🇳🇱
homeshowdomain.nl
2026-09-02 21:59:23
(12 hours ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-09-01.
show less
Web App Attack
SSH
Hacking
🇺🇸
mnsf
2026-09-02 01:05:24
(1 day ago)
Scanning/Probing (20)
Brute-Force
Web App Attack
Anonymous
2026-09-01 14:15:03
(1 day ago)
suspicious request in access.log
Web App Attack
🇺🇸
TPI-Abuse
2026-09-01 14:01:55
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.185.81.23 (23.81.185.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.185.81.23 (23.81.185.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 10:01:48.072457 2026] [security2:error] [pid 26106:tid 26106] [client 34.185.81.23:56824] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.slovenia-boat-registration.com"] [uri "/wp-config.php~"] [unique_id "apbazHWufxiBd3bI9mK4TAAAACs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
enpepet
2026-09-01 12:28:29
(1 day ago)
GENERAL: parametres: [url:env=] UA:crusader-worker/1.0 URL:/.env.example
Port Scan
Hacking
Brute-Force
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-01 11:05:44
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.185.81.23 (23.81.185.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.185.81.23 (23.81.185.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 07:05:39.813440 2026] [security2:error] [pid 32528:tid 32528] [client 34.185.81.23:50534] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.mindforestmovie.com"] [uri "/.env"] [unique_id "apaxg4jFOY2_Gd49WKzPngAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-01 11:00:05
(1 day ago)
Bot / scanning and/or hacking attempts: GET /wp-config.php~ HTTP/1.1
Hacking
Web App Attack
🇩🇪
Hazzard
2026-09-01 09:43:40
(2 days ago)
(mod_security) mod_security triggered on hostname [redacted]): (CF_ENABLE)
SQL Injection
🇩🇪
FeG Deutschland
2026-09-01 08:53:15
(2 days ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
🇺🇸
TPI-Abuse
2026-09-01 08:47:32
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.185.81.23 (23.81.185.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.185.81.23 (23.81.185.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 04:47:27.547540 2026] [security2:error] [pid 21928:tid 21928] [client 34.185.81.23:56450] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sierrablue.farm"] [uri "/.env.dev"] [unique_id "apaRH94hclsuufJDqIhtGAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
WeCloudit-Anti-Abuse
2026-09-01 08:35:51
(2 days ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
Anonymous
2026-09-01 08:30:04
(2 days ago)
CrowdSec decision: crowdsecurity/http-sensitive-files (origin: crowdsec)
Web App Attack
🇺🇸
TPI-Abuse
2026-09-01 08:25:21
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.185.81.23 (23.81.185.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.185.81.23 (23.81.185.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 04:25:17.941558 2026] [security2:error] [pid 32054:tid 32054] [client 34.185.81.23:53490] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mejorprostata.com.bestprostate.com"] [uri "/.env.dev"] [unique_id "apaL7eSBeCAOCGCgJaUe5wAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
raph
2026-09-01 08:23:09
(2 days ago)
[Wordpress] crawler /wp-admin/*, /wp-content/*, etc.
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-01 07:42:30
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.185.81.23 (23.81.185.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.185.81.23 (23.81.185.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 03:42:22.708965 2026] [security2:error] [pid 32297:tid 32297] [client 34.185.81.23:47186] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "femmefire.vanemby.com"] [uri "/.env.production"] [unique_id "apaB3hIkIMhP79V-7TiwcQAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack