🇳🇱
homeshowdomain.nl
2026-09-05 22:01:42
(22 hours ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-09-04.
show less
Web App Attack
SSH
Hacking
🇸🇪
Per-Erik Runebert
2026-09-05 08:39:38
(1 day ago)
Excessive unauthorized requests
Hacking
🇳🇱
homeshowdomain.nl
2026-09-04 22:02:23
(1 day ago)
Auto-ban: >3000 req/min op 2026-09-04
Web App Attack
SSH
Hacking
🇺🇸
TPI-Abuse
2026-09-04 15:20:56
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 23.251.158.197 (197.158.251.23.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 23.251.158.197 (197.158.251.23.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 11:20:50.934904 2026] [security2:error] [pid 4144:tid 4144] [client 23.251.158.197:38188] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.wglennburns.com"] [uri "/.env.production"] [unique_id "aprh0oZEgMrUMMDniOZrKQAAAIk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 14:41:28
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 23.251.158.197 (197.158.251.23.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 23.251.158.197 (197.158.251.23.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 10:41:25.284792 2026] [security2:error] [pid 28039:tid 28039] [client 23.251.158.197:34728] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "schonplanet.com"] [uri "/.env.dev"] [unique_id "aprYlW1KK4MhyYNIrzzDSwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇮
YF
2026-09-04 14:30:46
(2 days ago)
WordPress config file probe
Web App Attack
Anonymous
2026-09-04 13:37:12
(2 days ago)
Path traversal / sensitive-file exploit probing (jail=apache-scanners)
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 13:17:42
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 23.251.158.197 (197.158.251.23.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 23.251.158.197 (197.158.251.23.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 09:17:36.894969 2026] [security2:error] [pid 21586:tid 21586] [client 23.251.158.197:60322] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "stage.dtla2028.com"] [uri "/wp-config.php~"] [unique_id "aprE8E2FYUAoAGWSiMHvFQAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 11:50:10
(2 days ago)
(mod_security) mod_security (id:949110) triggered by 23.251.158.197 (197.158.251.23.bc.googleusercon ...
show more
(mod_security) mod_security (id:949110) triggered by 23.251.158.197 (197.158.251.23.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 07:50:06.463877 2026] [security2:error] [pid 32746:tid 32746] [client 23.251.158.197:33742] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "lizzyle.com"] [uri "/.env.production"] [unique_id "apqwbvYQqRQPc0cSdRqLvgAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
Skyrider
2026-09-04 11:23:59
(2 days ago)
Nginx: HTTP 4xx probe/scan attempts. Automated fail2ban report.
Bad Web Bot
Web App Attack
🇩🇪
FD-IX
2026-09-04 10:49:18
(2 days ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
🇬🇧
consul.to
2026-09-04 10:19:14
(2 days ago)
Web attack/malicious scanning detected
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 10:03:58
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 23.251.158.197 (197.158.251.23.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 23.251.158.197 (197.158.251.23.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 06:03:52.187897 2026] [security2:error] [pid 20999:tid 20999] [client 23.251.158.197:42846] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.blackstarmgmt.net"] [uri "/.env.dev"] [unique_id "apqXiKJr3_ZxycT0AWZ1LgAAACY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-04 09:49:16
(2 days ago)
Web application attack detected.
Web App Attack
🇪🇸
alferez
2026-09-04 08:47:15
(2 days ago)
Searching .(env|sql|zip|tar|rar) files
Hacking
Exploited Host
Web App Attack