๐ณ๐ฑ
homeshowdomain.nl
2026-08-01 21:59:09
(1 month ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-07-31.
show less
Web App Attack
SSH
Hacking
๐บ๐ธ
TPI-Abuse
2026-07-31 10:50:35
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 2a09:bac5:636f:2905::416:8 (Unknown): 1 in the ...
show more
(mod_security) mod_security (id:210492) triggered by 2a09:bac5:636f:2905::416:8 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 31 06:50:28.083744 2026] [security2:error] [pid 565947:tid 565947] [client 2a09:bac5:636f:2905::416:8:37282] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.cottrel.com"] [uri "/.env"] [unique_id "amx99JNFEZ1dERqsokKwAAAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
cmbplf
2026-07-31 10:31:40
(1 month ago)
199 requests with url.path *.env
Brute-Force
Bad Web Bot
๐บ๐ธ
k3rn3l109
2026-07-31 10:11:46
(1 month ago)
Sentinel honeypot: cf-waf-auto hit on vault.emby-media.com UA=Mozilla/5.0 AppleWebKit/537.36 (KHTML, ...
show more
Sentinel honeypot: cf-waf-auto hit on vault.emby-media.com UA=Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; GPTBot/1.2; +https://openai.com/gptbot
show less
Hacking
๐บ๐ธ
TPI-Abuse
2026-07-31 09:45:30
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 2a09:bac5:636f:2905::416:8 (Unknown): 1 in the ...
show more
(mod_security) mod_security (id:210492) triggered by 2a09:bac5:636f:2905::416:8 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 31 05:45:24.457804 2026] [security2:error] [pid 129549:tid 129549] [client 2a09:bac5:636f:2905::416:8:25954] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.hanabritgermanshepherds.com"] [uri "/.env.development"] [unique_id "amxutFtwP414QaM0xaZ8eQAAAB8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-31 09:11:07
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 2a09:bac5:636f:2905::416:8 (Unknown): 1 in the ...
show more
(mod_security) mod_security (id:210492) triggered by 2a09:bac5:636f:2905::416:8 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 31 05:11:03.246792 2026] [security2:error] [pid 29873:tid 29873] [client 2a09:bac5:636f:2905::416:8:57392] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.westoaksurgentcare.com"] [uri "/.env"] [unique_id "amxmp0mSiTnXfVakn0AngQAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-31 08:53:18
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 2a09:bac5:636f:2905::416:8 (Unknown): 1 in the ...
show more
(mod_security) mod_security (id:210492) triggered by 2a09:bac5:636f:2905::416:8 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 31 04:53:11.652857 2026] [security2:error] [pid 2928866:tid 2928910] [client 2a09:bac5:636f:2905::416:8:33702] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.econpage.com"] [uri "/.env"] [unique_id "amxidzrx2P0l5YfbyYhdqwAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
VHosting
2026-07-31 08:45:06
(1 month ago)
Detected WordPress attack from 4 different servers
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-31 08:36:08
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 2a09:bac5:636f:2905::416:8 (Unknown): 1 in the ...
show more
(mod_security) mod_security (id:210492) triggered by 2a09:bac5:636f:2905::416:8 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 31 04:36:01.438459 2026] [security2:error] [pid 162765:tid 162765] [client 2a09:bac5:636f:2905::416:8:43830] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.colbygrenier.com"] [uri "/.env.development"] [unique_id "amxecaGnwFMtzuw5gsGs5gAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
NL-crowdsec-reporter
2026-07-31 08:34:44
(1 month ago)
CrowdSec | Unauthorized Access | Country:US | AS:CLOUDFLARENET
Web App Attack
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-07-31 08:18:18
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 2a09:bac5:636f:2905::416:8 (Unknown): 1 in the ...
show more
(mod_security) mod_security (id:210492) triggered by 2a09:bac5:636f:2905::416:8 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 31 04:18:10.770703 2026] [security2:error] [pid 287418:tid 287418] [client 2a09:bac5:636f:2905::416:8:19964] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.corepsychotherapycenter.com"] [uri "/.env"] [unique_id "amxaQnMT2kAxsg6UTc4fdwAAAFA"]
show less
Brute-Force
Bad Web Bot
Web App Attack