๐ฉ๐ช
LRob
2026-09-25 09:52:50
(1 day ago)
This address is looking for secret files on our sites: .git directories, .env files, credential and ...
show more
This address is looking for secret files on our sites: .git directories, .env files, credential and configuration files, database dumps, backups. This is a targeted search for credentials to break into the sites, blocked at the first request. Please check the machine behind it for an attack tool or malware. | method: GET | path: /.env | 2026-09-25 09:52 UTC
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-25 08:09:38
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 89.46.105.166 (host166-105-46-89.serverdedicati ...
show more
(mod_security) mod_security (id:210492) triggered by 89.46.105.166 (host166-105-46-89.serverdedicati.aruba.it): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 25 04:09:31.189691 2026] [security2:error] [pid 15930:tid 15930] [client 89.46.105.166:29594] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "trailofcrumbs.com"] [uri "/.env"] [unique_id "arYsOyYZdxMOuq_TyJnI1gAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-25 06:49:55
(1 day ago)
(mod_security) mod_security (id:949110) triggered by 89.46.105.166 (host166-105-46-89.serverdedicati ...
show more
(mod_security) mod_security (id:949110) triggered by 89.46.105.166 (host166-105-46-89.serverdedicati.aruba.it): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 25 02:49:48.528875 2026] [security2:error] [pid 12220:tid 12220] [client 89.46.105.166:23582] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "greenpowerkorea.com"] [uri "/.env"] [unique_id "arYZjGnOvP4hHiT2bPdjkgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-25 06:08:21
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 89.46.105.166 (host166-105-46-89.serverdedicati ...
show more
(mod_security) mod_security (id:210492) triggered by 89.46.105.166 (host166-105-46-89.serverdedicati.aruba.it): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 25 02:08:13.764784 2026] [security2:error] [pid 27863:tid 27863] [client 89.46.105.166:20928] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mccarterestates.com"] [uri "/.env"] [unique_id "arYPzQ7ut9Qc7XiGP7dyGwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 19:47:47
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 89.46.105.166 (host166-105-46-89.serverdedicati ...
show more
(mod_security) mod_security (id:210492) triggered by 89.46.105.166 (host166-105-46-89.serverdedicati.aruba.it): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 15:47:42.711619 2026] [security2:error] [pid 23080:tid 23080] [client 89.46.105.166:22638] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "fatcavestudios.com"] [uri "/wp-config.php.bak"] [unique_id "arLbXhvL32jIS4xM8cyzMwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 19:25:20
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 89.46.105.166 (host166-105-46-89.serverdedicati ...
show more
(mod_security) mod_security (id:210492) triggered by 89.46.105.166 (host166-105-46-89.serverdedicati.aruba.it): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 15:25:12.468523 2026] [security2:error] [pid 29171:tid 29171] [client 89.46.105.166:36580] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "alissacaputo.com"] [uri "/wp-config.php.bak"] [unique_id "arLWGKo8shoMAM1QMO6WNQAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 18:15:27
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 89.46.105.166 (host166-105-46-89.serverdedicati ...
show more
(mod_security) mod_security (id:210492) triggered by 89.46.105.166 (host166-105-46-89.serverdedicati.aruba.it): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 14:15:21.056972 2026] [security2:error] [pid 14653:tid 14653] [client 89.46.105.166:38864] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "wcurtislloyd.com"] [uri "/wp-config.php.bak"] [unique_id "arLFudp0EvzWv4eCEyJQtgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 15:52:22
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 89.46.105.166 (host166-105-46-89.serverdedicati ...
show more
(mod_security) mod_security (id:210492) triggered by 89.46.105.166 (host166-105-46-89.serverdedicati.aruba.it): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 11:52:18.057627 2026] [security2:error] [pid 15279:tid 15279] [client 89.46.105.166:22330] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "nathanburd.com"] [uri "/wp-config.php.bak"] [unique_id "arKkMiH3t-b4SorSqbJcowAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 15:27:26
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 89.46.105.166 (host166-105-46-89.serverdedicati ...
show more
(mod_security) mod_security (id:210492) triggered by 89.46.105.166 (host166-105-46-89.serverdedicati.aruba.it): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 11:27:19.658227 2026] [security2:error] [pid 6926:tid 6926] [client 89.46.105.166:30914] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "doubloonswap.com"] [uri "/wp-config.php.bak"] [unique_id "arKeV9lXO5W-a4DV3oUDAAAAADE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 15:02:53
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 89.46.105.166 (host166-105-46-89.serverdedicati ...
show more
(mod_security) mod_security (id:210492) triggered by 89.46.105.166 (host166-105-46-89.serverdedicati.aruba.it): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 11:02:49.165347 2026] [security2:error] [pid 23416:tid 23460] [client 89.46.105.166:37864] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.conceptsinammunition.com"] [uri "/wp-config.php.bak"] [unique_id "arKYmeImP1leG3MswbtmbQAAAEA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 14:06:24
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 89.46.105.166 (host166-105-46-89.serverdedicati ...
show more
(mod_security) mod_security (id:210492) triggered by 89.46.105.166 (host166-105-46-89.serverdedicati.aruba.it): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 10:06:21.149730 2026] [security2:error] [pid 13718:tid 13791] [client 89.46.105.166:42760] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "beelineproductions.com"] [uri "/wp-config.php.bak"] [unique_id "arKLXU4l_-HKySCvTYY7TQAAAgQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 11:56:23
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 89.46.105.166 (host166-105-46-89.serverdedicati ...
show more
(mod_security) mod_security (id:210492) triggered by 89.46.105.166 (host166-105-46-89.serverdedicati.aruba.it): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 07:56:18.137781 2026] [security2:error] [pid 7196:tid 7196] [client 89.46.105.166:21424] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "orthopaedicsurgical.com"] [uri "/wp-config.php.bak"] [unique_id "arJs4hIyRnuuBIth8HrJbwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 02:13:49
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 89.46.105.166 (host166-105-46-89.serverdedicati ...
show more
(mod_security) mod_security (id:210492) triggered by 89.46.105.166 (host166-105-46-89.serverdedicati.aruba.it): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 22:13:41.676898 2026] [security2:error] [pid 19998:tid 19998] [client 89.46.105.166:43496] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "coloradospartans.com"] [uri "/.env"] [unique_id "arHkVaDnZeMHXLHGkxCUxgAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-04 12:02:17
(3 weeks ago)
Web attack
Bad Web Bot
Web App Attack
๐ง๐ช
Ivo Vynckier
2025-08-15 16:27:00
(1 year ago)
89.46.105.166 - - [15/Aug/2025:14:54:04 +0200] "HEAD /docs.zip HTTP/2.0" 404 0 "-" "-"
89.46.105.16 ...
show more
89.46.105.166 - - [15/Aug/2025:14:54:04 +0200] "HEAD /docs.zip HTTP/2.0" 404 0 "-" "-"
89.46.105.166 - - [15/Aug/2025:14:54:04 +0200] "HEAD /files.zip HTTP/2.0" 404 0 "-" "-"
89.46.105.166 - - [15/Aug/2025:14:54:04 +0200] "HEAD /blog.zip HTTP/2.0" 404 0 "-" "-"
89.46.105.166 - - [15/Aug/2025:14:54:05 +0200] "HEAD /bak.zip HTTP/2.0" 404 0 "-" "-"
show less
Web App Attack