๐ฎ๐น
CoreTech srl
2026-08-01 23:59:00
(1 week ago)
cloudlinux2 fail2ban: 2026-08-02 01:54:36,878 fail2ban.filter [1838]: INFO [plesk-wordpre ...
show more
cloudlinux2 fail2ban: 2026-08-02 01:54:36,878 fail2ban.filter [1838]: INFO [plesk-wordpress] Found 45.131.194.219 - 2026-08-02 01:54:35cloudlinux2 fail2ban: 2026-08-02 01:54:36,142 fail2ban.filter [1838]: INFO [plesk-wordpress] Found 45.131.194.224 - 2026-08-02 01:54:35cloudlinux2 fail2ban: 2026-08-02 01:54:42,954 fail2ban.actions [1838]: NOTICE [plesk-modsecurity] Ban 174.95.181.144cloudlinux2 fail2ban: 2026-08-02 01:54:42,961 fail2ban.filter [1838]: INFO [recidive] Found 174.95.181.144 - 2026-08-02 01:54:42cloudlinux2 fail2ban: 2026-08-02 01:54:42,798 fail2ban.filter [1838]: INFO [plesk-modsecurity] Found 174.95.181.144 - 2026-08-02 01:54:42cloudlinux2 fail2ban: 2026-08-02 01:55:09,878 fail2ban.filter [1838]: INFO [plesk-wordpress] Found 173.239.218.19 - 2026-08-02 01:55:09cloudlinux2 fail2ban: 2026-08-02 01:58:00,186 fail2ban.filter [1838]: INFO [plesk-wordpress] Found 65.98.12.23 - 2026-08-02 01:57:59cloudlinux2 fail2ban: 2026-08-02
show less
Web App Attack
๐ซ๐ท
masterguru
2026-07-24 00:23:33
(3 weeks ago)
Restricted File Access Attempt. Matched phrase ".env" at REQUEST_FILENAME. (930130-201)
Hacking
Web App Attack
๐ฉ๐ช
Vegascosmetics
2026-07-23 23:51:57
(3 weeks ago)
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after sensitive config/credentials exposure ...
show more
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after sensitive config/credentials exposure probe. Evidence: AttackPattern: /\.env (Match: /.env)
show less
Hacking
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-23 12:47:38
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 45.131.194.219 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 45.131.194.219 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 23 08:47:31.111263 2026] [security2:error] [pid 2807360:tid 2807360] [client 45.131.194.219:58941] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "form-a-tool.com"] [uri "/.env"] [unique_id "amINYyttKRJP-5gBvmB4pgAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
BlueWire Hosting
2026-07-23 12:19:53
(3 weeks ago)
Probing websites for vulnerabilities
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-23 08:48:45
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 45.131.194.219 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 45.131.194.219 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 23 04:48:39.235517 2026] [security2:error] [pid 2093644:tid 2093695] [client 45.131.194.219:44403] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "saltflowlogistics.com"] [uri "/.env"] [unique_id "amHVZ4WXk39PYY9khDb7mAAAARQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-23 05:53:13
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 45.131.194.219 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 45.131.194.219 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 23 01:53:08.548124 2026] [security2:error] [pid 208255:tid 208255] [client 45.131.194.219:62091] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "al-bukhari.org"] [uri "/.env"] [unique_id "amGsROOiGkDd1BudxbfwRAAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-23 05:30:17
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 45.131.194.219 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 45.131.194.219 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 23 01:30:13.375209 2026] [security2:error] [pid 2127129:tid 2127129] [client 45.131.194.219:23743] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cloggersunlimited.com"] [uri "/.env"] [unique_id "amGm5UarP8bwq980S5VJbQAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-23 04:29:12
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 45.131.194.219 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 45.131.194.219 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 23 00:29:08.299400 2026] [security2:error] [pid 1723345:tid 1723345] [client 45.131.194.219:26181] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "footshufflerz.com"] [uri "/.env"] [unique_id "amGYlALIZxys32Q7zh6bXAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-23 03:04:28
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 45.131.194.219 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 45.131.194.219 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 22 23:04:23.531635 2026] [security2:error] [pid 2102005:tid 2102005] [client 45.131.194.219:55199] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kevinfranz.com"] [uri "/.env"] [unique_id "amGEt9I9g41Q96ZprwB8jwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
YF
2026-07-23 02:30:32
(3 weeks ago)
Distributed subnet attack โ coordinated scanning from multiple IPs in the same /24
DDoS Attack
Web App Attack
๐ฉ๐ช
Bedios GmbH
2026-07-23 00:50:46
(3 weeks ago)
Login credentials theft attempt
Hacking
๐บ๐ธ
TPI-Abuse
2026-07-22 21:05:04
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 45.131.194.219 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 45.131.194.219 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 22 17:04:57.486602 2026] [security2:error] [pid 2131918:tid 2131918] [client 45.131.194.219:62903] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "editions.click"] [uri "/.env"] [unique_id "amEweaMRCJndTRFZnnYyEQAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
pltcldvlpr
2026-07-22 20:41:57
(3 weeks ago)
CMS/framework probe: 45.131.194.219 - - [22/Jul/2026:22:41:56 +0200] "GET /.env HTTP/1.1" 404 10591 ...
show more
CMS/framework probe: 45.131.194.219 - - [22/Jul/2026:22:41:56 +0200] "GET /.env HTTP/1.1" 404 10591 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:77.0) Gecko/20100101 Firefox/77.0" asn=206092 org="F.N.S. HOLDINGS LIMITED" country=US
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-22 19:15:55
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 45.131.194.219 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 45.131.194.219 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 22 15:15:48.170993 2026] [security2:error] [pid 1249521:tid 1249521] [client 45.131.194.219:50923] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ati.software"] [uri "/.env"] [unique_id "amEW5B1mEvloAAJgRuXRAwAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack