๐ณ๐ฑ
homeshowdomain.nl
2026-09-17 22:06:02
(11 hours ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-09-16.
show less
Web App Attack
SSH
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-16 08:52:44
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 76.13.37.253 (srv1327841.hstgr.cloud): 1 in the ...
show more
(mod_security) mod_security (id:210492) triggered by 76.13.37.253 (srv1327841.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 04:52:38.294037 2026] [security2:error] [pid 24090:tid 24207] [client 76.13.37.253:51268] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.jpdesign.us.jean-paullederer.com"] [uri "/.env.old"] [unique_id "aqpY1rC6F-7E3welQbb9fgAAAgY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฟ๐ฆ
conure.sh
2026-09-16 01:33:05
(2 days ago)
csagent: score 20.0: secrets grab x2; 2 domain(s) in 0s
Web App Attack
Anonymous
2026-09-15 17:28:41
(2 days ago)
(mod_security) mod_security triggered on hostname [redacted])
SQL Injection
๐บ๐ธ
TPI-Abuse
2026-09-15 16:49:50
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 76.13.37.253 (srv1327841.hstgr.cloud): 1 in the ...
show more
(mod_security) mod_security (id:210492) triggered by 76.13.37.253 (srv1327841.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 12:49:43.554744 2026] [security2:error] [pid 449:tid 449] [client 76.13.37.253:42690] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "activethinkers.net"] [uri "/wp-config.php.orig"] [unique_id "aql3J769VtR5AID7ntnKrQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
Origon
2026-09-15 16:45:27
(2 days ago)
http-sensitive-files - IP: 76.13.37.253 - time="2026-09-15T18:45:27+02:00" level=info msg="(555f66b ...
show more
http-sensitive-files - IP: 76.13.37.253 - time="2026-09-15T18:45:27+02:00" level=info msg="(555f66b4f6a74558bc11e3f93469658es8App0Mcc0TKEeje/crowdsec) crowdsecurity/http-sensitive-files by ip 76.13.37.253 (LT/47583) : 4h ban on Ip 76.13.37.253" module=db
show less
Web App Attack
๐ฎ๐น
VHosting
2026-09-15 08:00:06
(3 days ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 03:52:19
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 76.13.37.253 (srv1327841.hstgr.cloud): 1 in the ...
show more
(mod_security) mod_security (id:210492) triggered by 76.13.37.253 (srv1327841.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 14 23:52:13.639613 2026] [security2:error] [pid 28731:tid 28731] [client 76.13.37.253:35254] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ironsightsarmory.com"] [uri "/wp-config.php.orig"] [unique_id "aqjA7R33iPvL5r5VXWtyZgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 00:41:39
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 76.13.37.253 (srv1327841.hstgr.cloud): 1 in the ...
show more
(mod_security) mod_security (id:210492) triggered by 76.13.37.253 (srv1327841.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 14 20:41:33.204987 2026] [security2:error] [pid 21887:tid 21887] [client 76.13.37.253:59438] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "asdfwordpro.com"] [uri "/.env.txt"] [unique_id "aqiUPfpfFRECUAas5w9-ggAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack