๐ณ๐ฑ
homeshowdomain.nl
2026-09-01 22:00:56
(23 minutes ago)
Auto-ban: >3000 req/min op 2026-09-01
Web App Attack
SSH
Hacking
๐จ๐ญ
4server
2026-09-01 13:54:41
(8 hours ago)
[TueSep0115:54:35.7828802026][security2:error][pid3526681:tid3526812][client104.199.161.58:0]ModSecu ...
show more
[TueSep0115:54:35.7828802026][security2:error][pid3526681:tid3526812][client104.199.161.58:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\".env\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"610\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"cpcontacts.aidconsultancy.ch\"][uri\"/.env.bak\"][unique_id\"apbZGwSrbrkJKRkckcincgAAAMA\"]
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 13:51:26
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.199.161.58 (58.161.199.104.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 104.199.161.58 (58.161.199.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 09:51:18.052909 2026] [security2:error] [pid 7364:tid 7364] [client 104.199.161.58:56894] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.medics-group.com"] [uri "/.env.save"] [unique_id "apbYVgqI1UGCpVvSQzdIAgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 13:13:15
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.199.161.58 (58.161.199.104.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 104.199.161.58 (58.161.199.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 09:13:11.224270 2026] [security2:error] [pid 30422:tid 30422] [client 104.199.161.58:44532] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "layoverinamsterdam.thinkingepic.com"] [uri "/.env"] [unique_id "apbPZ6An85p2zJCa51zk1gAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ธ๐ช
SkyDancer
2026-09-01 13:10:29
(9 hours ago)
Multiple unauthorized attempts to access using wrong credentials. Attack automatically blocked by Sk ...
show more
Multiple unauthorized attempts to access using wrong credentials. Attack automatically blocked by SkyDancer Ai. EXT-SYS-Vx
show less
Hacking
Brute-Force
SSH
๐ฉ๐ช
mr.joecat
2026-09-01 13:05:36
(9 hours ago)
104.199.161.58 - - [01/Sep/2026:15:05:36 +0200] "GET /.env.backup HTTP/1.1" 404 4291 "-" "crusader-w ...
show more
104.199.161.58 - - [01/Sep/2026:15:05:36 +0200] "GET /.env.backup HTTP/1.1" 404 4291 "-" "crusader-worker/1.0"
104.199.161.58 - - [01/Sep/2026:15:05:36 +0200] "GET /wp-config.php.swp HTTP/1.1" 404 3403 "-" "crusader-worker/1.0"
104.199.161.58 - - [01/Sep/2026:15:05:36 +0200] "GET /.env HTTP/1.1" 404 4270 "-" "crusader-worker/1.0"
104.199.161.58 - - [01/Sep/2026:15:05:36 +0200] "GET /.env.example HTTP/1.1" 404 3329 "-" "crusader-worker/1.0"
104.199.161.58 - - [01/Sep/2026:15:05:36 +0200] "GET /.env.old HTTP/1.1" 404 3340 "-" "crusader-worker/1.0"
...
show less
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-09-01 13:04:37
(9 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐ฎ๐ฉ
Burayot
2026-09-01 12:35:17
(9 hours ago)
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 104.199.161.58 (TW/Taiwan/58.161.19 ...
show more
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 104.199.161.58 (TW/Taiwan/58.161.199.104.bc.googleusercontent.com): 1 in the last 3600 secs
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 11:10:35
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.199.161.58 (58.161.199.104.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 104.199.161.58 (58.161.199.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 07:10:30.803920 2026] [security2:error] [pid 2832:tid 2832] [client 104.199.161.58:53244] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.adultandchild.org"] [uri "/.env.old"] [unique_id "apaypuD6XRtycAW6Slla8wAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
thesimonmanuel
2026-09-01 08:53:45
(13 hours ago)
104.199.161.58 - - [01/Sep/2026:14:23:44 +0530] "GET /.env HTTP/1.1" 308 164 "-" "crusader-worker/1. ...
show more
104.199.161.58 - - [01/Sep/2026:14:23:44 +0530] "GET /.env HTTP/1.1" 308 164 "-" "crusader-worker/1.0" "-"
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 08:27:26
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.199.161.58 (58.161.199.104.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 104.199.161.58 (58.161.199.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 04:27:22.071224 2026] [security2:error] [pid 20084:tid 20124] [client 104.199.161.58:57960] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "maroontribe.com"] [uri "/.env.bak"] [unique_id "apaMaulg42CGBgLAd2Wn1QAAAMY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
Apache
2026-09-01 08:26:58
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.199.161.58 (TW/Taiwan/58.161.199.104.bc.goo ...
show more
(mod_security) mod_security (id:210492) triggered by 104.199.161.58 (TW/Taiwan/58.161.199.104.bc.googleusercontent.com): 5 in the last 300 secs (CF_ENABLE)
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 07:47:07
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.199.161.58 (58.161.199.104.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 104.199.161.58 (58.161.199.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 03:47:02.172837 2026] [security2:error] [pid 787:tid 787] [client 104.199.161.58:53196] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ftp.astrology7.com"] [uri "/.env.save"] [unique_id "apaC9j9r9aRNhfsrfLAngAAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-09-01 06:08:59
(16 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐ท๐บ
DZBOT
2026-09-01 05:28:22
(16 hours ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack