🇳🇱
homeshowdomain.nl
2026-09-04 22:01:28
(6 hours ago)
Auto-ban: >3000 req/min op 2026-09-04
Web App Attack
SSH
Hacking
🇩🇪
FeG Deutschland
2026-09-04 15:21:24
(13 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 15:15:54
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.154.210.42 (42.210.154.104.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 104.154.210.42 (42.210.154.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 11:15:48.083825 2026] [security2:error] [pid 26694:tid 26694] [client 104.154.210.42:48434] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.secureonebank.net"] [uri "/.env"] [unique_id "aprgpLMt--qHO2B2BrK27wAAADY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇨🇦
Anytech
2026-09-04 14:55:21
(13 hours ago)
Blocked by Conn-Monitor: env-probing
Web App Attack
Hacking
🇺🇸
daveoctober
2026-09-04 13:51:41
(14 hours ago)
October Sentinel: honeypot triggered
Bad Web Bot
Web App Attack
🇳🇱
WeCloudit-Anti-Abuse
2026-09-04 13:33:37
(14 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
🇳🇱
e.fierstra
2026-09-04 13:33:22
(14 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
🇬🇧
Aetherweb Ark
2026-09-04 13:21:03
(15 hours ago)
(mod_security) mod_security (id:949110) triggered by 104.154.210.42 (US/United States/42.210.154.104 ...
show more
(mod_security) mod_security (id:949110) triggered by 104.154.210.42 (US/United States/42.210.154.104.bc.googleusercontent.com): N in the last X secs
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 12:01:45
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.154.210.42 (42.210.154.104.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 104.154.210.42 (42.210.154.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 08:01:38.876292 2026] [security2:error] [pid 8017:tid 8017] [client 104.154.210.42:60894] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "test.garnetcreek.com"] [uri "/.env.dev"] [unique_id "apqzIqf2KHMk3GsA-gamDwAAADw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 11:15:06
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.154.210.42 (42.210.154.104.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 104.154.210.42 (42.210.154.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 07:14:57.708937 2026] [security2:error] [pid 23005:tid 23110] [client 104.154.210.42:38364] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.mailme.name"] [uri "/wp-config.php.bak"] [unique_id "apqoMbbRlZcG9IeHctb1IAAAANE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 10:56:28
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.154.210.42 (42.210.154.104.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 104.154.210.42 (42.210.154.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 06:56:24.180446 2026] [security2:error] [pid 3068:tid 3068] [client 104.154.210.42:52846] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "box.davisllp.com"] [uri "/wp-config.php~"] [unique_id "apqj2DjZaz9uCXD5fzRYiQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
masterguru
2026-09-04 10:14:05
(18 hours ago)
Attempt to access a backup or working file. Pattern match "\\\\. (920500-201)
Hacking
Anonymous
2026-09-04 10:07:05
(18 hours ago)
Automated web scanner. Requested suspicious paths: /.env.local | /.env.old | /.env.bak | /.env | /.e ...
show more
Automated web scanner. Requested suspicious paths: /.env.local | /.env.old | /.env.bak | /.env | /.env.prod | /actuator/env | /.env.save | /.env.dev | /.env.backup | /env | /.env.production | /crusader-404-probe | /.env.example | /storage/logs/laravel.log | /actuator/configprops, /_ignition/health-check | /.env.old | /.env.bak | /.env | /.env.prod | /actuator/env | /.env.save | /.env.dev | /.env.backup | /env | /.env.production | /crusader-404-probe | /.env.example | /storage/logs/laravel.log | /actuator/configprops. UTC: 2026-09-04 10:04:22.
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 10:00:56
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.154.210.42 (42.210.154.104.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 104.154.210.42 (42.210.154.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 06:00:49.462503 2026] [security2:error] [pid 1035:tid 1035] [client 104.154.210.42:37512] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.rodriguezclaudia.com"] [uri "/.env.local"] [unique_id "apqW0dMX-afrEa07IzGMOQAAADg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
LRob
2026-09-04 09:58:56
(18 hours ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /.env (+7 more) | 2026-09-04 09:58 UTC
show less
Hacking
Web App Attack