πΊπΈ
mnsf
2026-02-16 01:05:30
(4 months ago)
Scanning/Probing (25)
Brute-Force
Web App Attack
π³π±
homeshowdomain.nl
2026-02-15 22:59:28
(4 months ago)
Auto-ban: >3000 req/min op 2026-02-15
Hacking
Web App Attack
SSH
π¬π§
consul.to
2026-02-15 12:49:11
(4 months ago)
Web attack/malicious scanning detected
Web App Attack
π©πͺ
big-cloud.nl
2026-02-15 12:31:04
(4 months ago)
Try to access /api/.env
Web App Attack
π©πͺ
BlueWire Hosting
2026-02-15 12:21:30
(4 months ago)
Probing websites for vulnerabilities
SQL Injection
Web App Attack
πΊπΈ
TPI-Abuse
2026-02-15 06:47:15
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.55.181 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.55.181 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Feb 15 01:47:08.953167 2026] [security2:error] [pid 23978:tid 23978] [client 104.207.55.181:15673] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "talentguard.net"] [uri "/frontend/.env"] [unique_id "aZFr7DzqGnchsl__YGac5AAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π¦πΊ
2000cn.com.au
2026-02-15 05:25:55
(4 months ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Hacking
Web App Attack
πΊπΈ
TPI-Abuse
2026-02-15 04:30:48
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.55.181 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.55.181 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Feb 14 23:30:42.002747 2026] [security2:error] [pid 1321157:tid 1321157] [client 104.207.55.181:46961] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "stuartpearson.net"] [uri "/wp/.git/config"] [unique_id "aZFL8loPi2sYMP-k0Xi9vwAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-02-15 01:44:33
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.55.181 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.55.181 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Feb 14 20:44:25.999540 2026] [security2:error] [pid 25065:tid 25065] [client 104.207.55.181:63273] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "myaiphoneagent.com"] [uri "/.env"] [unique_id "aZEk-W89sd6oFlUVHZTONgAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
DocNetzwerk
2026-02-15 00:32:13
(4 months ago)
(mod_security) mod_security triggered on hostname [redacted] 104.207.55.181 (DE/Germany/-)
SQL Injection
πΊπΈ
mnsf
2026-02-15 00:05:48
(4 months ago)
Too many Status 40X (12)
Scanning/Probing (12)
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2026-02-14 23:19:04
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.55.181 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.55.181 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Feb 14 18:18:57.598375 2026] [security2:error] [pid 2169:tid 2269] [client 104.207.55.181:18129] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "livetalkusa.com"] [uri "/.env.local"] [unique_id "aZEC4XCmiqKc9qeqCdLOVwAAAJM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
myagent.site
2026-02-14 22:29:52
(4 months ago)
Blocking for trying to access an exploit file: /.env
Hacking
πΊπΈ
TPI-Abuse
2026-02-14 21:28:45
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.55.181 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.55.181 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Feb 14 16:28:40.155331 2026] [security2:error] [pid 23985:tid 23985] [client 104.207.55.181:38143] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "legalnexusbali.com"] [uri "/.env.staging"] [unique_id "aZDpCEjNO70fb0BwqsvI7QAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-12-10 14:52:11
(6 months ago)
"Participant in large-scale DDoS Attack in which data injection was attmpted to gain unauthorized ac ...
show more
"Participant in large-scale DDoS Attack in which data injection was attmpted to gain unauthorized access"
show less
DDoS Attack
SQL Injection
Exploited Host