๐ณ๐ฑ
homeshowdomain.nl
2026-09-01 22:00:17
(35 minutes ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-08-31.
show less
Web App Attack
SSH
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-01 14:05:44
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.123.197.142 (142.197.123.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.123.197.142 (142.197.123.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 10:05:39.212124 2026] [security2:error] [pid 28910:tid 28910] [client 34.123.197.142:47080] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.deckmasterscompany.com"] [uri "/wp-config.php~"] [unique_id "apbbs2k5Rlg0LIXOWRxyjQAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 13:47:22
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.123.197.142 (142.197.123.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.123.197.142 (142.197.123.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 09:47:14.683884 2026] [security2:error] [pid 30423:tid 30423] [client 34.123.197.142:53520] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.sonnyvo.com"] [uri "/.env"] [unique_id "apbXYj-enRYsWKQ3CAxaeAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FD-IX
2026-09-01 12:55:41
(9 hours ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 10:59:31
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.123.197.142 (142.197.123.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.123.197.142 (142.197.123.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 06:59:24.666601 2026] [security2:error] [pid 20082:tid 20174] [client 34.123.197.142:49500] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.idwic.com"] [uri "/.env.production"] [unique_id "apawDEzo3XFLOK5zIgB-vQAAAFM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 09:38:54
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.123.197.142 (142.197.123.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.123.197.142 (142.197.123.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 05:38:48.691398 2026] [security2:error] [pid 31850:tid 31850] [client 34.123.197.142:45760] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "softwarezz.net"] [uri "/.env.prod"] [unique_id "apadKLI0W1bPscA95pIg-QAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฒ๐พ
Rizzy
2026-09-01 08:18:05
(14 hours ago)
Multiple WAF Violations
Brute-Force
Web App Attack
๐ซ๐ท
spot
2026-09-01 07:57:41
(14 hours ago)
34.123.197.142 - - [01/Sep/2026:08:57:40 +0100] "GET /wp-config.php.bak HTTP/1.1" 404 4657 "-" "crus ...
show more
34.123.197.142 - - [01/Sep/2026:08:57:40 +0100] "GET /wp-config.php.bak HTTP/1.1" 404 4657 "-" "crusader-worker/1.0"
...
show less
Web App Attack
Hacking
๐ณ๐ฑ
e.fierstra
2026-09-01 07:14:32
(15 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
Anonymous
2026-09-01 05:32:49
(17 hours ago)
Banned by Fail2Ban on server
Web App Attack
๐ท๐บ
DZBOT
2026-09-01 05:13:47
(17 hours ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 05:08:45
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.123.197.142 (142.197.123.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.123.197.142 (142.197.123.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 01:08:39.167448 2026] [security2:error] [pid 11262:tid 11283] [client 34.123.197.142:54810] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.dba.center"] [uri "/.env.example"] [unique_id "apZd1571TID858fczemVRAAAAU4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-01 04:16:42
(18 hours ago)
Fuzzing/Looking for credentials files.
Brute-Force
Web App Attack
Anonymous
2026-09-01 04:03:31
(18 hours ago)
[ssd1.kdns.gr] httpd-config-scan: sites=www.lifeenlighteningproject.com; logs=/var/log/httpd/domains ...
show more
[ssd1.kdns.gr] httpd-config-scan: sites=www.lifeenlighteningproject.com; logs=/var/log/httpd/domains/lifeenlighteningproject.com.log; samples=/.env.bak | /.env.local | /.env.dev
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 03:54:42
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.123.197.142 (142.197.123.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.123.197.142 (142.197.123.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 23:54:35.587832 2026] [security2:error] [pid 22380:tid 22380] [client 34.123.197.142:60610] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "knorgmusic.org"] [uri "/.env"] [unique_id "apZMew7gcqK2c6kXvHQuZwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack