π«π·
chengkev
2026-09-15 03:17:40
(1 week ago)
Esta IP fue detectada por CrowdSec, activando crowdsecurity/http-sensitive-files
Web App Attack
Hacking
π©πͺ
webanyone
2026-08-25 00:17:37
(4 weeks ago)
Repeated 404 errors, blocked by Fail2ban in custom-404 jail
Bad Web Bot
π«π·
Baking333
2026-08-19 13:49:03
(1 month ago)
[redacted] 172.68.15.146 - - [19/Aug/2026:14:48:40 +0100] "GET /.[redacted] HTTP/2.0" 301 187 "-" "M ...
show more
[redacted] 172.68.15.146 - - [19/Aug/2026:14:48:40 +0100] "GET /.[redacted] HTTP/2.0" 301 187 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; +claudebot@[redacted])" [redacted] 172.68.15.146 - - [19/Aug/2026:14:48:49 +0100] "GET /backend/.aws/credentials HTTP/2.0" 301 89 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; +claudebot@[redacted])"
show less
Bad Web Bot
Web App Attack
π§πͺ
madeit
2026-08-18 13:48:48
(1 month ago)
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-17 14:07:48
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.68.15.146 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.15.146 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 10:07:41.746234 2026] [security2:error] [pid 1714:tid 1714] [client 172.68.15.146:11958] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.pages4you.com"] [uri "/.git/HEAD"] [unique_id "aoMVrfThuta-sNSI1nu2HQAAAB8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-17 11:43:37
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.68.15.146 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.15.146 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 07:43:34.094421 2026] [security2:error] [pid 17733:tid 17733] [client 172.68.15.146:13928] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.bodiehistory.com"] [uri "/.git/HEAD"] [unique_id "aoLz5vUytF_bhUdGNJRZ2wAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π§πͺ
madeit
2026-08-07 08:53:23
(1 month ago)
Web App Attack
Anonymous
2026-06-23 06:37:01
(2 months ago)
LH-Watcher: FAKE_ID [Fake Bingbot]
Bad Web Bot
Anonymous
2026-06-20 00:15:24
(3 months ago)
LH-Watcher: FAKE_ID [Fake Bingbot]
Bad Web Bot
π³π±
homeshowdomain.nl
2026-05-14 22:06:15
(4 months ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-05-13.
show less
Web App Attack
SSH
Hacking
πΊπΈ
TPI-Abuse
2026-04-22 04:19:07
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 172.68.15.146 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.15.146 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 22 00:18:57.499151 2026] [security2:error] [pid 22239:tid 22239] [client 172.68.15.146:10894] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.hillsboroughcountyresident.com.alanmariotti.com"] [uri "/.env.save"] [unique_id "aehMMRVt98jZQg0rH4hRSAAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
mnsf
2026-04-05 21:05:35
(5 months ago)
Too many Status 40X (12)
Scanning/Probing (12)
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2026-03-31 00:00:47
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 172.68.15.146 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.15.146 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Mar 30 20:00:39.480162 2026] [security2:error] [pid 387605:tid 387605] [client 172.68.15.146:13177] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.fatparrots.org"] [uri "/.env2"] [unique_id "acsOp1Un3HqxSRZFXe5pOAAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-03-30 13:36:22
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 172.68.15.146 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.15.146 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Mar 30 09:36:14.354255 2026] [security2:error] [pid 14396:tid 14396] [client 172.68.15.146:9288] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.lockyers.com"] [uri "/.env.tmp"] [unique_id "acp8TmslyWmf_UwqZA6m7gAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-03-30 08:46:00
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 172.68.15.146 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.15.146 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Mar 30 04:45:52.261396 2026] [security2:error] [pid 3575:tid 3575] [client 172.68.15.146:12781] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.afscmelocal2794.com"] [uri "/.env.php"] [unique_id "aco4QEk5l4sIpnT5Mvc6xwAAACM"]
show less
Brute-Force
Bad Web Bot
Web App Attack