๐ณ๐ฑ
homeshowdomain.nl
2026-06-08 22:00:37
(1 week ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-06-07.
show less
Web App Attack
SSH
Hacking
๐ณ๐ฑ
e.fierstra
2026-06-08 09:02:41
(1 week ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
Anonymous
2026-06-08 09:02:36
(1 week ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2026-06-08 08:53:40
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 145.79.211.14 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 145.79.211.14 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 08 04:53:35.159042 2026] [security2:error] [pid 12539:tid 12539] [client 145.79.211.14:47064] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sexycyborg.net"] [uri "/backend/.env"] [unique_id "aiaDDyeXLdk9agB76DVj9AAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-08 07:50:06
(1 week ago)
Web App Attack, Hacking
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-08 07:44:13
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 145.79.211.14 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 145.79.211.14 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 08 03:44:10.140136 2026] [security2:error] [pid 9742:tid 9742] [client 145.79.211.14:45974] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "perlcreative.com"] [uri "/api/.env"] [unique_id "aiZyykmKSuHuNe0upf6U_wAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-08 06:25:05
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 145.79.211.14 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 145.79.211.14 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 08 02:24:57.319351 2026] [security2:error] [pid 23628:tid 23628] [client 145.79.211.14:27912] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "nematoads.com"] [uri "/app/.env"] [unique_id "aiZgOTVrWZvFZdK70PXykAAAAE8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-06-08 05:03:23
(1 week ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 127
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-08 04:12:47
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 145.79.211.14 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 145.79.211.14 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 08 00:12:40.666015 2026] [security2:error] [pid 31623:tid 31623] [client 145.79.211.14:43202] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "technology-connection.net"] [uri "/.env"] [unique_id "aiZBOFWo87wHT1sNpaAXzQAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
paulshipley.com.au
2026-06-08 04:11:42
(1 week ago)
[Mon Jun 08 14:11:41.391446 2026] [security2:error] [pid 68175] [client 145.79.211.14:29288] [client ...
show more
[Mon Jun 08 14:11:41.391446 2026] [security2:error] [pid 68175] [client 145.79.211.14:29288] [client 145.79.211.14] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/modsecurity/crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "shotbysuzanne.com.au"] [uri "/core/.env"] [unique_id "aiZA_adrl2aSPHKex2mv6QAAADA"]
...
show less
Web App Attack
๐ป๐ณ
trung.fun
2026-06-08 03:43:56
(1 week ago)
DDoS, Hack, Brute Force, Web Attack
...
DDoS Attack
Web Spam
Hacking
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-08 03:40:33
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 145.79.211.14 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 145.79.211.14 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 07 23:40:26.932332 2026] [security2:error] [pid 23306:tid 23306] [client 145.79.211.14:54804] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kindbyamber.com"] [uri "/backend/.env"] [unique_id "aiY5qiaM8ZCBhyKL9ROG-gAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-08 03:18:39
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 145.79.211.14 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 145.79.211.14 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 07 23:18:33.535222 2026] [security2:error] [pid 21866:tid 21866] [client 145.79.211.14:52138] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mldlnn.com"] [uri "/members/.env"] [unique_id "aiY0iVM1jo4MS4ehlmPiSQAAACo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-08 02:40:51
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 145.79.211.14 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 145.79.211.14 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 07 22:40:46.618204 2026] [security2:error] [pid 19221:tid 19221] [client 145.79.211.14:26060] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "soudertonbigred.org"] [uri "/dev/.env"] [unique_id "aiYrrq5f4ME3_wD25DvDSAAAAFs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
screwlooseit.com.au
2026-06-08 02:06:14
(1 week ago)
Blocked by CSF 13 firewall - Rule: config-dotfile
NL/Netherlands/-
Web App Attack