๐ณ๐ฑ
homeshowdomain.nl
2026-09-20 22:00:25
(2 days ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-09-19.
show less
Web App Attack
SSH
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-20 04:00:08
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 2a05:f480:1400:3d24:5400:6ff:feb5:e35a (Unknown ...
show more
(mod_security) mod_security (id:210492) triggered by 2a05:f480:1400:3d24:5400:6ff:feb5:e35a (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 19 23:59:54.647957 2026] [security2:error] [pid 16132:tid 16132] [client 2a05:f480:1400:3d24:5400:6ff:feb5:e35a:52468] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "thebradleyclinic.com"] [uri "/.env"] [unique_id "aq9aOrGPPwwxo2uQrBUJYAAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 03:21:27
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 2a05:f480:1400:3d24:5400:6ff:feb5:e35a (Unknown ...
show more
(mod_security) mod_security (id:210492) triggered by 2a05:f480:1400:3d24:5400:6ff:feb5:e35a (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 19 23:21:19.536831 2026] [security2:error] [pid 16780:tid 16780] [client 2a05:f480:1400:3d24:5400:6ff:feb5:e35a:39344] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "rosawallas.com"] [uri "/.env"] [unique_id "aq9RL788pWnlzzK-CdXB0wAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 03:00:27
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 2a05:f480:1400:3d24:5400:6ff:feb5:e35a (Unknown ...
show more
(mod_security) mod_security (id:210492) triggered by 2a05:f480:1400:3d24:5400:6ff:feb5:e35a (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 19 23:00:19.806250 2026] [security2:error] [pid 15725:tid 15725] [client 2a05:f480:1400:3d24:5400:6ff:feb5:e35a:54566] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bayareahiphopforever.org"] [uri "/.env"] [unique_id "aq9MQygRQGNBZfYP92Lb3wAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
helios.live
2026-09-20 02:36:05
(3 days ago)
2026/09/20 02:36:03 [error] 1522636#1522636: *3848884 access forbidden by rule, client: 2a05:f480:14 ...
show more
2026/09/20 02:36:03 [error] 1522636#1522636: *3848884 access forbidden by rule, client: 2a05:f480:1400:3d24:5400:6ff:feb5:e35a, server: kocervpn.com, request: "GET /.env HTTP/1.1", host: "kocervpn.com"
2026/09/20 02:36:04 [error] 1522635#1522635: *3848872 access forbidden by rule, client: 2a05:f480:1400:3d24:5400:6ff:feb5:e35a, server: kocervpn.com, request: "GET /conf/.env HTTP/1.1", host: "kocervpn.com"
2026/09/20 02:36:04 [error] 1522636#1522636: *3848884 access forbidden by rule, client: 2a05:f480:1400:3d24:5400:6ff:feb5:e35a, server: kocervpn.com, request: "GET /wp-content/.env HTTP/1.1", host: "kocervpn.com"
2026/09/20 02:36:05 [error] 1522636#1522636: *3848884 access forbidden by rule, client: 2a05:f480:1400:3d24:5400:6ff:feb5:e35a, server: kocervpn.com, request: "GET /wp-admin/.env HTTP/1.1", host: "kocervpn.com"
2026/09/20 02:36:05 [error] 1522636#1522636: *3848884 access forbidden by rule, client: 2a05:f480:1400:3d24:5400:6ff:feb5:e35a, server: kocervpn.com, request: "GET /li
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 02:05:17
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 2a05:f480:1400:3d24:5400:6ff:feb5:e35a (Unknown ...
show more
(mod_security) mod_security (id:210492) triggered by 2a05:f480:1400:3d24:5400:6ff:feb5:e35a (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 19 22:05:09.168670 2026] [security2:error] [pid 16319:tid 16319] [client 2a05:f480:1400:3d24:5400:6ff:feb5:e35a:37164] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "recorplast.com"] [uri "/.env"] [unique_id "aq8_VUUcIoQp_TLmWcmhAQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 01:22:28
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 2a05:f480:1400:3d24:5400:6ff:feb5:e35a (Unknown ...
show more
(mod_security) mod_security (id:210492) triggered by 2a05:f480:1400:3d24:5400:6ff:feb5:e35a (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 19 21:22:21.431542 2026] [security2:error] [pid 24177:tid 24177] [client 2a05:f480:1400:3d24:5400:6ff:feb5:e35a:49430] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "stickittomebuttons.com"] [uri "/.env"] [unique_id "aq81TU_6SRkWZIncHlxkZgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 01:06:45
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 2a05:f480:1400:3d24:5400:6ff:feb5:e35a (Unknown ...
show more
(mod_security) mod_security (id:210492) triggered by 2a05:f480:1400:3d24:5400:6ff:feb5:e35a (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 19 21:06:40.534802 2026] [security2:error] [pid 20657:tid 20657] [client 2a05:f480:1400:3d24:5400:6ff:feb5:e35a:54942] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "freightmotivity.com"] [uri "/.env"] [unique_id "aq8xoCop2jO99CqMn462lgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 00:50:44
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 2a05:f480:1400:3d24:5400:6ff:feb5:e35a (Unknown ...
show more
(mod_security) mod_security (id:210492) triggered by 2a05:f480:1400:3d24:5400:6ff:feb5:e35a (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 19 20:50:41.434862 2026] [security2:error] [pid 9472:tid 9472] [client 2a05:f480:1400:3d24:5400:6ff:feb5:e35a:51052] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "johnedwardsconsulting.com"] [uri "/.env"] [unique_id "aq8t4eTOMFeen0MqiWRadAAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 00:31:04
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 2a05:f480:1400:3d24:5400:6ff:feb5:e35a (Unknown ...
show more
(mod_security) mod_security (id:210492) triggered by 2a05:f480:1400:3d24:5400:6ff:feb5:e35a (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 19 20:30:55.650379 2026] [security2:error] [pid 2485:tid 2485] [client 2a05:f480:1400:3d24:5400:6ff:feb5:e35a:51898] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "flyingdodopublications.com"] [uri "/.env"] [unique_id "aq8pP3DtaDbh04UFbfsyUAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Mangelot Hosting
2026-09-20 00:19:27
(3 days ago)
(modsecurity) srv102 ModSecurity 2a05:f480:1400:3d24:5400:6ff:feb5:e35a (NL/The Netherlands/-): 30 i ...
show more
(modsecurity) srv102 ModSecurity 2a05:f480:1400:3d24:5400:6ff:feb5:e35a (NL/The Netherlands/-): 30 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs:
show less
Web App Attack
๐ณ๐ฑ
BlueWire Hosting
2026-09-20 00:19:04
(3 days ago)
High-confidence malicious configuration/VCS probe
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-19 23:15:26
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 2a05:f480:1400:3d24:5400:6ff:feb5:e35a (Unknown ...
show more
(mod_security) mod_security (id:210492) triggered by 2a05:f480:1400:3d24:5400:6ff:feb5:e35a (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 19 19:15:18.337093 2026] [security2:error] [pid 6000:tid 6000] [client 2a05:f480:1400:3d24:5400:6ff:feb5:e35a:43534] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "infrared-heaters.us"] [uri "/.env"] [unique_id "aq8Xhu1fD_c39YsLkt6CNAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-09-19 22:58:08
(3 days ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-19 22:23:04
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 2a05:f480:1400:3d24:5400:6ff:feb5:e35a (Unknown ...
show more
(mod_security) mod_security (id:210492) triggered by 2a05:f480:1400:3d24:5400:6ff:feb5:e35a (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 19 18:22:57.150052 2026] [security2:error] [pid 1151:tid 1151] [client 2a05:f480:1400:3d24:5400:6ff:feb5:e35a:50100] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "agrizel.com"] [uri "/.env"] [unique_id "aq8LQUqI2GhnTyXqGth4zgAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack