π³π±
homeshowdomain.nl
2026-09-02 22:00:38
(6 hours ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-09-01.
show less
Web App Attack
SSH
Hacking
πΊπΈ
TPI-Abuse
2026-09-01 14:02:01
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.48.91.210 (210.91.48.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.48.91.210 (210.91.48.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 10:01:57.354958 2026] [security2:error] [pid 26925:tid 26925] [client 34.48.91.210:47348] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.tckgbookkeeping.biz"] [uri "/.env.bak"] [unique_id "apba1WpJemzB5gXzKVp7rAAAACw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-01 13:46:51
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.48.91.210 (210.91.48.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.48.91.210 (210.91.48.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 09:46:47.384442 2026] [security2:error] [pid 10613:tid 10613] [client 34.48.91.210:48576] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.toxicwater.com"] [uri "/.env.prod"] [unique_id "apbXRyrPTnFM7LLNAubvvwAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π±π»
garmtech.com
2026-09-01 11:00:53
(1 day ago)
Attempted access to sensitive endpoint (/.env.production) detected. Automated scan or unauthorized p ...
show more
Attempted access to sensitive endpoint (/.env.production) detected. Automated scan or unauthorized probing.
show less
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-01 10:57:26
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.48.91.210 (210.91.48.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.48.91.210 (210.91.48.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 06:57:20.054612 2026] [security2:error] [pid 1881:tid 1881] [client 34.48.91.210:42176] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.dymesich.com"] [uri "/.env.local"] [unique_id "apavkL8vPcpiam5MhmNpawAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-01 10:26:32
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.48.91.210 (210.91.48.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.48.91.210 (210.91.48.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 06:26:27.641408 2026] [security2:error] [pid 5598:tid 5598] [client 34.48.91.210:36348] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "adorningmetal.com"] [uri "/.env.example"] [unique_id "apaoU1zdDEP5y_WPItcNEgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π«π·
Octopuce
2026-09-01 10:15:21
(1 day ago)
Aggressive web search of vulnerable pages: /wp-config.php.bak /.env.production /.env.save /.env.exam ...
show more
Aggressive web search of vulnerable pages: /wp-config.php.bak /.env.production /.env.save /.env.example /.env.dev /.env.backup /.env.old /.env. ...
show less
Web App Attack
π©πͺ
FD-IX
2026-09-01 09:37:31
(1 day ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
π©πͺ
raph
2026-09-01 08:53:51
(1 day ago)
[Wordpress] crawler /wp-admin/*, /wp-content/*, etc.
Bad Web Bot
Web App Attack
Anonymous
2026-09-01 08:26:13
(1 day ago)
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-01 07:55:59
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.48.91.210 (210.91.48.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.48.91.210 (210.91.48.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 03:55:50.940347 2026] [security2:error] [pid 11305:tid 11305] [client 34.48.91.210:56314] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "salinabible.org"] [uri "/.env.dev"] [unique_id "apaFBsRsxsYfu9YGuAQqsgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-01 07:34:51
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.48.91.210 (210.91.48.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.48.91.210 (210.91.48.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 03:34:44.194007 2026] [security2:error] [pid 9798:tid 9798] [client 34.48.91.210:50762] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "yaseminomer.com.kircali.net"] [uri "/.env.save"] [unique_id "apaAFOwCllULuYgX2esOGQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπ¦
URAN Publishing Service
2026-09-01 07:16:46
(1 day ago)
[01/Sep/2026:10:16:46 +0300] -- 34.48.91.210 Ban reason: Scanner [CMS_GENERIC] | Request: GET /wp-co ...
show more
[01/Sep/2026:10:16:46 +0300] -- 34.48.91.210 Ban reason: Scanner [CMS_GENERIC] | Request: GET /wp-config.php.swp HTTP/1.1
show less
Bad Web Bot
Web App Attack
π΅π±
Budyn
2026-09-01 06:42:10
(1 day ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scan ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scanner. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: teddypot.site | URI: /_ignition/health-check | UA: crusader-worker/1.0 | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-01 06:38:04
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.48.91.210 (210.91.48.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.48.91.210 (210.91.48.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 02:37:58.843630 2026] [security2:error] [pid 27191:tid 27191] [client 34.48.91.210:48792] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "test.hawkinsenterprise.com"] [uri "/.env.example"] [unique_id "apZyxvgqvhxwuIGkxLjb_AAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack