Anonymous
2026-09-14 16:33:06
(8 hours ago)
Failed login attempt detected by Fail2Ban in plesk-modsecurity jail
Exploited Host
🇺🇸
xxkodedxx
2026-09-13 15:40:36
(1 day ago)
[Zorvexus edge-defense] GET .env / WordPress honeypot probe
Trigger: 1× honeypot-get, 15× edge-block ...
show more
[Zorvexus edge-defense] GET .env / WordPress honeypot probe
Trigger: 1× honeypot-get, 15× edge-block in 10m window.
Origin: US / AS396982 Google LLC
Active: 15:40:18→15:40:31 UTC
Volume: 114 HTTP req, 66 honeypot probe(s)
Bait taken: /config.json, /wp-json, /build../.env, /dist../.env, /public../.env
Status mix: 200×85 444×15 405×6 404×5 499×2 301×1
UA: "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36"
Auto-banned 30d. zorvexus-banner.
show less
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-13 15:08:12
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 8.231.138.100 (100.138.231.8.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 8.231.138.100 (100.138.231.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 11:08:05.018231 2026] [security2:error] [pid 5399:tid 5417] [client 8.231.138.100:59034] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "zoomtexas.com"] [uri "/static//home/user/.env"] [unique_id "aqa8VcsX92qw2Q3sQXjN7QAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-13 14:51:26
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 8.231.138.100 (100.138.231.8.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 8.231.138.100 (100.138.231.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 10:51:21.737531 2026] [security2:error] [pid 3722:tid 3722] [client 8.231.138.100:58520] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "zoboz.com"] [uri "/@fs/.env"] [unique_id "aqa4aT4iD-ZkRV4chMzqSgAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
dbmwebdesign
2026-09-13 13:40:06
(1 day ago)
WAF repeated trigger detected by Fail2Ban in plesk-modsecurity jail
Web App Attack
🇺🇸
TPI-Abuse
2026-09-13 12:57:49
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 8.231.138.100 (100.138.231.8.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 8.231.138.100 (100.138.231.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 08:57:45.475037 2026] [security2:error] [pid 19579:tid 19579] [client 8.231.138.100:34544] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||xmlprotocol.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "xmlprotocol.com"] [uri "/z9x8c7v6b5-debug-trigger-xmlprotocol.com"] [unique_id "aqadyQEit1WZflmk1LgXCgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-13 10:19:42
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 8.231.138.100 (100.138.231.8.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 8.231.138.100 (100.138.231.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 06:19:37.026172 2026] [security2:error] [pid 22694:tid 22694] [client 8.231.138.100:38212] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "xcingenieria.com"] [uri "/images../.env"] [unique_id "aqZ4ufUOmjVDiwjfIfLlOwAAACU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-13 09:07:03
(1 day ago)
Automated web scanner. Requested suspicious paths: /static/.env | /.vite/manifest.json | /build/mani ...
show more
Automated web scanner. Requested suspicious paths: /static/.env | /.vite/manifest.json | /build/manifest.json | /dist/manifest.json | /dist/.vite/manifest.json | /wp-json | /files../.env | /media../.env. UTC: 2026-09-13 08:47:40.
show less
Web App Attack
🇨🇦
lakered
2026-09-13 08:32:22
(1 day ago)
Detectors: [NGINX, SURICATA] | Reasons: Suricata: Web Server attack | Automated scan targeting an un ...
show more
Detectors: [NGINX, SURICATA] | Reasons: Suricata: Web Server attack | Automated scan targeting an unauthorized host or default server sinkhole | Evidence: Verified-Bot-JA4-Match (t13d1516h2) | TCP Fingerprint: Modern Linux (Kernel 3.x+) (Link:generic tunnel or VPN, Uptime:0m)
show less
Web App Attack
Hacking
Port Scan
Bad Web Bot
🇩🇪
itsolon
2026-09-13 08:02:36
(1 day ago)
[13/Sep/2026:10:02:35 +0200] 178928655515.699329 8.231.138.100 56990 217.154.7.177 443
[13/Sep/2026: ...
show more
[13/Sep/2026:10:02:35 +0200] 178928655515.699329 8.231.138.100 56990 217.154.7.177 443
[13/Sep/2026:10:02:35 +0200] 178928655559.098609 8.231.138.100 56990 217.154.7.177 443
[13/Sep/2026:10:02:36 +0200] 178928655634.134864 8.231.138.100 56990 217.154.7.177 443
[13/Sep/2026:10:02:36 +0200] 178928655692.642568 8.231.138.100 56990 217.154.7.177 443
[13/Sep/2026:10:02:36 +0200] 17892865566.392978 8.231.138.100 56990 217.154.7.177 443
...
show less
Port Scan
Hacking
Brute-Force
Web App Attack
🇩🇪
bazter.pro
2026-09-13 07:51:00
(1 day ago)
Fail2Ban: plesk-bot-aggressive - 15 failures
Port Scan
Bad Web Bot
Web App Attack
Anonymous
2026-09-13 07:36:04
(1 day ago)
GET console | UA: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152. ...
show more
GET console | UA: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36 | Time: 2026-09-13 07:36:03 UTC
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-13 07:15:47
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 8.231.138.100 (100.138.231.8.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 8.231.138.100 (100.138.231.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 03:15:42.061955 2026] [security2:error] [pid 27808:tid 27808] [client 8.231.138.100:49364] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ablogisticsgroup.com"] [uri "/.git/config"] [unique_id "aqZNnr8NjQAKh-z6vJ22bwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇮🇳
evicky2002
2026-09-13 06:00:01
(1 day ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
🇺🇸
LotPhantom
2026-09-13 03:49:49
(1 day ago)
2026-09-13T03:49:48.525821+00:00 bridginggaps kernel: [UFW BLOCK] IN=eth0 OUT= MAC=2e:bc:64:1d:2c:e1 ...
show more
2026-09-13T03:49:48.525821+00:00 bridginggaps kernel: [UFW BLOCK] IN=eth0 OUT= MAC=2e:bc:64:1d:2c:e1:fe:00:00:00:01:01:08:00 SRC=8.231.138.100 DST=157.230.217.55 LEN=60 TOS=0x00 PREC=0x00 TTL=57 ID=52465 DF PROTO=TCP SPT=33520 DPT=8443 WINDOW=65320 RES=0x00 SYN URGP=0
2026-09-13T03:49:48.526870+00:00 bridginggaps kernel: [UFW BLOCK] IN=eth0 OUT= MAC=2e:bc:64:1d:2c:e1:fe:00:00:00:01:01:08:00 SRC=8.231.138.100 DST=157.230.217.55 LEN=60 TOS=0x00 PREC=0x00 TTL=57 ID=21837 DF PROTO=TCP SPT=56646 DPT=8080 WINDOW=65320 RES=0x00 SYN URGP=0
...
show less
Port Scan
Hacking