๐ณ๐ฑ
homeshowdomain.nl
2026-05-28 22:03:30
(1 week ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-05-27.
show less
Web App Attack
SSH
Hacking
๐บ๐ธ
TPI-Abuse
2026-05-27 23:39:56
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 82.22.235.173 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 82.22.235.173 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 27 19:39:49.179979 2026] [security2:error] [pid 20455:tid 20455] [client 82.22.235.173:35381] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.old" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "lookatpriscoolwebsite.click"] [uri "/wp-config.old"] [unique_id "aheAxZvGWcb5Op75fyC8YAAAAA8"], referer: https://www.google.com/search?q=lookatpriscoolwebsite.click
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-27 18:52:44
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 82.22.235.173 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 82.22.235.173 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 27 14:52:36.016671 2026] [security2:error] [pid 25306:tid 25306] [client 82.22.235.173:32795] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.bdtv.tremulant.com"] [uri "/.env.dev"] [unique_id "ahc9dI9PzIhzVZMhQPLsCwAAAEY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-27 17:54:30
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 82.22.235.173 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 82.22.235.173 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 27 13:54:22.796028 2026] [security2:error] [pid 19088:tid 19111] [client 82.22.235.173:41861] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "aafm.org"] [uri "/.env.local"] [unique_id "ahcvzmVS84MIgvmZSEmjMQAAANU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
big-cloud.nl
2026-05-27 17:10:11
(1 week ago)
Try to access /.env
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-27 14:42:22
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 82.22.235.173 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 82.22.235.173 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 27 10:42:15.634537 2026] [security2:error] [pid 20868:tid 20868] [client 82.22.235.173:37667] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.agirlwithaguitar.misscharlottemusic.com"] [uri "/.env.bak"] [unique_id "ahcCx27jCe1gLdnJHJtwoAAAAAs"], referer: https://www.google.com/search?q=www.agirlwithaguitar.misscharlottemusic.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-27 00:27:28
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 82.22.235.173 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 82.22.235.173 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 26 20:27:24.121003 2026] [security2:error] [pid 24062:tid 24062] [client 82.22.235.173:35693] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.athletestandard.com"] [uri "/.env.backup"] [unique_id "ahY6bGuEge6GuL7BsR0ikAAAAA4"], referer: https://www.google.com/search?q=autodiscover.athletestandard.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-05-26 21:59:05
(1 week ago)
Auto-ban: >3000 req/min op 2026-05-26
Web App Attack
SSH
Hacking
๐บ๐ธ
TPI-Abuse
2026-05-26 17:57:31
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 82.22.235.173 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 82.22.235.173 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 26 13:57:08.065533 2026] [security2:error] [pid 25551:tid 25551] [client 82.22.235.173:53811] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||www.l3prime.systemcapacityoptimization.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.l3prime.systemcapacityoptimization.com"] [uri "/backup.sql"] [unique_id "ahXe9PSBoj4GScsttcXR0AAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
tinect
2026-05-11 19:09:43
(3 weeks ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-bad-user-agent
Web App Attack
Bad Web Bot
๐จ๐ญ
backslash
2025-11-14 22:30:15
(6 months ago)
block ruleset CC531825F9395F9A07FB06C1247C46770A2690F8
Bad Web Bot