🇳🇱
homeshowdomain.nl
2026-09-08 22:00:48
(5 minutes ago)
Auto-ban: >3000 req/min op 2026-09-08
Web App Attack
SSH
Hacking
🇺🇸
TPI-Abuse
2026-09-08 13:10:01
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.198.120.237 (237.120.198.104.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 104.198.120.237 (237.120.198.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 09:09:54.686217 2026] [security2:error] [pid 32589:tid 32589] [client 104.198.120.237:40624] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.persnicketyinc.com"] [uri "/@fs/root/.env"] [unique_id "aqAJIrNQedSg7uMVx-QksgAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 12:17:00
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.198.120.237 (237.120.198.104.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 104.198.120.237 (237.120.198.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 08:16:56.609596 2026] [security2:error] [pid 1714235:tid 1714297] [client 104.198.120.237:23134] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.vtweaversguild.org"] [uri "/@fs/.env"] [unique_id "ap_8uC4xGzxztlzDx72GcQAAANU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 11:41:34
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.198.120.237 (237.120.198.104.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 104.198.120.237 (237.120.198.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 07:41:28.931100 2026] [security2:error] [pid 29247:tid 29247] [client 104.198.120.237:51270] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.justiart.com"] [uri "/@fs/.env"] [unique_id "ap_0aAj7Vc3eVKt9KcHGTgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 11:12:13
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.198.120.237 (237.120.198.104.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 104.198.120.237 (237.120.198.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 07:12:09.371191 2026] [security2:error] [pid 24192:tid 24192] [client 104.198.120.237:29904] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.grabnerconsulting.com"] [uri "/@fs/.env"] [unique_id "ap_tiTzuSOTySxbUJ6nO3QAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
Hazzard
2026-09-08 10:54:09
(11 hours ago)
(mod_security) mod_security triggered on hostname [redacted]): (CF_ENABLE)
SQL Injection
Anonymous
2026-09-08 10:38:41
(11 hours ago)
Fail2Ban: request for a known-malicious path (.env, .git, wp-login, actuator, ...) on a public web s ...
show more
Fail2Ban: request for a known-malicious path (.env, .git, wp-login, actuator, ...) on a public web server; honeypot hit, banned on first attempt.
show less
Web App Attack
Bad Web Bot
🇩🇪
LRob
2026-09-08 10:29:35
(11 hours ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /@fs/.env (+10 more) | 2026-09-08 10:29 UTC
show less
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 10:28:29
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.198.120.237 (237.120.198.104.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 104.198.120.237 (237.120.198.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 06:28:21.524856 2026] [security2:error] [pid 25459:tid 25459] [client 104.198.120.237:4050] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.cyqci.eu"] [uri "/@fs/app/.env"] [unique_id "ap_jRWRYEEfeNWPKYYTd5AAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
Vegascosmetics
2026-09-08 08:26:28
(13 hours ago)
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after sensitive config/credentials exposure ...
show more
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after sensitive config/credentials exposure probe. Evidence: AttackPattern: /\.env (Match: /.env)
show less
Hacking
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 08:19:23
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.198.120.237 (237.120.198.104.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 104.198.120.237 (237.120.198.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 04:19:17.207086 2026] [security2:error] [pid 15350:tid 15350] [client 104.198.120.237:28300] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.scomparsa-disappearance.tandm.us"] [uri "/@fs/src/.env"] [unique_id "ap_FBSQeNiIHExUhezIMwgAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇷🇸
Smel
2026-09-08 08:07:02
(13 hours ago)
HTTP/80/443/8080 Unauthorized Probe, Hack -
Hacking
Web App Attack
🇫🇷
Octopuce
2026-09-08 08:03:44
(14 hours ago)
Aggressive web search of vulnerable pages: /img../.env /images../.env /app/.env /uploads../.env /lar ...
show more
Aggressive web search of vulnerable pages: /img../.env /images../.env /app/.env /uploads../.env /laravel/.env ...
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 07:48:50
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.198.120.237 (237.120.198.104.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 104.198.120.237 (237.120.198.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 03:48:43.627178 2026] [security2:error] [pid 27772:tid 27772] [client 104.198.120.237:3778] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.herstonfarm.com"] [uri "/@fs/src/.env"] [unique_id "ap-92ywexajbzQx_frDe-AAAACA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
Site.eu
2026-09-08 07:43:13
(14 hours ago)
Excessive multi-domain requests
Brute-Force