๐ณ๐ฑ
homeshowdomain.nl
2026-07-05 21:59:05
(3 weeks ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-07-04.
show less
Web App Attack
SSH
Hacking
๐บ๐ธ
TPI-Abuse
2026-07-05 20:27:38
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 2a01:4f8:1c19:a57f::1 (Unknown): 1 in the last ...
show more
(mod_security) mod_security (id:210492) triggered by 2a01:4f8:1c19:a57f::1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 05 16:27:30.876711 2026] [security2:error] [pid 30256:tid 30263] [client 2a01:4f8:1c19:a57f::1:7706] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.lavotel.com.oplconnect.com"] [uri "/.git/config"] [unique_id "akq-MlXVpugFw6SFcb7rBQAAAAE"], referer: https://www.google.com/search?q=www.lavotel.com.oplconnect.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
filstal.org
2026-07-05 17:58:23
(3 weeks ago)
Web reconnaissance detected: automated probing for sensitive files, backup archives, admin panels an ...
show more
Web reconnaissance detected: automated probing for sensitive files, backup archives, admin panels and known vulnerability paths.
show less
Hacking
Brute-Force
Web App Attack
๐ฉ๐ช
Blexyel
2026-07-05 15:10:35
(3 weeks ago)
2a01:4f8:1c19:a57f::1 - - [05/Jul/2026:17:10:34 +0200] "HEAD /.git/config HTTP/1.1" 404 0 "https://w ...
show more
2a01:4f8:1c19:a57f::1 - - [05/Jul/2026:17:10:34 +0200] "HEAD /.git/config HTTP/1.1" 404 0 "https://www.google.com/search?q=autodiscover.blexyel.wtf" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ChatGPT-User/1.0; +https://openai.com/bot)"
...
show less
Brute-Force
Web App Attack
๐ฉ๐ช
4server
2026-07-05 14:39:31
(3 weeks ago)
[SunJul0516:39:27.4030132026][security2:error][pid2943912:tid2943942][client2a01:4f8:1c19:a57f::1:0] ...
show more
[SunJul0516:39:27.4030132026][security2:error][pid2943912:tid2943942][client2a01:4f8:1c19:a57f::1:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:5\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.9\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"autodiscover.atelier-lara.ch\"][uri\"/.env.production.local\"][unique_id\"akpsn0l6fHKY-g8Riv0s6wAAABI\"]\,referer:https://www.google.com/search\?q=autodiscover.atelier-lara.ch
show less
Port Scan
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-05 13:40:43
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 2a01:4f8:1c19:a57f::1 (Unknown): 1 in the last ...
show more
(mod_security) mod_security (id:210492) triggered by 2a01:4f8:1c19:a57f::1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 05 09:40:35.797472 2026] [security2:error] [pid 24336:tid 24336] [client 2a01:4f8:1c19:a57f::1:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.365soft.top"] [uri "/.env.local"] [unique_id "akpe0wIAbgRG-rMmLRBltAAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-05 07:35:54
(3 weeks ago)
(mod_security) mod_security (id:210730) triggered by 2a01:4f8:1c19:a57f::1 (Unknown): 1 in the last ...
show more
(mod_security) mod_security (id:210730) triggered by 2a01:4f8:1c19:a57f::1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 05 03:35:50.304834 2026] [security2:error] [pid 4751:tid 4751] [client 2a01:4f8:1c19:a57f::1:50340] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||ten0.forefrontmusic.com|F|2"] [data ".env.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "ten0.forefrontmusic.com"] [uri "/.env.bak"] [unique_id "akoJVlUiCTr9HfmSfeYn_wAAAAs"], referer: https://www.google.com/search?q=ten0.forefrontmusic.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
big-cloud.nl
2026-07-05 06:32:25
(3 weeks ago)
Try to access /.env
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-05 05:10:12
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 2a01:4f8:1c19:a57f::1 (Unknown): 1 in the last ...
show more
(mod_security) mod_security (id:210492) triggered by 2a01:4f8:1c19:a57f::1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 05 01:10:04.753101 2026] [security2:error] [pid 13767:tid 13767] [client 2a01:4f8:1c19:a57f::1:31346] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mlappa.net"] [uri "/.git/config"] [unique_id "aknnLETDXL_bgr5faVFlUQAAAAo"], referer: https://www.google.com/search?q=mlappa.net
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-04 22:17:31
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 2a01:4f8:1c19:a57f::1 (Unknown): 1 in the last ...
show more
(mod_security) mod_security (id:210492) triggered by 2a01:4f8:1c19:a57f::1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 04 18:17:25.940278 2026] [security2:error] [pid 31735:tid 31735] [client 2a01:4f8:1c19:a57f::1:3950] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.livingawakenedbook.com"] [uri "/.env.bak"] [unique_id "akmGdaE8uAU6mcJFgloRoAAAAA0"], referer: https://www.google.com/search?q=autodiscover.livingawakenedbook.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
on-com
2026-07-04 20:54:34
(3 weeks ago)
URL scan
Brute-Force
Web App Attack
๐ฉ๐ช
0x44
2026-07-04 19:02:35
(3 weeks ago)
TCP SYN Discovery - Flooding
DDoS Attack
๐ซ๐ฎ
YF
2026-07-04 06:00:35
(3 weeks ago)
WordPress config file probe
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-04 05:59:31
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 2a01:4f8:1c19:a57f::1 (Unknown): 1 in the last ...
show more
(mod_security) mod_security (id:210492) triggered by 2a01:4f8:1c19:a57f::1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 04 01:59:25.221813 2026] [security2:error] [pid 2161:tid 2161] [client 2a01:4f8:1c19:a57f::1:12090] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "assembliesofgodinsamoa.org"] [uri "/wp-config.php.bak"] [unique_id "akihPVO9X7aMbmk2aaOrwwAAAAk"], referer: https://www.google.com/search?q=assembliesofgodinsamoa.org
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-04 05:27:38
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 2a01:4f8:1c19:a57f::1 (Unknown): 1 in the last ...
show more
(mod_security) mod_security (id:210492) triggered by 2a01:4f8:1c19:a57f::1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 04 01:27:31.680684 2026] [security2:error] [pid 9308:tid 9308] [client 2a01:4f8:1c19:a57f::1:20820] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "arklahomaflooring.com"] [uri "/.env.dist"] [unique_id "akiZwwsjtwk2x4iQ7bT2JAAAAAY"], referer: https://www.google.com/search?q=arklahomaflooring.com
show less
Brute-Force
Bad Web Bot
Web App Attack