53] ModSecurity: Access denied with code 403 (phas
...
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
VHosting
2026-09-05 22:20:03
(2 weeks ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐ฌ๐ง
Aetherweb Ark
2026-09-05 22:13:59
(2 weeks ago)
(mod_security) mod_security (id:949110) triggered by 8.228.246.53 (US/United States/53.246.228.8.bc. ...
show more
(mod_security) mod_security (id:949110) triggered by 8.228.246.53 (US/United States/53.246.228.8.bc.googleusercontent.com): N in the last X secs
show less
Web App Attack
๐บ๐ธ
mnsf
2026-09-05 22:06:44
(2 weeks ago)
Abuse Detected (1)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-05 21:21:01
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 8.228.246.53 (53.246.228.8.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 8.228.246.53 (53.246.228.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 17:20:53.203336 2026] [security2:error] [pid 2830:tid 2830] [client 8.228.246.53:59978] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "vanmeter.work"] [uri "/.env.production"] [unique_id "apyHtZJTqx_SXpigUBLqOAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack