๐ณ๐ฑ
homeshowdomain.nl
2026-08-23 21:59:03
(1 hour ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-08-22.
show less
Web App Attack
SSH
Hacking
๐ฉ๐ช
Bedios GmbH
2026-08-23 20:41:18
(2 hours ago)
Login credentials theft attempt
Hacking
๐บ๐ธ
TPI-Abuse
2026-08-23 17:13:49
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 45.55.37.165 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 45.55.37.165 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 23 13:13:42.808609 2026] [security2:error] [pid 1541:tid 1541] [client 45.55.37.165:47618] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "andy-blakk.org"] [uri "/.env"] [unique_id "aosqRsEs1Dr8MnIvKo2HhwAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-23 16:20:59
(7 hours ago)
45.55.37.165 - - [23/Aug/2026:16:20:56 +0000] "GET /.env HTTP/1.1" 404 196 "-" "Mozilla/5.0 (Windows ...
show more
45.55.37.165 - - [23/Aug/2026:16:20:56 +0000] "GET /.env HTTP/1.1" 404 196 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36"
45.55.37.165 - - [23/Aug/2026:16:20:58 +0000] "GET /_profiler/phpinfo HTTP/1.1" 404 196 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-23 14:00:33
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 45.55.37.165 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 45.55.37.165 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 23 10:00:25.734052 2026] [security2:error] [pid 6398:tid 6398] [client 45.55.37.165:52228] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "anamericanabroad.com"] [uri "/.env"] [unique_id "aor8-SQa3jgniWQNUVXkTAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-08-23 10:59:53
(12 hours ago)
[23/Aug/2026:13:59:52 +0300] -- 45.55.37.165 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET /. ...
show more
[23/Aug/2026:13:59:52 +0300] -- 45.55.37.165 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET /.env HTTP/1.1
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-23 05:49:50
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 45.55.37.165 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 45.55.37.165 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 23 01:49:45.522087 2026] [security2:error] [pid 10372:tid 10372] [client 45.55.37.165:42686] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "amazingthailand.net"] [uri "/.env"] [unique_id "aoqJ-UJe4OPPswq9TgvQ-wAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
mail.avx.gr
2026-08-23 05:35:03
(17 hours ago)
Plesk Fail2Ban jail: Plesk-Web-Exploits. Evidence: 45.55.37.165 - - [23/Aug/2026:08:35:03 +0300] "GE ...
show more
Plesk Fail2Ban jail: Plesk-Web-Exploits. Evidence: 45.55.37.165 - - [23/Aug/2026:08:35:03 +0300] "GET /.env HTTP/1.1" 404 808 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36"
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-23 02:46:28
(20 hours ago)
(mod_security) mod_security (id:210492) triggered by 45.55.37.165 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 45.55.37.165 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 22:46:21.152523 2026] [security2:error] [pid 24489:tid 24489] [client 45.55.37.165:55882] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "alsetsystems.com"] [uri "/.env"] [unique_id "aope_XqTTwrFSc19Sj8HxgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-23 02:13:02
(21 hours ago)
(mod_security) mod_security (id:210492) triggered by 45.55.37.165 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 45.55.37.165 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 22:12:58.289160 2026] [security2:error] [pid 9745:tid 9745] [client 45.55.37.165:41358] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "alpinaproperties.gescosigns.com"] [uri "/.env"] [unique_id "aopXKnVwN7ewaO7CTbZcGwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-23 00:56:48
(22 hours ago)
(mod_security) mod_security (id:210492) triggered by 45.55.37.165 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 45.55.37.165 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 20:56:43.454210 2026] [security2:error] [pid 3093:tid 3093] [client 45.55.37.165:55778] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "aifactoid.com"] [uri "/.env"] [unique_id "aopFS100-f1o_srG2gRYlgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-08-22 22:03:05
(1 day ago)
Auto-ban: >3000 req/min op 2026-08-22
Web App Attack
SSH
Hacking
Anonymous
2026-08-22 20:25:02
(1 day ago)
suspicious request in access.log
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-22 20:12:25
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 45.55.37.165 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 45.55.37.165 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 16:12:19.727093 2026] [security2:error] [pid 21328:tid 21328] [client 45.55.37.165:40152] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "agroeurocommodities.com.asiancommoditiescorporation.com"] [uri "/.env"] [unique_id "aooCo5J2hy_eKH8v5awYagAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-22 18:54:54
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 45.55.37.165 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 45.55.37.165 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 14:54:50.688830 2026] [security2:error] [pid 15415:tid 15415] [client 45.55.37.165:50982] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "agkgt.org.ctsaagt.org"] [uri "/.env"] [unique_id "aonweriGJOuzol0Ciab1SAAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack