🇮🇩
sockominfo
2026-09-06 04:00:34
(3 hours ago)
Reported by TangerangKota-CSIRT. Status: MALICIOUS
Hacking
Email Spam
🇺🇸
TPI-Abuse
2026-09-06 03:52:04
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 8.229.121.161 (161.121.229.8.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 8.229.121.161 (161.121.229.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 23:51:57.722104 2026] [security2:error] [pid 2614:tid 2614] [client 8.229.121.161:54464] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.primelb.com"] [uri "/.env"] [unique_id "apzjXQXt-Ve1r58ylelXjQAAAHw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-06 03:36:40
(3 hours ago)
(mod_security) mod_security triggered on hostname [redacted])
SQL Injection
🇩🇪
tentwentyfour
2026-09-06 02:58:05
(4 hours ago)
Blocked for probing for sensitive web application components
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 02:57:55
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 8.229.121.161 (161.121.229.8.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 8.229.121.161 (161.121.229.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 22:57:47.581771 2026] [security2:error] [pid 32548:tid 32548] [client 8.229.121.161:54682] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.brennanarchitecture.com"] [uri "/.env.old"] [unique_id "apzWq_-gHGqtcJpjefhOIwAAAJU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 02:10:10
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 8.229.121.161 (161.121.229.8.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 8.229.121.161 (161.121.229.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 22:10:04.647890 2026] [security2:error] [pid 15969:tid 16004] [client 8.229.121.161:57540] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "seguroslugo.soluciona.biz"] [uri "/.env.old"] [unique_id "apzLfJ6NkPE_6xMYHKO6iwAAAVY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
mnsf
2026-09-06 02:05:26
(5 hours ago)
Scanning/Probing (20)
Brute-Force
Web App Attack
🇳🇱
e.fierstra
2026-09-06 01:44:49
(5 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
🇳🇱
WeCloudit-Anti-Abuse
2026-09-06 01:34:37
(5 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
Anonymous
2026-09-06 01:10:03
(5 hours ago)
suspicious request in access.log
Web App Attack
🇨🇭
4server
2026-09-06 00:47:10
(6 hours ago)
[SunSep0602:47:05.2318482026][security2:error][pid2480174:tid2480629][client8.229.121.161:0]ModSecur ...
show more
[SunSep0602:47:05.2318482026][security2:error][pid2480174:tid2480629][client8.229.121.161:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\".env\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"610\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"cpanel.inserzioniticino.ch\"][uri\"/.env.dev\"][unique_id\"apy4Cd9V4vEhvs_z0g5bAQAAAQI\"]
show less
Hacking
Web App Attack
🇩🇪
ddobko
2026-09-06 00:30:37
(6 hours ago)
Bad Web Bot
Web App Attack
🇫🇷
✨
2026-09-06 00:17:12
(6 hours ago)
Domain : inchesstudio.co.uk
Rule : hack
2026-09-06 00:15:10 ***hidden-privacy*** GET /wp-config.php. ...
show more
Domain : inchesstudio.co.uk
Rule : hack
2026-09-06 00:15:10 ***hidden-privacy*** GET /wp-config.php.bak - 443 - 8.229.121.161 HTTP/1.1 crusader-worker/1.0 - inchesstudio.co.uk 403 0 0 1446 107 284 - -
show less
Hacking
SQL Injection
Brute-Force
Anonymous
2026-09-06 00:09:46
(7 hours ago)
[da.kdns.gr] httpd-config-scan: sites=www.panetsos.gr; logs=/var/log/httpd/domains/panetsos.gr.log; ...
show more
[da.kdns.gr] httpd-config-scan: sites=www.panetsos.gr; logs=/var/log/httpd/domains/panetsos.gr.log; samples=/.env.local | /.env.backup | /.env.dev
show less
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 23:41:18
(7 hours ago)
(mod_security) mod_security (id:210730) triggered by 8.229.121.161 (161.121.229.8.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 8.229.121.161 (161.121.229.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 19:41:15.252275 2026] [security2:error] [pid 23696:tid 23716] [client 8.229.121.161:44906] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||theyogicat.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "theyogicat.com"] [uri "/database.sql"] [unique_id "apyom0qgQ3jqkQdLLG7cIAAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack