๐ณ๐ฑ
homeshowdomain.nl
2026-09-26 22:01:03
(1 week ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-09-25.
show less
Web App Attack
SSH
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-25 11:52:02
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 2001:8d8:5ff:5f:82:165:80:178 (infong1195.clien ...
show more
(mod_security) mod_security (id:210492) triggered by 2001:8d8:5ff:5f:82:165:80:178 (infong1195.clienthosting.eu): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 25 07:51:57.847077 2026] [security2:error] [pid 20101:tid 20101] [client 2001:8d8:5ff:5f:82:165:80:178:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "earscript.net"] [uri "/.env"] [unique_id "arZgXTN8zyAD34iAJBWk1gAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-25 10:33:43
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 2001:8d8:5ff:5f:82:165:80:178 (infong1195.clien ...
show more
(mod_security) mod_security (id:210492) triggered by 2001:8d8:5ff:5f:82:165:80:178 (infong1195.clienthosting.eu): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 25 06:33:36.333662 2026] [security2:error] [pid 24364:tid 24364] [client 2001:8d8:5ff:5f:82:165:80:178:59818] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "dennisconnellyphotography.com"] [uri "/.env"] [unique_id "arZOAKdZ3AlW3YvBWMJmpwAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-25 06:30:27
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 2001:8d8:5ff:5f:82:165:80:178 (infong1195.clien ...
show more
(mod_security) mod_security (id:210492) triggered by 2001:8d8:5ff:5f:82:165:80:178 (infong1195.clienthosting.eu): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 25 02:30:19.568392 2026] [security2:error] [pid 23569:tid 23569] [client 2001:8d8:5ff:5f:82:165:80:178:58976] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "elimer.com.ve"] [uri "/.env"] [unique_id "arYU-_vm_9xwcpd1qWst9AAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
YF
2026-09-25 05:30:39
(1 week ago)
Environment file probe
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 22:46:21
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 2001:8d8:5ff:5f:82:165:80:178 (infong1195.clien ...
show more
(mod_security) mod_security (id:210492) triggered by 2001:8d8:5ff:5f:82:165:80:178 (infong1195.clienthosting.eu): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 18:46:17.218293 2026] [security2:error] [pid 16534:tid 16750] [client 2001:8d8:5ff:5f:82:165:80:178:47498] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mastersofthesecrets.com"] [uri "/wp-config.php.bak"] [unique_id "arMFOU4D9BfKmCVpJATvTAAAAlc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 20:56:54
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 2001:8d8:5ff:5f:82:165:80:178 (infong1195.clien ...
show more
(mod_security) mod_security (id:210492) triggered by 2001:8d8:5ff:5f:82:165:80:178 (infong1195.clienthosting.eu): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 16:56:47.578991 2026] [security2:error] [pid 6109:tid 6109] [client 2001:8d8:5ff:5f:82:165:80:178:50548] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "creartest.com"] [uri "/wp-config.php.bak"] [unique_id "arLrj6ymCbnrvY14agLtagAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 18:58:38
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 2001:8d8:5ff:5f:82:165:80:178 (infong1195.clien ...
show more
(mod_security) mod_security (id:210492) triggered by 2001:8d8:5ff:5f:82:165:80:178 (infong1195.clienthosting.eu): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 14:58:31.071029 2026] [security2:error] [pid 25753:tid 25753] [client 2001:8d8:5ff:5f:82:165:80:178:58394] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "albertmassaad.com"] [uri "/wp-config.php.bak"] [unique_id "arLP1wnZpyORwR9YY8UBcQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-22 16:46:08
(2 weeks ago)
2001:8d8:5ff:5f:82:165:80:178 - - [23/Sep/2026:00:46:07 +0800] "GET /wp-config.php.bak HTTP/1.1" 404 ...
show more
2001:8d8:5ff:5f:82:165:80:178 - - [23/Sep/2026:00:46:07 +0800] "GET /wp-config.php.bak HTTP/1.1" 404 196 "-" "-"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 16:37:54
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 2001:8d8:5ff:5f:82:165:80:178 (infong1195.clien ...
show more
(mod_security) mod_security (id:210492) triggered by 2001:8d8:5ff:5f:82:165:80:178 (infong1195.clienthosting.eu): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 12:37:47.878951 2026] [security2:error] [pid 12754:tid 12754] [client 2001:8d8:5ff:5f:82:165:80:178:35916] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "stukabird.com"] [uri "/wp-config.php.bak"] [unique_id "arKu21GeVstMcAAjOJE-DgAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 16:10:46
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 2001:8d8:5ff:5f:82:165:80:178 (infong1195.clien ...
show more
(mod_security) mod_security (id:210492) triggered by 2001:8d8:5ff:5f:82:165:80:178 (infong1195.clienthosting.eu): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 12:10:42.748611 2026] [security2:error] [pid 18847:tid 19164] [client 2001:8d8:5ff:5f:82:165:80:178:48724] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "killyourattitude.com"] [uri "/wp-config.php.bak"] [unique_id "arKogq_mHM7BdlFcSacsHwAAAJA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 12:16:31
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 2001:8d8:5ff:5f:82:165:80:178 (infong1195.clien ...
show more
(mod_security) mod_security (id:210492) triggered by 2001:8d8:5ff:5f:82:165:80:178 (infong1195.clienthosting.eu): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 08:16:26.300096 2026] [security2:error] [pid 13716:tid 13740] [client 2001:8d8:5ff:5f:82:165:80:178:50264] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "rbarw.com"] [uri "/wp-config.php.bak"] [unique_id "arJxmqJdpEbRpM-GHp_4OgAAAQc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 11:57:35
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 2001:8d8:5ff:5f:82:165:80:178 (infong1195.clien ...
show more
(mod_security) mod_security (id:210492) triggered by 2001:8d8:5ff:5f:82:165:80:178 (infong1195.clienthosting.eu): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 07:57:31.838345 2026] [security2:error] [pid 7017:tid 7017] [client 2001:8d8:5ff:5f:82:165:80:178:50658] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kaneprotectivecoatings.com"] [uri "/wp-config.php.bak"] [unique_id "arJtK6fOJ7aCFsD5HqEGyQAAAFM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 11:40:37
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 2001:8d8:5ff:5f:82:165:80:178 (infong1195.clien ...
show more
(mod_security) mod_security (id:210492) triggered by 2001:8d8:5ff:5f:82:165:80:178 (infong1195.clienthosting.eu): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 07:40:30.737042 2026] [security2:error] [pid 17857:tid 17857] [client 2001:8d8:5ff:5f:82:165:80:178:46334] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bsa1688.com"] [uri "/wp-config.php.bak"] [unique_id "arJpLi-Nzrb3ylmZmzAligAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 08:57:20
(2 weeks ago)
(mod_security) mod_security (id:949110) triggered by 2001:8d8:5ff:5f:82:165:80:178 (infong1195.clien ...
show more
(mod_security) mod_security (id:949110) triggered by 2001:8d8:5ff:5f:82:165:80:178 (infong1195.clienthosting.eu): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 04:57:15.226786 2026] [security2:error] [pid 13806:tid 13806] [client 2001:8d8:5ff:5f:82:165:80:178:56880] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "faithfoundationenterprise.com"] [uri "/wp-config.php.bak"] [unique_id "arJC636ErSqUXGxHXjghJgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack