๐ช๐ธ
Gem
2026-07-31 22:23:53
(29 minutes ago)
Unauthorized web scan.
Web App Attack
๐จ๐ญ
lufi
2026-07-31 21:39:52
(1 hour ago)
2026-07-31T23:39:52+02:00 lufischer04 ids442 2026-07-31 23:39:52 94.237.4.51: blacklisted Pattern: / ...
show more
2026-07-31T23:39:52+02:00 lufischer04 ids442 2026-07-31 23:39:52 94.237.4.51: blacklisted Pattern: /.env.local
...
show less
Web Spam
Brute-Force
Hacking
Web App Attack
๐ฉ๐ช
Jochen Pretli
2026-07-31 21:32:39
(1 hour ago)
connection to honeypot
Email Spam
Port Scan
๐จ๐ญ
4server
2026-07-31 21:22:52
(1 hour ago)
[FriJul3123:22:49.1469902026][security2:error][pid525583:tid525895][client94.237.4.51:0]ModSecurity: ...
show more
[FriJul3123:22:49.1469902026][security2:error][pid525583:tid525895][client94.237.4.51:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\"wp-config\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"365\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"4-server.com\"][uri\"/wp-config.php.old\"][unique_id\"am0SKWVcRjvemn5D85PhbAAAAQc\"]
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-31 21:17:10
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 94.237.4.51 (94-237-4-51.nl-ams1.upcloud.host): ...
show more
(mod_security) mod_security (id:210492) triggered by 94.237.4.51 (94-237-4-51.nl-ams1.upcloud.host): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 31 17:17:06.200872 2026] [security2:error] [pid 3421:tid 3427] [client 94.237.4.51:42138] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "3stepreviewforyou.com"] [uri "/.env.v1"] [unique_id "am0Q0mX7dY2KKjrHargP_QAAAEQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
poundawebsiteltd
2026-07-31 21:09:46
(1 hour ago)
Malicious activity in general-malicious. Evidence: (apache_probe) Failed Access (403/404) 94.237.4.5 ...
show more
Malicious activity in general-malicious. Evidence: (apache_probe) Failed Access (403/404) 94.237.4.51 (NL/The Netherlands/[REDACTED_DOMAIN]): 20 in the last 3600 secs | UA: (apache_probe) Failed Access (403/404) 94.237.4.51 (NL/The Netherlands/94-237-4-51.nl-ams1.upcloud.host): 20 in the last 3600 secs
show less
Brute-Force
Web App Attack
๐บ๐ธ
Matthew Ping
2026-07-31 21:00:01
(1 hour ago)
Excessive connections (DDoS/flood) blocked by CSF CT_LIMIT on wp1.
DDoS Attack
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-07-31 20:51:33
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 94.237.4.51 (94-237-4-51.nl-ams1.upcloud.host): ...
show more
(mod_security) mod_security (id:210492) triggered by 94.237.4.51 (94-237-4-51.nl-ams1.upcloud.host): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 31 16:51:28.715024 2026] [security2:error] [pid 3165245:tid 3165245] [client 94.237.4.51:58188] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "3dcounty.com"] [uri "/stage/.env"] [unique_id "am0K0B0O4XVe03bc-M52vwAAAFs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-31 20:25:34
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 94.237.4.51 (94-237-4-51.nl-ams1.upcloud.host): ...
show more
(mod_security) mod_security (id:210492) triggered by 94.237.4.51 (94-237-4-51.nl-ams1.upcloud.host): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 31 16:25:27.632736 2026] [security2:error] [pid 3216947:tid 3216947] [client 94.237.4.51:37012] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "365m4.com"] [uri "/%00wp-config.php.swp"] [unique_id "am0EtxGh-7ZYlmPbolWJJAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
MatCat
2026-07-31 20:05:02
(2 hours ago)
Banned by fail2ban: apache-webprobe
Port Scan
Bad Web Bot
๐ฉ๐ช
Ba-Yu
2026-07-31 20:00:33
(2 hours ago)
General hacking/exploits/scanning
Web Spam
Hacking
Brute-Force
Exploited Host
Web App Attack
๐ซ๐ท
masterguru
2026-07-31 19:49:20
(3 hours ago)
BAD BOT - Detected and Blocked.. Matched phrase "mozlila" at REQUEST_HEADERS:User-Agent. (1100000-20 ...
show more
BAD BOT - Detected and Blocked.. Matched phrase "mozlila" at REQUEST_HEADERS:User-Agent. (1100000-201)
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-07-31 19:42:04
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 94.237.4.51 (94-237-4-51.nl-ams1.upcloud.host): ...
show more
(mod_security) mod_security (id:210492) triggered by 94.237.4.51 (94-237-4-51.nl-ams1.upcloud.host): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 31 15:41:57.736189 2026] [security2:error] [pid 3462745:tid 3462745] [client 94.237.4.51:42806] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "30daysout.com"] [uri "/%00wp-config.php.save"] [unique_id "amz6hVCtrQ58Iu_qvgBQsAAAACw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ท๐บ
DZBOT
2026-07-31 19:36:28
(3 hours ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-31 19:24:35
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 94.237.4.51 (94-237-4-51.nl-ams1.upcloud.host): ...
show more
(mod_security) mod_security (id:210492) triggered by 94.237.4.51 (94-237-4-51.nl-ams1.upcloud.host): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 31 15:24:26.809113 2026] [security2:error] [pid 1138673:tid 1138673] [client 94.237.4.51:37292] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "2mpr.com"] [uri "/internal/.env"] [unique_id "amz2agVVYflDk7iMIdeaFAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack