๐บ๐ธ
Matthew Ping
2026-08-01 17:30:03
(2 hours ago)
ModSecurity rule 949110 triggered on dedicated4785. Web application attack blocked by CSF/LFD.
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-08-01 16:33:49
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 207.175.176.160 (160.176.175.207.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 207.175.176.160 (160.176.175.207.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 12:33:43.752237 2026] [security2:error] [pid 135960:tid 135960] [client 207.175.176.160:50284] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "stage.dtla2028.com"] [uri "/.env.local"] [unique_id "am4f5ygnSE_vXgyPs9KdWAAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
tmiland
2026-08-01 16:31:17
(3 hours ago)
(nginx_404) Dot directory Honeypot Trap 207.175.176.160 (BE/Belgium/160.176.175.207.bc.googleusercon ...
show more
(nginx_404) Dot directory Honeypot Trap 207.175.176.160 (BE/Belgium/160.176.175.207.bc.googleusercontent.com): 2 in the last 3600 secs; IP: 207.175.176.160; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 207.175.176.160 - - [01/Aug/2026:18:31:16 +0200] "GET /.env.production HTTP/1.1" 404 2992 "-" "crusader-worker/1.0" 207.175.176.160 - - [01/Aug/2026:18:31:16 +0200] "GET /.env HTTP/1.1" 404 2992 "-" "crusader-worker/1.0"
show less
Brute-Force
๐ซ๐ท
YF
2026-08-01 16:30:55
(3 hours ago)
Environment file probe
Web App Attack
๐ฎ๐น
clamehost.it
2026-08-01 16:27:04
(3 hours ago)
Automatic report - Brute Force attack using this IP address
Brute-Force
๐ณ๐ฑ
e.fierstra
2026-08-01 15:42:38
(3 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐ฌ๐ง
Aetherweb Ark
2026-08-01 15:28:57
(4 hours ago)
(mod_security) mod_security (id:949110) triggered by 207.175.176.160 (BE/Belgium/160.176.175.207.bc. ...
show more
(mod_security) mod_security (id:949110) triggered by 207.175.176.160 (BE/Belgium/160.176.175.207.bc.googleusercontent.com): N in the last X secs
show less
Web App Attack
๐ฉ๐ช
LRob
2026-08-01 15:27:38
(4 hours ago)
CrowdSec: crowdsecurity/http-sensitive-files | req: /.env.dev | 5 distinct paths | UA: crusader-work ...
show more
CrowdSec: crowdsecurity/http-sensitive-files | req: /.env.dev | 5 distinct paths | UA: crusader-worker/1.0
show less
Hacking
๐ซ๐ท
masterguru
2026-08-01 15:20:46
(4 hours ago)
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 207.175.176.160 (BE/Belgium/160.176.1 ...
show more
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 207.175.176.160 (BE/Belgium/160.176.175.207.bc.googleusercontent.com): 2 in the last 3600 secs (0-196)
show less
Hacking
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-08-01 15:01:04
(4 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐บ๐ธ
NXTwoThou
2026-08-01 14:28:57
(5 hours ago)
/.env.prod
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-01 14:18:02
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 207.175.176.160 (160.176.175.207.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 207.175.176.160 (160.176.175.207.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 10:17:55.465470 2026] [security2:error] [pid 1163005:tid 1163005] [client 207.175.176.160:40156] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "thepeonypeople.com.vanemby.com"] [uri "/.env.old"] [unique_id "am4AE1Cv6kCZ5rXHiYt_ugAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-01 14:00:06
(5 hours ago)
suspicious request in access.log
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-01 13:52:26
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 207.175.176.160 (160.176.175.207.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 207.175.176.160 (160.176.175.207.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 09:52:20.635194 2026] [security2:error] [pid 465459:tid 465459] [client 207.175.176.160:45986] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "herston.us"] [uri "/.env.bak"] [unique_id "am36FIcmCMBiHyKs-pi4fwAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
inlink.ltd
2026-08-01 13:36:18
(6 hours ago)
dot file probe
Web App Attack