๐ณ๐ฑ
homeshowdomain.nl
2026-10-03 21:59:52
(6 days ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-10-02.
show less
Web App Attack
SSH
Hacking
๐บ๐ธ
Copious7283
2026-10-02 20:46:06
(1 week ago)
This IP was detected by CrowdSec triggering crowdsecurity/CVE-2017-9841
Web App Attack
๐ฉ๐ช
rzk
2026-10-02 20:27:03
(1 week ago)
CrowdSec scenario: crowdsecurity/http-cve-probing. Banned by Koru Cloud platform after multi-event d ...
show more
CrowdSec scenario: crowdsecurity/http-cve-probing. Banned by Koru Cloud platform after multi-event detection. ASN: DIGITALOCEAN-ASN. Country: AU. Timestamp: 2026-10-02T20:27:03+00:00.
show less
Bad Web Bot
Web App Attack
๐ฆ๐บ
aranguren.org
2026-10-02 20:02:29
(1 week ago)
2400:6180:10:200::e6b7:8000 - - [03/Oct/2026:06:02:28 +1000] "POST /vendor/phpunit/phpunit/src/Util/ ...
show more
2400:6180:10:200::e6b7:8000 - - [03/Oct/2026:06:02:28 +1000] "POST /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/2.0" 404 985 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36"
2400:6180:10:200::e6b7:8000 - - [03/Oct/2026:06:02:28 +1000] "GET /bitcoin/.env HTTP/2.0" 404 1138 "https://bitcoin.aranguren.org/.env" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36"
2400:6180:10:200::e6b7:8000 - - [03/Oct/2026:06:02:28 +1000] "GET /bitcoin/.git/config HTTP/2.0" 404 1152 "https://bitcoin.aranguren.org/.git/config" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36"
2400:6180:10:200::e6b7:8000 - - [03/Oct/2026:06:02:28 +1000] "GET /bitcoin/wp HTTP/2.0" 404 1134 "https://bitcoin.aranguren.org/wp" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0
...
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-10-02 19:23:06
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 2400:6180:10:200::e6b7:8000 (Unknown): 1 in the ...
show more
(mod_security) mod_security (id:210492) triggered by 2400:6180:10:200::e6b7:8000 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 15:23:01.746445 2026] [security2:error] [pid 10482:tid 10482] [client 2400:6180:10:200::e6b7:8000:37484] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "birthplaceofprohockey.org"] [uri "/.env"] [unique_id "asAElcwo6A6SSs2kFvKZgQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 19:02:27
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 2400:6180:10:200::e6b7:8000 (Unknown): 1 in the ...
show more
(mod_security) mod_security (id:210492) triggered by 2400:6180:10:200::e6b7:8000 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 15:02:22.536027 2026] [security2:error] [pid 6646:tid 6646] [client 2400:6180:10:200::e6b7:8000:35968] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "birdlovesfish.com"] [uri "/.env"] [unique_id "ar__vkGsy9pUR59kYipqagAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 18:38:30
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 2400:6180:10:200::e6b7:8000 (Unknown): 1 in the ...
show more
(mod_security) mod_security (id:210492) triggered by 2400:6180:10:200::e6b7:8000 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 14:38:23.576505 2026] [security2:error] [pid 17614:tid 17614] [client 2400:6180:10:200::e6b7:8000:40420] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bipocmentalhealthcoalition.org"] [uri "/.env"] [unique_id "ar_6H93OWNOV9yrOWSRLygAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
BlueWire Hosting
2026-10-02 18:15:01
(1 week ago)
Aggressive scanning resulting into 404
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-10-02 18:01:23
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 2400:6180:10:200::e6b7:8000 (Unknown): 1 in the ...
show more
(mod_security) mod_security (id:210492) triggered by 2400:6180:10:200::e6b7:8000 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 14:01:16.820294 2026] [security2:error] [pid 17701:tid 17701] [client 2400:6180:10:200::e6b7:8000:44550] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "biomechanicalwars.com"] [uri "/.env"] [unique_id "ar_xbHgwRztlTNRyl9t9GAAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 17:21:11
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 2400:6180:10:200::e6b7:8000 (Unknown): 1 in the ...
show more
(mod_security) mod_security (id:210492) triggered by 2400:6180:10:200::e6b7:8000 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 13:21:08.131401 2026] [security2:error] [pid 26049:tid 26049] [client 2400:6180:10:200::e6b7:8000:25900] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bins.mcbrearty.org"] [uri "/.env"] [unique_id "ar_oBPoivcru73XA54Ew8AAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
macrob
2026-10-02 17:15:46
(1 week ago)
2026/10/02 17:15:44 [error] 2231819#2231819: *9370692 access forbidden by rule, client: 2400:6180:10 ...
show more
2026/10/02 17:15:44 [error] 2231819#2231819: *9370692 access forbidden by rule, client: 2400:6180:10:200::e6b7:8000, server: binixo-vn.com, request: "GET /wordpress HTTP/2.0", host: "binixo-vn.com"
2026/10/02 17:15:44 [error] 2231817#2231817: *9370696 access forbidden by rule, client: 2400:6180:10:200::e6b7:8000, server: binixo-vn.com, request: "GET /.env HTTP/2.0", host: "binixo-vn.com"
2026/10/02 17:15:44 [error] 2231819#2231819: *9370697 access forbidden by rule, client: 2400:6180:10:200::e6b7:8000, server: binixo-vn.com, request: "GET /.git/config HTTP/2.0", host: "binixo-vn.com"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 16:57:13
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 2400:6180:10:200::e6b7:8000 (Unknown): 1 in the ...
show more
(mod_security) mod_security (id:210492) triggered by 2400:6180:10:200::e6b7:8000 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 12:57:09.126902 2026] [security2:error] [pid 10810:tid 10810] [client 2400:6180:10:200::e6b7:8000:62008] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "binasplace.thinkingepic.com"] [uri "/.env"] [unique_id "ar_iZQD7iy2j_ZSuVv978wAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 16:29:41
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 2400:6180:10:200::e6b7:8000 (Unknown): 1 in the ...
show more
(mod_security) mod_security (id:210492) triggered by 2400:6180:10:200::e6b7:8000 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 12:29:35.715850 2026] [security2:error] [pid 16982:tid 16982] [client 2400:6180:10:200::e6b7:8000:13428] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "billwegener.net"] [uri "/.env"] [unique_id "ar_b77ZUsxa1st8Y47h8XgAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 16:14:08
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 2400:6180:10:200::e6b7:8000 (Unknown): 1 in the ...
show more
(mod_security) mod_security (id:210492) triggered by 2400:6180:10:200::e6b7:8000 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 12:14:03.792815 2026] [security2:error] [pid 5205:tid 5275] [client 2400:6180:10:200::e6b7:8000:12428] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "billingsleyonline.com"] [uri "/.env"] [unique_id "ar_YS1giYfl8tBks_qB-lgAAAE0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ต๐ฑ
Budyn
2026-10-02 16:00:51
(1 week ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: CRITICAL: RCE / Payload Injection ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: CRITICAL: RCE / Payload Injection. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: billing.astropot.website | URI: /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36 | BODY: <?=base64_decode("bWVtZWtjaW5h");?>
show less
Hacking
Web App Attack