๐ซ๐ท
SpaceHost-Server
2026-07-17 22:34:50
(2 days ago)
Brute-Force
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-07-17 22:03:48
(2 days ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-07-16.
show less
Web App Attack
SSH
Hacking
๐บ๐ธ
TPI-Abuse
2026-07-17 12:52:47
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 47.83.180.96 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 47.83.180.96 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 17 08:52:41.921671 2026] [security2:error] [pid 3951:tid 3951] [client 47.83.180.96:39384] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "tupansetc.com"] [uri "/.env"] [unique_id "alolmSVBqvIrP9eHmp9BSwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Tilellit.PRO
2026-07-17 12:47:27
(2 days ago)
Malicious web traffic detected by CrowdSec
Hacking
๐บ๐ธ
TPI-Abuse
2026-07-17 12:35:55
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 47.83.180.96 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 47.83.180.96 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 17 08:35:48.111031 2026] [security2:error] [pid 6478:tid 6478] [client 47.83.180.96:58880] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "automationmp.com.cgautomatizacion.com"] [uri "/.env.local"] [unique_id "alohpLy8HkIuV12WG5T8kgAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-17 10:45:12
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 47.83.180.96 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 47.83.180.96 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 17 06:45:04.292601 2026] [security2:error] [pid 11922:tid 11922] [client 47.83.180.96:56258] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "advantagebrandservices.advantageinvestigation.com"] [uri "/.env.test"] [unique_id "aloHsAvBd2ZkmUgrK2D-LAAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
largo-it.net
2026-07-17 10:30:41
(2 days ago)
Jul 17 12:30:32 vps-9f3cdc33 haproxy[1195832]: 47.83.180.96:56356 [17/Jul/2026:12:30:32.092] www_fro ...
show more
Jul 17 12:30:32 vps-9f3cdc33 haproxy[1195832]: 47.83.180.96:56356 [17/Jul/2026:12:30:32.092] www_frontend~ finance_cluster/finance1_test1_https 0/0/11/343/354 404 3252 - - ---- 72/21/0/0/0 0/0 "GET /google-cloud-key.json HTTP/1.1"
Jul 17 12:30:35 vps-9f3cdc33 haproxy[1195832]: 47.83.180.96:56356 [17/Jul/2026:12:30:35.216] www_frontend~ finance_cluster/finance1_test1_https 0/0/10/330/340 404 3252 - - ---- 73/22/0/0/0 0/0 "GET /firebase-adminsdk.json HTTP/1.1"
Jul 17 12:30:36 vps-9f3cdc33 haproxy[1195832]: 47.83.180.96:56356 [17/Jul/2026:12:30:36.006] www_frontend~ finance_cluster/finance1_test1_https 0/0/11/326/337 404 3252 - - ---- 72/21/0/0/0 0/0 "GET /firebase-credentials.json HTTP/1.1"
Jul 17 12:30:37 vps-9f3cdc33 haproxy[1195832]: 47.83.180.96:56356 [17/Jul/2026:12:30:37.097] www_frontend~ finance_cluster/finance1_test1_https 0/0/11/329/340 404 3252 - - ---- 75/24/0/0/0 0/0 "GET /root/.config/gcloud/application_default_credentials.json HTTP/1.1"
Jul 17 12:30:38 vps-9f3cdc33 haproxy
...
show less
Hacking
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob
2026-07-17 10:11:07
(2 days ago)
CrowdSec: crowdsecurity/http-probing | req: /home/node/.config/gcloud/application_default_credential ...
show more
CrowdSec: crowdsecurity/http-probing | req: /home/node/.config/gcloud/application_default_credentials.json | 11 distinct paths | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/136.0.0.0 Safari/537.36 (Silvy X Ran; +https://silvyxran.love;
show less
Port Scan
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-17 09:09:00
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 47.83.180.96 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 47.83.180.96 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 17 05:08:56.041378 2026] [security2:error] [pid 535569:tid 535569] [client 47.83.180.96:57948] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.knowledgepreservationalliance.theknowledgemaster.com"] [uri "/.env"] [unique_id "alnxKHSAWmLHhhAgW2w-JwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
breubit
2026-07-17 09:05:30
(2 days ago)
47.83.180.96 - - [17/Jul/2026:11:05:29 +0200] "GET /wp-config.php.txt HTTP/1.1" 404 4589 "-" "Mozill ...
show more
47.83.180.96 - - [17/Jul/2026:11:05:29 +0200] "GET /wp-config.php.txt HTTP/1.1" 404 4589 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/136.0.0.0 Safari/537.36 (Silvy X Ran; +https://silvyxran.love; +https://silver.inc)"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-17 08:19:48
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 47.83.180.96 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 47.83.180.96 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 17 04:19:43.683606 2026] [security2:error] [pid 15801:tid 15801] [client 47.83.180.96:59200] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "icoinedthewordironesty.com"] [uri "/.env"] [unique_id "alnln4mrtZxn14Pzr1gWyAAAACU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
gadix
2026-07-17 08:03:58
(2 days ago)
[17/Jul/2026:10:03:52.608055 +0200] alnh6FOYg_2Dy4WZrGVDWAAAAAg 47.83.180.96 33050 127.0.0.1 7081
[1 ...
show more
[17/Jul/2026:10:03:52.608055 +0200] alnh6FOYg_2Dy4WZrGVDWAAAAAg 47.83.180.96 33050 127.0.0.1 7081
[17/Jul/2026:10:03:55.546921 +0200] alnh64R-mj4sj7p2cldF-wAAAAE 47.83.180.96 33064 127.0.0.1 7081
[17/Jul/2026:10:03:58.558657 +0200] alnh7uDhUQTd2XTVQnTIvAAAAAo 47.83.180.96 33080 127.0.0.1 7081
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-17 07:49:02
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 47.83.180.96 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 47.83.180.96 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 17 03:48:56.510571 2026] [security2:error] [pid 443999:tid 443999] [client 47.83.180.96:50936] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "clinicacero.com"] [uri "/.env.development.local"] [unique_id "alneaPM6o5N-rC7lEjDKhQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-07-17 07:31:36
(2 days ago)
Excessive multi-domain requests
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-07-17 04:18:26
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 47.83.180.96 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 47.83.180.96 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 17 00:18:21.034333 2026] [security2:error] [pid 187909:tid 187914] [client 47.83.180.96:55872] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.healingwithtouch.com.captainpurpleproductions.com"] [uri "/.env"] [unique_id "almtDQD_OulB9eMmxEK4zQAAAII"]
show less
Brute-Force
Bad Web Bot
Web App Attack