๐ซ๐ท
bigorre.org
2026-08-05 16:53:27
(1 month ago)
Forbidden access for mozilla/5.0 (compatible; googlebot/2.1; +http://www.google.com/bot.html)
Bad Web Bot
Anonymous
2026-07-20 13:31:38
(2 months ago)
Fake Googlebot crawler detected. The IP used the Googlebot user-agent but does not belong to Google' ...
show more
Fake Googlebot crawler detected. The IP used the Googlebot user-agent but does not belong to Google's verified crawler IP ranges.
show less
Bad Web Bot
๐ณ๐ฑ
homeshowdomain.nl
2026-05-28 22:03:58
(3 months ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-05-27.
show less
Web App Attack
SSH
Hacking
๐ณ๐ฑ
homeshowdomain.nl
2026-05-27 22:00:42
(3 months ago)
Auto-ban: >3000 req/min op 2026-05-27
Web App Attack
SSH
Hacking
๐บ๐ธ
TPI-Abuse
2026-05-27 17:50:54
(3 months ago)
(mod_security) mod_security (id:949110) triggered by 198.23.214.219 (198-23-214-219-host.colocrossin ...
show more
(mod_security) mod_security (id:949110) triggered by 198.23.214.219 (198-23-214-219-host.colocrossing.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 27 13:50:44.476230 2026] [security2:error] [pid 3476:tid 3476] [client 198.23.214.219:43135] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "letahitibookings.com"] [uri "/wp-config.php.swp"] [unique_id "ahcu9Nf6UznHLYpfB4E4WwAAAAI"], referer: https://www.google.com/search?q=letahitibookings.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-27 00:57:59
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 198.23.214.219 (198-23-214-219-host.colocrossin ...
show more
(mod_security) mod_security (id:210492) triggered by 198.23.214.219 (198-23-214-219-host.colocrossing.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 26 20:57:42.558319 2026] [security2:error] [pid 17753:tid 17753] [client 198.23.214.219:54975] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "johnlittlehorn.com"] [uri "/.env.production"] [unique_id "ahZBhvClH07MWQthFKbe0AAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
4server
2026-05-27 00:57:34
(3 months ago)
[WedMay2702:57:27.7471602026][security2:error][pid366229:tid366431][client198.23.214.219:0]ModSecuri ...
show more
[WedMay2702:57:27.7471602026][security2:error][pid366229:tid366431][client198.23.214.219:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\".env\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"364\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"carolin-mizio.ch.81-17-25-250.cpanel.site\"][uri\"/.env.local\"][unique_id\"ahZBdw4gdtan8RdqNWI69gAAAJA\"]
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-27 00:33:36
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 198.23.214.219 (198-23-214-219-host.colocrossin ...
show more
(mod_security) mod_security (id:210492) triggered by 198.23.214.219 (198-23-214-219-host.colocrossing.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 26 20:33:06.023136 2026] [security2:error] [pid 15507:tid 15507] [client 198.23.214.219:51187] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "rdu.kmp.net"] [uri "/.env.bak"] [unique_id "ahY7wlFB6fpgMTBk1i65oQAAAC4"], referer: https://www.google.com/search?q=rdu.kmp.net
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-26 18:11:22
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 198.23.214.219 (198-23-214-219-host.colocrossin ...
show more
(mod_security) mod_security (id:210492) triggered by 198.23.214.219 (198-23-214-219-host.colocrossing.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 26 14:11:14.688569 2026] [security2:error] [pid 3912:tid 3912] [client 198.23.214.219:49995] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "dbfitwell.com"] [uri "/wp-config.php.save"] [unique_id "ahXiQtjz4H927gj593_JhgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-17 17:14:28
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 198.23.214.219 (198-23-214-219-host.colocrossin ...
show more
(mod_security) mod_security (id:210492) triggered by 198.23.214.219 (198-23-214-219-host.colocrossing.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jan 17 12:14:21.939412 2026] [security2:error] [pid 21613:tid 21613] [client 198.23.214.219:32849] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.nbcnewsradio.com"] [uri "/wp-content/plugins/site-editor/editor/extensions/pagebuilder/includes/ajax_shortcode_pattern.php"] [unique_id "aWvDbbJ2M6eNLNWQvohMowAAACE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-29 18:39:46
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 198.23.214.219 (198-23-214-219-host.colocrossin ...
show more
(mod_security) mod_security (id:210492) triggered by 198.23.214.219 (198-23-214-219-host.colocrossing.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Dec 29 13:39:35.360428 2025] [security2:error] [pid 22838:tid 22912] [client 198.23.214.219:53373] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.kettlehill.com"] [uri "/.env.live"] [unique_id "aVLK5-HXaA_hkms52yNsogAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-29 10:38:03
(9 months ago)
(mod_security) mod_security (id:211190) triggered by 198.23.214.219 (198-23-214-219-host.colocrossin ...
show more
(mod_security) mod_security (id:211190) triggered by 198.23.214.219 (198-23-214-219-host.colocrossing.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Nov 29 05:38:00.031571 2025] [security2:error] [pid 29620:tid 29750] [client 198.23.214.219:46047] ModSecurity: Access denied with code 403 (phase 2). Match of "contains cpanel" against "REQUEST_URI" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "55"] [id "211190"] [rev "9"] [msg "COMODO WAF: Remote File Access Attempt||mail.kettlehill.com|F|2"] [data "Matched Data: /etc/ found within REQUEST_URI: /cgi-bin/wapopen?B1=OK&NO=CAM_16&REFRESH_TIME=Auto_00&FILECAMERA=../../etc/passwd%00&REFRESH_HTML=auto.htm&ONLOAD_HTML=onload.htm&STREAMING_HTML=streaming.htm&NAME=admin&PWD=admin&PIC_SIZE=0"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.kettlehill.com"] [uri "/cgi-bin/wapopen"] [unique_id "aSrNCGvS3KDdkNmxDpWnOgAAAkA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-08-05 07:30:06
(1 year ago)
Backdrop CMS module - malicious activity detected
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-07-27 00:22:50
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 198.23.214.219 (198-23-214-219-host.colocrossin ...
show more
(mod_security) mod_security (id:210492) triggered by 198.23.214.219 (198-23-214-219-host.colocrossing.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 26 20:22:43.823946 2025] [security2:error] [pid 172499:tid 172616] [client 198.23.214.219:60351] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ftp.kettlehill.net"] [uri "/.env.production"] [unique_id "aIVxU4En7YGnahfIo_jKlAAAAUo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-07-08 11:50:54
(1 year ago)
Malicious activity detected
Hacking
Brute-Force