🇺🇸
TPI-Abuse
2026-09-09 19:17:52
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 8.228.28.41 (41.28.228.8.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 8.228.28.41 (41.28.228.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 15:17:47.704276 2026] [security2:error] [pid 12171:tid 12171] [client 8.228.28.41:16894] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.pnp42.com.grancanariaholidays.com"] [uri "/@fs/..%252f..%252f..%252f..%252f..%252fapp/.env"] [unique_id "aqGw27HfH85ZuJDDF3GuKAAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 15:49:17
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 8.228.28.41 (41.28.228.8.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 8.228.28.41 (41.28.228.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 11:49:11.496326 2026] [security2:error] [pid 588:tid 588] [client 8.228.28.41:33036] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "lazymanvegan.com.trafficstopper.com"] [uri "/@fs/.env.local"] [unique_id "aqF_9wWeUos8nLBbfTOiDgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
Feelautom
2026-09-09 15:45:44
(4 hours ago)
[FeelAutom Auto-Ban] BotIdentityRotation: /@fs/..%252f..%252f..%252f..%252f..%252fproc/self/environ? ...
show more
[FeelAutom Auto-Ban] BotIdentityRotation: /@fs/..%252f..%252f..%252f..%252f..%252fproc/self/environ?raw?? (Score: 220)
show less
Hacking
🇨🇦
Not Fake
2026-09-09 14:31:10
(6 hours ago)
$f2bV_matches
Web App Attack
🇳🇱
svr
2026-09-09 13:39:26
(7 hours ago)
Abusive Automated Web Scanner
Web App Attack
🇮🇹
CoreTech srl
2026-09-09 13:13:57
(7 hours ago)
cloudlinux2 fail2ban: 2026-09-09 15:09:11,415 fail2ban.filter [1892]: INFO [plesk-modsecu ...
show more
cloudlinux2 fail2ban: 2026-09-09 15:09:11,415 fail2ban.filter [1892]: INFO [plesk-modsecurity] Found 8.228.28.41 - 2026-09-09 15:09:11cloudlinux2 fail2ban: 2026-09-09 15:09:11,394 fail2ban.filter [1892]: INFO [plesk-modsecurity] Found 8.228.28.41 - 2026-09-09 15:09:11cloudlinux2 fail2ban: 2026-09-09 15:09:11,785 fail2ban.filter [1892]: INFO [recidive] Found 8.228.28.41 - 2026-09-09 15:09:11cloudlinux2 fail2ban: 2026-09-09 15:09:11,779 fail2ban.actions [1892]: NOTICE [plesk-modsecurity] Ban 8.228.28.41cloudlinux2 fail2ban: 2026-09-09 15:09:56,631 fail2ban.filter [1892]: INFO [plesk-wordpress] Found 37.212.2.67 - 2026-09-09 15:09:55cloudlinux2 fail2ban: 2026-09-09 15:10:51,803 fail2ban.filter [1892]: INFO [plesk-modsecurity] Found 34.150.224.120 - 2026-09-09 15:10:51cloudlinux2 fail2ban: 2026-09-09 15:10:51,846 fail2ban.filter [1892]: INFO [plesk-modsecurity] Found 34.150.224.120 - 2026-09-09 15:10:51cloudlinux2 fail2ban: 2026-09-09 15:10
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 12:33:17
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 8.228.28.41 (41.28.228.8.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 8.228.28.41 (41.28.228.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 08:33:14.526894 2026] [security2:error] [pid 1824:tid 1824] [client 8.228.28.41:21594] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.cleaningsuppliescr.elcocotours.com"] [uri "/@fs/.env"] [unique_id "aqFSCkvAmrLUoG-Cdi53hwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
bescared
2026-09-09 12:19:37
(8 hours ago)
F2B - Malicious activity detected. Too many 403. -8ff06ede-
Bad Web Bot
Web App Attack
🇩🇪
bescared
2026-09-09 12:19:00
(8 hours ago)
WAF (1) - Referer spoofing.
Hacking
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 12:17:19
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 8.228.28.41 (41.28.228.8.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 8.228.28.41 (41.28.228.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 08:17:14.950858 2026] [security2:error] [pid 26300:tid 26300] [client 8.228.28.41:47408] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "toomuchcaffeine.theillustrator.net"] [uri "/@fs/.env"] [unique_id "aqFOSr4QFZjtrrJJn5fH7wAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 11:45:26
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 8.228.28.41 (41.28.228.8.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 8.228.28.41 (41.28.228.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 07:45:19.906166 2026] [security2:error] [pid 22210:tid 22210] [client 8.228.28.41:62922] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.solarfarms.info"] [uri "/@fs/app/.env"] [unique_id "aqFGz8PU-nv0k6M3pWix8AAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
Jochen Pretli
2026-09-09 11:04:42
(9 hours ago)
connection to honeypot
Email Spam
Port Scan
🇺🇸
TPI-Abuse
2026-09-09 11:04:33
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 8.228.28.41 (41.28.228.8.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 8.228.28.41 (41.28.228.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 07:04:27.448304 2026] [security2:error] [pid 18404:tid 18404] [client 8.228.28.41:46922] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.blairsmasterplan.com"] [uri "/@fs/.env.production"] [unique_id "aqE9OztrLzM82_oMb1QL6wAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-09 10:18:16
(10 hours ago)
Multiple web server 400 error codes from same source ip
Web App Attack
🇩🇪
LRob
2026-09-09 09:58:37
(10 hours ago)
Enumerating paths that do not exist (scanning) | method: GET | path: /@fs/..%252f..%252f..%252f..%25 ...
show more
Enumerating paths that do not exist (scanning) | method: GET | path: /@fs/..%252f..%252f..%252f..%252f..%252fproc/self/environ (+6 more) | ua: Mozilla/5.0 (Linux; Android 15; SM-S918B) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/109.0.5755.137 Mobile Safari/537.36; com (+6 more) | 2026-09-09 09:58 UTC
show less
Port Scan
Web App Attack