🇳🇱
homeshowdomain.nl
2026-08-29 22:00:36
(2 hours ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-08-28.
show less
Web App Attack
SSH
Hacking
🇺🇸
TPI-Abuse
2026-08-29 03:34:00
(21 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.196.175.107 (107.175.196.104.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 104.196.175.107 (107.175.196.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 23:33:57.119173 2026] [security2:error] [pid 17057:tid 17057] [client 104.196.175.107:55952] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "test.marisetravel.com"] [uri "/.env"] [unique_id "apJTJYjTP3WACXTjm__F6gAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇨🇭
Ribeye375
2026-08-29 02:27:31
(22 hours ago)
HIPS recon-attempt - Block tcp/0:65535
Web App Attack
🇳🇱
debestelapp
2026-08-29 01:50:09
(23 hours ago)
Web App Attack
🇨🇦
polycoda
2026-08-29 01:07:03
(23 hours ago)
AutoBlock: 🎯 Vulnerability Scanner (Non Decay-Based) - ↪️ Excessive 30X Errors (Decay-Based)
Hacking
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-29 00:28:47
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 104.196.175.107 (107.175.196.104.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 104.196.175.107 (107.175.196.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 20:28:39.065884 2026] [security2:error] [pid 5135:tid 5135] [client 104.196.175.107:38474] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.n4fh.cosentient.com"] [uri "/.env.backup"] [unique_id "apInt1uZHk2O6fnAlcVySQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-28 22:02:33
(1 day ago)
(mod_security) mod_security triggered on hostname [redacted])
SQL Injection
🇫🇷
dwmp
2026-08-28 22:00:05
(1 day ago)
Url probing: /wp-config.php.swp
Web App Attack
Anonymous
2026-08-28 21:50:47
(1 day ago)
104.196.175.107 - - [28/Aug/2026:23:50:37 +0200] "GET /wp-config.php.swp HTTP/1.1" 403 146 "-" "crus ...
show more
104.196.175.107 - - [28/Aug/2026:23:50:37 +0200] "GET /wp-config.php.swp HTTP/1.1" 403 146 "-" "crusader-worker/1.0"
...
show less
Web App Attack
🇷🇴
iulianh
2026-08-28 21:28:04
(1 day ago)
80,443
Brute-Force
SSH
🇺🇸
TPI-Abuse
2026-08-28 21:11:21
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 104.196.175.107 (107.175.196.104.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 104.196.175.107 (107.175.196.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 17:11:13.871568 2026] [security2:error] [pid 21694:tid 21694] [client 104.196.175.107:55940] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ruralroutes.ca"] [uri "/.env.example"] [unique_id "apH5cedqjYvvnvfCpw3hzAAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-28 20:40:22
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 104.196.175.107 (107.175.196.104.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 104.196.175.107 (107.175.196.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 16:40:10.718618 2026] [security2:error] [pid 15757:tid 15757] [client 104.196.175.107:36420] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.katisfaction.dannyvanrijswijk.com"] [uri "/wp-config.php.bak"] [unique_id "apHyKhS7q9uFv7t7oTK7vwAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-28 19:30:45
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 104.196.175.107 (107.175.196.104.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 104.196.175.107 (107.175.196.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 15:30:39.533630 2026] [security2:error] [pid 18898:tid 18898] [client 104.196.175.107:36528] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.documents.progressivefileshare.org"] [uri "/.env.old"] [unique_id "apHh31_6Yv9YDOh1SK9QKQAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-28 19:09:46
(1 day ago)
Apache vulnerability scan
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-08-28 19:01:20
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 104.196.175.107 (107.175.196.104.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 104.196.175.107 (107.175.196.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 15:01:17.680494 2026] [security2:error] [pid 4578:tid 4578] [client 104.196.175.107:59224] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "arabou.co"] [uri "/.env.old"] [unique_id "apHa_di1nO4bwkCGlBES0wAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack