๐ณ๐ฑ
homeshowdomain.nl
2026-05-28 22:04:14
(3 weeks ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-05-27.
show less
Web App Attack
SSH
Hacking
๐จ๐ญ
4server
2026-05-28 01:11:39
(3 weeks ago)
[ThuMay2803:11:33.6914932026][security2:error][pid1761963:tid1762160][client86.38.236.79:0]ModSecuri ...
show more
[ThuMay2803:11:33.6914932026][security2:error][pid1761963:tid1762160][client86.38.236.79:0]ModSecurity:Accessdeniedwithcode403\(phase2\).Patternmatch\"\\\\\\\\.sql\(\?:\$\|\\\\\\\\.\(\?:zip\|\(\?:t\|r\)ar\\\\\\\\.\?g\?z\?\|t\?\(\?:g\|b\)z\|old\|ba\(\?:k\|c\)u\?p\?\)\$\)\"atREQUEST_FILENAME.[file\"/etc/apache2/conf.d/modsec_rules/10_asl_rules.conf\"][line\"1183\"][id\"350590\"][rev\"3\"][msg\"Atomicorp.comWAFRules:AttackBlocked-Dataleakage-attempttoaccessrawSQLfiles\(disablethisruleifyourequireaccesstofilesthatendwith.sql\)\"][severity\"CRITICAL\"][hostname\"aid-web.ch.81-17-25-250.cpanel.site\"][uri\"/backup.sql.gz\"][unique_id\"aheWRXzcE-S9SIJQA3MfwwAAAI0\"]
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-28 00:17:52
(3 weeks ago)
(mod_security) mod_security (id:210730) triggered by 86.38.236.79 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 86.38.236.79 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 27 20:17:47.958965 2026] [security2:error] [pid 4209:tid 4209] [client 86.38.236.79:57575] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||curriergallery.com|F|2"] [data ".key"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "curriergallery.com"] [uri "/config/master.key"] [unique_id "aheJq3eqCsywaZw0aC3YrgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-27 02:56:57
(3 weeks ago)
(mod_security) mod_security (id:210730) triggered by 86.38.236.79 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 86.38.236.79 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 26 22:56:52.405904 2026] [security2:error] [pid 32720:tid 32728] [client 86.38.236.79:55933] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||riversideturners.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "riversideturners.com"] [uri "/db_backup.sql"] [unique_id "ahZddO9a8T_ik7ANGI1xHAAAAMQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
Vano Ganzzz
2026-05-27 01:07:21
(3 weeks ago)
Triggered Cloudflare WAF (firewallCustom) from GB.
Action taken: BLOCK
ASN: 210906 (UAB "Bite Lietuv ...
show more
Triggered Cloudflare WAF (firewallCustom) from GB.
Action taken: BLOCK
ASN: 210906 (UAB "Bite Lietuva")
Protocol: HTTP/1.1 (HEAD method)
Endpoint: /.kube/config
Timestamp: 2026-05-27T01:07:21Z
Ray ID: a0211f4e5a4f789f
UA: Mozilla/5.0 (Linux; Android 14; Pixel 8) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/135.0.6422.113 Mobile Safari/537.36
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-05-27 00:22:46
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 86.38.236.79 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 86.38.236.79 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 26 20:22:17.136694 2026] [security2:error] [pid 11081:tid 11081] [client 86.38.236.79:46997] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.old" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.allisonbtaylor.ingberinteriors.com"] [uri "/wp-config.old"] [unique_id "ahY5Ob0d4uDxlTv1ai-sJwAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-26 18:13:50
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 86.38.236.79 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 86.38.236.79 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 26 14:13:28.241309 2026] [security2:error] [pid 7774:tid 7774] [client 86.38.236.79:40323] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "progresstraining.info"] [uri "/.env.save"] [unique_id "ahXiyO5mjups_XiNeMXzmgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
VHosting
2026-02-24 02:25:04
(3 months ago)
Detected WordPress attack from 4 different servers
Brute-Force
Web App Attack