๐บ๐ธ
mnsf
2026-05-29 10:06:15
(1 week ago)
Abuse Detected (1)
Brute-Force
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-05-28 21:59:45
(1 week ago)
Auto-ban: >3000 req/min op 2026-05-28
Web App Attack
SSH
Hacking
๐ง๐ช
sid3windr
2026-05-28 03:55:16
(1 week ago)
HEAD /config/local.json (Tarpitted for , wasted 120B)
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-05-27 22:01:09
(1 week ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-05-26.
show less
Web App Attack
SSH
Hacking
๐บ๐ธ
TPI-Abuse
2026-05-27 17:50:37
(1 week ago)
(mod_security) mod_security (id:949110) triggered by 82.26.208.169 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:949110) triggered by 82.26.208.169 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 27 13:50:28.667008 2026] [security2:error] [pid 16204:tid 16204] [client 82.26.208.169:56665] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "www.motonaonaobookings.hamiltonbookings.com"] [uri "/wp-config.php"] [unique_id "ahcu5P4mC8Ov02mrVXBM0AAAAAM"], referer: https://www.google.com/search?q=www.motonaonaobookings.hamiltonbookings.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-27 13:26:12
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 82.26.208.169 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 82.26.208.169 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 27 09:26:05.906433 2026] [security2:error] [pid 14050:tid 14050] [client 82.26.208.169:41785] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.mufasa.borzois.com"] [uri "/.env.development.local"] [unique_id "ahbw7VoCxl5s140DN-VM3wAAACQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-27 11:54:43
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 82.26.208.169 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 82.26.208.169 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 27 07:54:35.442326 2026] [security2:error] [pid 16569:tid 16569] [client 82.26.208.169:34085] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.miranda-race-walks.com"] [uri "/.env.save"] [unique_id "ahbbexFObm2eIRnLzjng7gAAAAg"], referer: https://www.google.com/search?q=www.miranda-race-walks.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-27 00:58:34
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 82.26.208.169 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 82.26.208.169 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 26 20:58:11.046449 2026] [security2:error] [pid 9695:tid 9695] [client 82.26.208.169:52169] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "partybusesflint.com"] [uri "/wp-config.php.save"] [unique_id "ahZBo1-vAwJV5ipCJFEtuwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-05-27 00:58:03
(1 week ago)
(caddyscan) Scanner path probe from 82.26.208.169 (US/United States/-): 5 in the last 3600 secs; Por ...
show more
(caddyscan) Scanner path probe from 82.26.208.169 (US/United States/-): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 0 82.26.208.169 - - [27/May/2026:00:58:00 +0000] "HEAD /.env.vercel HTTP/1.1"
[REDACTED] 200 0 82.26.208.169 - - [27/May/2026:00:58:00 +0000] "HEAD /.env.backup HTTP/1.1"
[REDACTED] 200 0 82.26.208.169 - - [27/May/2026:00:58:00 +0000] "HEAD /.env.development.local HTTP/1.1"
[REDACTED] 200 0 82.26.208.169 - - [27/May/2026:00:58:01 +0000] "HEAD /wp-config.php.swp HTTP/1.1"
[REDACTED] 200 0 82.26.208.169 - - [27/May/2026:00:58:01 +0000] "HEAD /.env.local HTTP/1.1"
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-05-27 00:21:03
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 82.26.208.169 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 82.26.208.169 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 26 20:20:58.214671 2026] [security2:error] [pid 23242:tid 23242] [client 82.26.208.169:58617] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "theprideproject.net"] [uri "/wp-config.php.swp"] [unique_id "ahY46vYXrkrlFSF95zy25QAAABU"], referer: https://www.google.com/search?q=theprideproject.net
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-26 23:51:32
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 82.26.208.169 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 82.26.208.169 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 26 19:51:04.798998 2026] [security2:error] [pid 27976:tid 27976] [client 82.26.208.169:36415] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.asfmglobal.com"] [uri "/wp-config.php~"] [unique_id "ahYx6Cim4S5MvO1eVPqiqgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-26 18:15:32
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 82.26.208.169 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 82.26.208.169 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 26 14:15:00.186727 2026] [security2:error] [pid 12457:tid 12457] [client 82.26.208.169:39421] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.elianabeam.com.amybeam.com"] [uri "/.env.dusk.local"] [unique_id "ahXjJCRdnREIgefE0nWTrAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-26 17:57:23
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 82.26.208.169 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 82.26.208.169 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 26 13:57:05.599353 2026] [security2:error] [pid 28458:tid 28458] [client 82.26.208.169:36973] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.britanniapilates.com.systemcapacityoptimization.com"] [uri "/.env"] [unique_id "ahXe8V4a4Dop5gVkw6r85QAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
inlink.ltd
2026-05-26 17:20:23
(1 week ago)
dot file probe
Web App Attack
๐จ๐ญ
4server
2026-05-26 17:05:59
(1 week ago)
[TueMay2619:05:53.0805852026][security2:error][pid2832562:tid2832735][client82.26.208.169:0]ModSecur ...
show more
[TueMay2619:05:53.0805852026][security2:error][pid2832562:tid2832735][client82.26.208.169:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\".env\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"364\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"benvenutialfood.org\"][uri\"/.env.save\"][unique_id\"ahXS8UM_3Lw1w5tfiBPK1gAAAIQ\"]
show less
Hacking
Web App Attack