๐ณ๐ฑ
homeshowdomain.nl
2026-10-03 21:59:51
(1 day ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-10-02.
show less
Web App Attack
SSH
Hacking
๐บ๐ธ
TPI-Abuse
2026-10-02 17:48:00
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 2400:6180:10:200::e6b7:6000 (Unknown): 1 in the ...
show more
(mod_security) mod_security (id:210492) triggered by 2400:6180:10:200::e6b7:6000 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 13:47:53.115366 2026] [security2:error] [pid 12483:tid 12483] [client 2400:6180:10:200::e6b7:6000:28224] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bazzoli.com"] [uri "/.env"] [unique_id "ar_uSbX7i-buacWMbUv6FgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 17:29:53
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 2400:6180:10:200::e6b7:6000 (Unknown): 1 in the ...
show more
(mod_security) mod_security (id:210492) triggered by 2400:6180:10:200::e6b7:6000 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 13:29:48.369153 2026] [security2:error] [pid 31341:tid 31341] [client 2400:6180:10:200::e6b7:6000:34806] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "baysidechiropractic.net"] [uri "/.env"] [unique_id "ar_qDNFcoQCA0-iVLFnShAAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 17:12:02
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 2400:6180:10:200::e6b7:6000 (Unknown): 1 in the ...
show more
(mod_security) mod_security (id:210492) triggered by 2400:6180:10:200::e6b7:6000 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 13:11:59.018346 2026] [security2:error] [pid 24765:tid 24765] [client 2400:6180:10:200::e6b7:6000:54368] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bayarealangarts.com"] [uri "/.env"] [unique_id "ar_l31L1VErgSW194aO79AAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
SCHAPPY
2026-10-02 16:49:23
(3 days ago)
Malicious activity from IP detected: crowdsecurity/CVE-2017-9841.
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 16:29:25
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 2400:6180:10:200::e6b7:6000 (Unknown): 1 in the ...
show more
(mod_security) mod_security (id:210492) triggered by 2400:6180:10:200::e6b7:6000 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 12:29:21.210812 2026] [security2:error] [pid 5418:tid 5418] [client 2400:6180:10:200::e6b7:6000:40946] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "battleprides.tracybur.net"] [uri "/.env"] [unique_id "ar_b4Uy-Tr3bG5ObOzod7gAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
VHosting
2026-10-02 16:25:03
(3 days ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 16:02:52
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 2400:6180:10:200::e6b7:6000 (Unknown): 1 in the ...
show more
(mod_security) mod_security (id:210492) triggered by 2400:6180:10:200::e6b7:6000 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 12:02:45.919233 2026] [security2:error] [pid 1119:tid 1119] [client 2400:6180:10:200::e6b7:6000:15474] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "batesstrategygroup.com"] [uri "/.git/config"] [unique_id "ar_VpbAIJ9SNCAXeH7IEZgAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 15:40:20
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 2400:6180:10:200::e6b7:6000 (Unknown): 1 in the ...
show more
(mod_security) mod_security (id:210492) triggered by 2400:6180:10:200::e6b7:6000 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 11:40:16.070700 2026] [security2:error] [pid 24503:tid 24503] [client 2400:6180:10:200::e6b7:6000:33576] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "basselier.com"] [uri "/.env"] [unique_id "ar_QYLcVQfOP4uO-QDP6IgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 15:03:16
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 2400:6180:10:200::e6b7:6000 (Unknown): 1 in the ...
show more
(mod_security) mod_security (id:210492) triggered by 2400:6180:10:200::e6b7:6000 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 11:03:10.934114 2026] [security2:error] [pid 1745:tid 1745] [client 2400:6180:10:200::e6b7:6000:7060] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "basecampexp.com.smartstylehair.com"] [uri "/.git/config"] [unique_id "ar_Hrlbcbp2k-Cet_ISkrgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 14:29:21
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 2400:6180:10:200::e6b7:6000 (Unknown): 1 in the ...
show more
(mod_security) mod_security (id:210492) triggered by 2400:6180:10:200::e6b7:6000 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 10:29:14.263877 2026] [security2:error] [pid 5978:tid 5978] [client 2400:6180:10:200::e6b7:6000:14328] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "barriebrown.com.thephysicsroom.com"] [uri "/.git/config"] [unique_id "ar-_umCmIPm30L_bD6xwBgAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Mangelot Hosting
2026-10-02 14:27:03
(3 days ago)
(web_sensitive_file) srv101 Sensitive file probe (.env/.git/backup) 2400:6180:10:200::e6b7:6000 (AU/ ...
show more
(web_sensitive_file) srv101 Sensitive file probe (.env/.git/backup) 2400:6180:10:200::e6b7:6000 (AU/Australia/-): 2 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs:
show less
Web App Attack
๐ณ๐ฑ
Alt255
2026-10-02 14:12:07
(3 days ago)
[ti-02ov] Web exploit scanning: 2 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-02ov] Web exploit scanning: 2 suspicious requests detected by fail2ban jail apache-scanner. Example: 2400:6180:10:200::e6b7:6000 - - [02/Oct/2026:16:11:51 +0200] "GET /.env HTTP/2.0" 301 475 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36"
2400:6180:10:200::e6b7:6000 - - [02/Oct/2026:16:11:51 +0200] "GET /.git/config HTTP/2.0" 301 489 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-10-02 14:11:33
(3 days ago)
This IP was detected by CrowdSec triggering crowdsecurity/CVE-2017-9841
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 13:59:31
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 2400:6180:10:200::e6b7:6000 (Unknown): 1 in the ...
show more
(mod_security) mod_security (id:210492) triggered by 2400:6180:10:200::e6b7:6000 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 09:59:25.060194 2026] [security2:error] [pid 21604:tid 21604] [client 2400:6180:10:200::e6b7:6000:16236] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "barmitzvahnapkins.com"] [uri "/.env"] [unique_id "ar-4vcpC1jS-pOTczJnLEgAAACI"]
show less
Brute-Force
Bad Web Bot
Web App Attack