๐ณ๐ฑ
homeshowdomain.nl
2026-07-17 21:59:26
(4 days ago)
Auto-ban: >3000 req/min op 2026-07-17
Web App Attack
SSH
Hacking
๐บ๐ธ
TPI-Abuse
2026-07-17 01:48:42
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 3.147.142.15 (ec2-3-147-142-15.us-east-2.comput ...
show more
(mod_security) mod_security (id:210492) triggered by 3.147.142.15 (ec2-3-147-142-15.us-east-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 16 21:48:39.266112 2026] [security2:error] [pid 774048:tid 774048] [client 3.147.142.15:40108] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "powerlessons.net"] [uri "/.env.production"] [unique_id "almJ92AdY7AhD7HPJeuBfQAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
Matthew Ping
2026-07-17 01:45:02
(5 days ago)
ModSecurity rule 949110 triggered on wp3. Web application attack blocked by CSF/LFD.
Web App Attack
Hacking
๐จ๐ญ
4server
2026-07-17 01:36:12
(5 days ago)
[FriJul1703:36:05.1301202026][security2:error][pid2285136:tid2285457][client3.147.142.15:0]ModSecuri ...
show more
[FriJul1703:36:05.1301202026][security2:error][pid2285136:tid2285457][client3.147.142.15:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\".env\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"365\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"gipfelbild.com\"][uri\"/backend/.env\"][unique_id\"almHBcl_ruHbSjMBDhsThwAAANM\"]
show less
Hacking
Web App Attack
๐ซ๐ท
Tilellit.PRO
2026-07-17 01:23:58
(5 days ago)
Malicious web traffic detected by CrowdSec
Hacking
๐ฌ๐ง
consul.to
2026-07-17 00:20:37
(5 days ago)
Web attack/malicious scanning detected
Web App Attack
๐ฎ๐น
mediarama.com
2026-07-16 22:40:26
(5 days ago)
Banned by Fail2Ban
Web App Attack
๐ณ๐ฑ
Site.eu
2026-07-16 22:15:27
(5 days ago)
Excessive multi-domain requests
Brute-Force
Anonymous
2026-07-16 21:35:30
(5 days ago)
(caddyscan) Scanner path probe from 3.147.142.15 (US/United States/ec2-3-147-142-15.us-east-2.comput ...
show more
(caddyscan) Scanner path probe from 3.147.142.15 (US/United States/ec2-3-147-142-15.us-east-2.compute.amazonaws.com): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 2627 3.147.142.15 - - [16/Jul/2026:21:35:29 +0000] "GET /config/.env HTTP/1.1"
[REDACTED] 200 2627 3.147.142.15 - - [16/Jul/2026:21:35:29 +0000] "GET /backend/.env HTTP/1.1"
[REDACTED] 200 2627 3.147.142.15 - - [16/Jul/2026:21:35:29 +0000] "GET /frontend/.env HTTP/1.1"
[REDACTED] 200 2627 3.147.142.15 - - [16/Jul/2026:21:35:29 +0000] "GET /api/.env HTTP/1.1"
[REDACTED] 200 2627 3.147.142.15 - - [16/Jul/2026:21:35:29 +0000] "GET /server/.env HTTP/1.1"
show less
Port Scan
๐ณ๐ฑ
Mangelot Hosting
2026-07-16 21:22:30
(5 days ago)
(modsecurity) srv102 ModSecurity 3.147.142.15 (US/United States/ec2-3-147-142-15.us-east-2.compute.a ...
show more
(modsecurity) srv102 ModSecurity 3.147.142.15 (US/United States/ec2-3-147-142-15.us-east-2.compute.amazonaws.com): 10 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs:
show less
Web App Attack
๐ต๐ฑ
lns.bz
2026-07-16 21:02:20
(5 days ago)
Web app attack [PL.Lu]
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-16 20:57:28
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 3.147.142.15 (ec2-3-147-142-15.us-east-2.comput ...
show more
(mod_security) mod_security (id:210492) triggered by 3.147.142.15 (ec2-3-147-142-15.us-east-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 16 16:57:24.394924 2026] [security2:error] [pid 7614:tid 7705] [client 3.147.142.15:38246] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.agrigrailtech.com"] [uri "/api/.env"] [unique_id "allFtJr2fMUhZAbfoiisDQAAAcE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Trashware
2026-07-16 20:56:34
(5 days ago)
Excessive vulnerability probing
Hacking
Bad Web Bot
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-07-16 20:43:04
(5 days ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-16 20:36:12
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 3.147.142.15 (ec2-3-147-142-15.us-east-2.comput ...
show more
(mod_security) mod_security (id:210492) triggered by 3.147.142.15 (ec2-3-147-142-15.us-east-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 16 16:36:05.866281 2026] [security2:error] [pid 24808:tid 24808] [client 3.147.142.15:36200] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "instituteofscience.com"] [uri "/.env"] [unique_id "allAtZa-6Xq4UPbig0NIJwAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack