🇳🇱
homeshowdomain.nl
2026-08-29 22:01:28
(1 day ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-08-28.
show less
Web App Attack
SSH
Hacking
🇺🇸
TPI-Abuse
2026-08-29 02:59:34
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.53.3.246 (246.3.53.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.53.3.246 (246.3.53.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 22:59:29.015018 2026] [security2:error] [pid 11086:tid 11086] [client 34.53.3.246:44802] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.infinitewashingsolutions.finishlineenterprisesllc.com"] [uri "/.env.backup"] [unique_id "apJLEeViH7JI9rVYWi5X1wAAACY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
foxxelabs
2026-08-29 02:48:15
(1 day ago)
Automated report from FoxxeLabs Sentinel. Path probed: /actuator/env | Project: anseo | Reason(s): K ...
show more
Automated report from FoxxeLabs Sentinel. Path probed: /actuator/env | Project: anseo | Reason(s): Known exploit path: /actuator/env; AbuseIPDB score: 100/100 | User-Agent: crusader-worker/1.0
show less
Web App Attack
🇳🇱
SysAdmin Dylan
2026-08-29 02:24:31
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.53.3.246 (US/United States/246.3.53.34.bc.go ...
show more
(mod_security) mod_security (id:210492) triggered by 34.53.3.246 (US/United States/246.3.53.34.bc.googleusercontent.com): 10 in the last 3600 secs
show less
Brute-Force
🇩🇪
wassita
2026-08-29 02:00:42
(1 day ago)
many 404 errors, suspected URL fuzzing / bot scan — requested path: /.env — response: 404
Bad Web Bot
Web App Attack
🇫🇷
arsonist
2026-08-29 01:35:57
(1 day ago)
This IP accessed the path /.env.production, which is banned. Powered by ListenCaddy
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-29 00:59:41
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.53.3.246 (246.3.53.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.53.3.246 (246.3.53.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 20:59:32.645457 2026] [security2:error] [pid 12760:tid 12779] [client 34.53.3.246:40052] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "lawyerlouisiana.com"] [uri "/wp-config.php.bak"] [unique_id "apIu9OZol2ShRDQtw-hJmQAAAIQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
factor1
2026-08-29 00:32:44
(2 days ago)
CrowdSec at apollo Reports Abuse
Web App Attack
🇺🇸
TPI-Abuse
2026-08-29 00:02:02
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.53.3.246 (246.3.53.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.53.3.246 (246.3.53.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 20:01:55.137199 2026] [security2:error] [pid 26154:tid 26154] [client 34.53.3.246:59116] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "rockitfish.com"] [uri "/.env.bak"] [unique_id "apIhc6fS_oYjvMWWMNUN4wAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-28 23:35:17
(2 days ago)
Failed login attempt detected by Fail2Ban in plesk-modsecurity jail
Exploited Host
🇳🇱
debestelapp
2026-08-28 23:20:18
(2 days ago)
Web App Attack
🇩🇪
Dominik Lysiak
2026-08-28 23:18:22
(2 days ago)
34.53.3.246 - - [29/Aug/2026:01:18:21 +0200] "GET /.env.old HTTP/1.1" 404 146 "-" "crusader-worker/1 ...
show more
34.53.3.246 - - [29/Aug/2026:01:18:21 +0200] "GET /.env.old HTTP/1.1" 404 146 "-" "crusader-worker/1.0"
34.53.3.246 - - [29/Aug/2026:01:18:21 +0200] "GET /wp-config.php.swp HTTP/1.1" 404 146 "-" "crusader-worker/1.0"
34.53.3.246 - - [29/Aug/2026:01:18:21 +0200] "GET /.env.save HTTP/1.1" 404 146 "-" "crusader-worker/1.0"
...
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-08-28 21:24:47
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.53.3.246 (246.3.53.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.53.3.246 (246.3.53.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 17:24:41.452552 2026] [security2:error] [pid 2423:tid 2423] [client 34.53.3.246:35322] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.pearson-specter.com"] [uri "/wp-config.php.swp"] [unique_id "apH8maRYAxhpmFh0SRxrKwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-28 20:44:41
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.53.3.246 (246.3.53.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.53.3.246 (246.3.53.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 16:44:35.552361 2026] [security2:error] [pid 3356584:tid 3356761] [client 34.53.3.246:43124] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.gabegabel.prismatik.com"] [uri "/wp-config.php.swp"] [unique_id "apHzM1aK7I3gFT1ABKRZ3AAAAQo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
e.fierstra
2026-08-28 20:41:24
(2 days ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack