๐ณ๐ฑ
homeshowdomain.nl
2026-05-28 22:03:56
(1 week ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-05-27.
show less
Web App Attack
SSH
Hacking
๐บ๐ธ
TPI-Abuse
2026-05-27 22:44:16
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 23.95.150.45 (23-95-150-45-host.colocrossing.co ...
show more
(mod_security) mod_security (id:210492) triggered by 23.95.150.45 (23-95-150-45-host.colocrossing.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 27 18:44:03.911190 2026] [security2:error] [pid 14635:tid 14635] [client 23.95.150.45:50879] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.louisianamasons.anthonyjoseph.us"] [uri "/wp-config.php~"] [unique_id "ahdzs-VmU4AaNeMjP54bCwAAAAQ"], referer: https://www.google.com/search?q=www.louisianamasons.anthonyjoseph.us
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-27 16:39:11
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 23.95.150.45 (23-95-150-45-host.colocrossing.co ...
show more
(mod_security) mod_security (id:210492) triggered by 23.95.150.45 (23-95-150-45-host.colocrossing.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 27 12:39:05.999702 2026] [security2:error] [pid 18942:tid 18942] [client 23.95.150.45:45997] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.academicesl.com.nilestree.com"] [uri "/.env.vercel"] [unique_id "ahceKUVBPKo5IVRCPgkRmQAAAHE"], referer: https://www.google.com/search?q=www.academicesl.com.nilestree.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-27 00:21:23
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 23.95.150.45 (23-95-150-45-host.colocrossing.co ...
show more
(mod_security) mod_security (id:210492) triggered by 23.95.150.45 (23-95-150-45-host.colocrossing.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 26 20:20:55.302379 2026] [security2:error] [pid 14384:tid 14384] [client 23.95.150.45:52231] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.ultratec.com.mx.activethinkers.net"] [uri "/wp-config.php"] [unique_id "ahY452dcgnj0V1F4QsUbDAAAAAY"], referer: https://www.google.com/search?q=www.ultratec.com.mx.activethinkers.net
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-26 18:13:57
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 23.95.150.45 (23-95-150-45-host.colocrossing.co ...
show more
(mod_security) mod_security (id:210492) triggered by 23.95.150.45 (23-95-150-45-host.colocrossing.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 26 14:13:15.788469 2026] [security2:error] [pid 7486:tid 7486] [client 23.95.150.45:34675] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "amybeam.info"] [uri "/.env.backup"] [unique_id "ahXiu2r-7N9NeKrw0o-V7wAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-26 16:44:47
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 23.95.150.45 (23-95-150-45-host.colocrossing.co ...
show more
(mod_security) mod_security (id:210730) triggered by 23.95.150.45 (23-95-150-45-host.colocrossing.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 26 12:44:40.906284 2026] [security2:error] [pid 19477:tid 19502] [client 23.95.150.45:34389] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||appraisalteam.net|F|2"] [data ".db"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "appraisalteam.net"] [uri "/.config/gcloud/credentials.db"] [unique_id "ahXN-J7UaO9qoQjw7qBckwAAANY"], referer: https://www.google.com/search?q=appraisalteam.net
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-17 06:30:01
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 23.95.150.45 (23-95-150-45-host.colocrossing.co ...
show more
(mod_security) mod_security (id:210492) triggered by 23.95.150.45 (23-95-150-45-host.colocrossing.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jan 17 01:29:55.211634 2026] [security2:error] [pid 11802:tid 11802] [client 23.95.150.45:47465] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.nbcnewsradio.com"] [uri "/wp-content/plugins/simple-file-list/includes/ee-downloader.php"] [unique_id "aWssY3uuciip4PUkzsy8aQAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-13 09:12:06
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 23.95.150.45 (23-95-150-45-host.colocrossing.co ...
show more
(mod_security) mod_security (id:210492) triggered by 23.95.150.45 (23-95-150-45-host.colocrossing.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Nov 13 04:11:49.906092 2025] [security2:error] [pid 23590:tid 23590] [client 23.95.150.45:45069] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ftp.nbcnewsradio.com"] [uri "/.env.live"] [unique_id "aRWg1V2Us-JC-J6M3426NgAAACA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-07-27 00:48:39
(10 months ago)
(mod_security) mod_security (id:210492) triggered by 23.95.150.45 (23-95-150-45-host.colocrossing.co ...
show more
(mod_security) mod_security (id:210492) triggered by 23.95.150.45 (23-95-150-45-host.colocrossing.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 26 20:48:28.954733 2025] [security2:error] [pid 404370:tid 404567] [client 23.95.150.45:39593] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "whm.staging.kettlehill.com"] [uri "/content../.git/config"] [unique_id "aIV3XMy-cZtwxEkIWL8upwAAAM4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-05-29 20:54:06
(1 year ago)
(mod_security) mod_security (id:221260) triggered by 23.95.150.45 (23-95-150-45-host.colocrossing.co ...
show more
(mod_security) mod_security (id:221260) triggered by 23.95.150.45 (23-95-150-45-host.colocrossing.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 29 16:54:01.183754 2025] [security2:error] [pid 3485104:tid 3485104] [client 23.95.150.45:42635] ModSecurity: Access denied with code 403 (phase 1). Pattern match "^(?:\\\\'\\\\w+?=)?\\\\(\\\\)\\\\s{" at MATCHED_VAR. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "77"] [id "221260"] [rev "3"] [msg "COMODO WAF: Shellshock Command Injection Vulnerabilities in GNU Bash through 4.3 bash43-026 (CVE-2014-7187, CVE-2014-7186, CVE-2014-7169, CVE-2014-6278, CVE-2014-6277, CVE-2014-6271)||whm.farmers123.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "whm.farmers123.com"] [uri "/"] [unique_id "aDjJaWgjHRVvzQqTXFNOOwAAAAQ"], referer: () { ignored; }; echo Content-Type: text/html; echo ; /bin/cat /etc/passwd
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-01-26 11:00:21
(1 year ago)
| Common web attack.
Hacking
SQL Injection
Web App Attack