🇳🇱
WeCloudit-Anti-Abuse
2026-09-13 04:42:22
(1 day ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
🇳🇱
homeshowdomain.nl
2026-09-10 21:59:48
(3 days ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-09-09.
show less
Web App Attack
SSH
Hacking
🇨🇳
Peter Yu
2026-09-10 04:15:20
(4 days ago)
Bad Web Bot
Web App Attack
🇨🇿
Prcek
2026-09-10 00:05:45
(4 days ago)
PortScan:HOST=206.189.156.212,DPORTS=443,1080,1082,3128
Port Scan
🇳🇱
homeshowdomain.nl
2026-09-09 22:02:02
(4 days ago)
Auto-ban: >3000 req/min op 2026-09-09
Web App Attack
SSH
Hacking
🇺🇸
TPI-Abuse
2026-09-09 12:32:26
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 206.189.156.212 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 206.189.156.212 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 08:32:20.621815 2026] [security2:error] [pid 5528:tid 5528] [client 206.189.156.212:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "whiteblackbird.com"] [uri "/.env.dist"] [unique_id "aqFR1FM8zC8CxLGWW9m6nAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-09 11:11:13
(5 days ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 07:16:47
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 206.189.156.212 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 206.189.156.212 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 03:16:34.838382 2026] [security2:error] [pid 8430:tid 8430] [client 206.189.156.212:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mitchellamazing.com"] [uri "/.env.production"] [unique_id "aqEH0mvNSpRdQNQ0D91nCQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 05:33:33
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 206.189.156.212 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 206.189.156.212 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 01:33:28.115667 2026] [security2:error] [pid 8585:tid 8585] [client 206.189.156.212:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "herrell.net"] [uri "/.env.test"] [unique_id "aqDvqNiXw7BYflBa8rod0QAAAAA"], referer: https://www.google.com/search?q=herrell.net
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 04:12:16
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 206.189.156.212 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 206.189.156.212 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 00:11:58.840317 2026] [security2:error] [pid 14887:tid 14900] [client 206.189.156.212:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "farmerlabor.org"] [uri "/.env.production"] [unique_id "aqDcjopnrR67CalsbTOcngAAAQk"], referer: https://www.google.com/search?q=farmerlabor.org
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 01:49:36
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 206.189.156.212 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 206.189.156.212 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 21:49:32.487107 2026] [security2:error] [pid 11913:tid 11913] [client 206.189.156.212:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bakerimaging.com"] [uri "/.git/HEAD"] [unique_id "aqC7LM0ZE6ZnLy458qAg2wAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
FeG Deutschland
2026-09-08 11:41:04
(6 days ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
Anonymous
2020-12-24 06:37:29
(5 years ago)
port scan and connect, tcp 8443 (https-alt)
Port Scan