๐ณ๐ฑ
homeshowdomain.nl
2026-07-21 22:00:34
(6 days ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-07-20.
show less
Web App Attack
SSH
Hacking
๐บ๐ธ
WellSpring
2026-07-20 15:14:20
(1 week ago)
env leak on 816.today/.openclaw/.env โ WellSpr.ing/NetSentinel civic-AI security layer
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-20 15:04:25
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 2a09:bac5:6d1c:323c::501:c (Unknown): 1 in the ...
show more
(mod_security) mod_security (id:210730) triggered by 2a09:bac5:6d1c:323c::501:c (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 20 11:04:17.471853 2026] [security2:error] [pid 310725:tid 310725] [client 2a09:bac5:6d1c:323c::501:c:56422] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||dev.philipma.com|F|2"] [data ".philipma.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "dev.philipma.com"] [uri "/z9x8c7v6b5-debug-trigger-dev.philipma.com"] [unique_id "al448TeMbv5MOjulYMQ0QwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-18 08:20:06
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 2a09:bac5:6d1c:323c::501:c (Unknown): 1 in the ...
show more
(mod_security) mod_security (id:210730) triggered by 2a09:bac5:6d1c:323c::501:c (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 18 04:20:01.806559 2026] [security2:error] [pid 1770573:tid 1770573] [client 2a09:bac5:6d1c:323c::501:c:62518] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||webserviceswest.com|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "webserviceswest.com"] [uri "/rclone.conf"] [unique_id "als3Mc11B_E3PY7TJsu-4gAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
big-cloud.nl
2026-07-18 08:09:18
(1 week ago)
Try to access /config/.env
Web App Attack
Anonymous
2026-07-15 06:33:24
(1 week ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-14 01:45:23
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 2a09:bac5:6d1c:323c::501:c (Unknown): 1 in the ...
show more
(mod_security) mod_security (id:210492) triggered by 2a09:bac5:6d1c:323c::501:c (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 13 21:45:17.680761 2026] [security2:error] [pid 6242:tid 6242] [client 2a09:bac5:6d1c:323c::501:c:31970] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "lozzy.net"] [uri "/.git/HEAD"] [unique_id "alWUrWX6yLmBib8bfmiDzAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Mangelot Hosting
2026-07-13 18:14:14
(2 weeks ago)
(modsecurity) srv101 ModSecurity 2a09:bac5:6d1c:323c::501:c (US/United States/-): 10 in the last 360 ...
show more
(modsecurity) srv101 ModSecurity 2a09:bac5:6d1c:323c::501:c (US/United States/-): 10 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs:
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-13 18:10:33
(2 weeks ago)
(mod_security) mod_security (id:210730) triggered by 2a09:bac5:6d1c:323c::501:c (Unknown): 1 in the ...
show more
(mod_security) mod_security (id:210730) triggered by 2a09:bac5:6d1c:323c::501:c (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 13 14:10:28.452999 2026] [security2:error] [pid 1573:tid 1573] [client 2a09:bac5:6d1c:323c::501:c:38174] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||lg.cloudex.link|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "lg.cloudex.link"] [uri "/rclone.conf"] [unique_id "alUqFG-CbwH7939wj1I8MQAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-12 12:25:42
(2 weeks ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
๐ฉ๐ช
AbuseBaer
2026-07-12 05:55:13
(2 weeks ago)
access attempt detected by IDS script (B)
Web App Attack
๐ณ๐ฑ
Site.eu
2026-07-12 04:40:44
(2 weeks ago)
Excessive 404/403 errors
Brute-Force