🇳🇱
homeshowdomain.nl
2026-09-05 21:59:42
(8 hours ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-09-04.
show less
Web App Attack
SSH
Hacking
🇮🇹
CoreTech srl
2026-09-04 15:18:56
(1 day ago)
cloudlinux2 fail2ban: 2026-09-04 17:14:41,503 fail2ban.actions [1594]: NOTICE [plesk-modsecu ...
show more
cloudlinux2 fail2ban: 2026-09-04 17:14:41,503 fail2ban.actions [1594]: NOTICE [plesk-modsecurity] Ban 196.190.61.28cloudlinux2 fail2ban: 2026-09-04 17:14:40,985 fail2ban.filter [1594]: INFO [plesk-modsecurity] Found 196.190.61.28 - 2026-09-04 17:14:40cloudlinux2 fail2ban: 2026-09-04 17:14:41,697 fail2ban.filter [1594]: INFO [recidive] Found 196.190.61.28 - 2026-09-04 17:14:41cloudlinux2 fail2ban: 2026-09-04 17:14:45,524 fail2ban.filter [1594]: INFO [plesk-wordpress] Found 173.239.224.31 - 2026-09-04 17:14:44cloudlinux2 fail2ban: 2026-09-04 17:14:45,294 fail2ban.filter [1594]: INFO [plesk-wordpress] Found 173.239.224.36 - 2026-09-04 17:14:44cloudlinux2 fail2ban: 2026-09-04 17:14:45,299 fail2ban.filter [1594]: INFO [plesk-wordpress] Found 173.239.224.236 - 2026-09-04 17:14:44cloudlinux2 fail2ban: 2026-09-04 17:14:58,128 fail2ban.filter [1594]: INFO [plesk-wordpress] Found 193.56.116.62 - 2026-09-04 17:14:57cloudlinux2 fail2ban: 2026-09-04
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 14:52:44
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.75.162.3 (3.162.75.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.75.162.3 (3.162.75.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 10:52:38.841021 2026] [security2:error] [pid 6108:tid 6108] [client 34.75.162.3:36764] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "centrovision21.opticasprisma.com"] [uri "/wp-config.php~"] [unique_id "aprbNvEU4Rw6tzeZmHzgJwAAACk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
Marc
2026-09-04 14:38:16
(1 day ago)
34.75.162.3 - - [04/Sep/2026:16:38:15 +0200] "GET /actuator/configprops HTTP/1.1" 404 4617 "-" "crus ...
show more
34.75.162.3 - - [04/Sep/2026:16:38:15 +0200] "GET /actuator/configprops HTTP/1.1" 404 4617 "-" "crusader-worker/1.0" 34.75.162.3 - - [04/Sep/2026:16:38:15 +0200] "GET /.env.bak HTTP/1.1" 404 4616 "-" "crusader-worker/1.0" 34.75.162.3 - - [04/Sep/2026:16:38:15 +0200] "GET /.env.old HTTP/1.1" 404 4617 "-" "crusader-worker/1.0"
show less
Brute-Force
🇧🇷
Sabrina Soto
2026-09-04 14:36:00
(1 day ago)
Probe for vulnerabilities. Path attempted: /.env.local
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 14:06:18
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.75.162.3 (3.162.75.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.75.162.3 (3.162.75.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 10:06:10.006056 2026] [security2:error] [pid 8630:tid 8630] [client 34.75.162.3:42648] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.skyesongtollers.com"] [uri "/.env.local"] [unique_id "aprQUr51LGobUGbcqO6tAQAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-04 13:35:02
(1 day ago)
suspicious request in access.log
Web App Attack
🇳🇱
e.fierstra
2026-09-04 12:41:24
(1 day ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
🇬🇧
relianoid.com
2026-09-04 12:30:55
(1 day ago)
404 Errors Abuse detected by Relianoid OSS Load Balancer - relianoid.com
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 11:56:40
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.75.162.3 (3.162.75.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.75.162.3 (3.162.75.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 07:56:35.220030 2026] [security2:error] [pid 19643:tid 19643] [client 34.75.162.3:49668] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "staging.lindenwoodpark.org"] [uri "/.env.local"] [unique_id "apqx8_0uKe3K1KQ5_4ycXQAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 10:00:25
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.75.162.3 (3.162.75.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.75.162.3 (3.162.75.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 06:00:18.290481 2026] [security2:error] [pid 23005:tid 23100] [client 34.75.162.3:38260] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.deyyoungart.com"] [uri "/.env.backup"] [unique_id "apqWsrbRlZcG9IeHctbyDwAAAM0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 08:21:21
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.75.162.3 (3.162.75.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.75.162.3 (3.162.75.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 04:21:15.021071 2026] [security2:error] [pid 19293:tid 19293] [client 34.75.162.3:57504] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.crazypencil.com"] [uri "/.env.backup"] [unique_id "app_e0_BWDQ21wkcWEz2qAAAADE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
pscriptos
2026-09-04 08:00:01
(1 day ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
🇳🇱
WeCloudit-Anti-Abuse
2026-09-04 07:48:14
(1 day ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-04 07:43:57
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.75.162.3 (3.162.75.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.75.162.3 (3.162.75.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 03:43:53.962057 2026] [security2:error] [pid 10313:tid 10313] [client 34.75.162.3:42010] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ftp.netcastcorp.com"] [uri "/.env.save"] [unique_id "app2ufWdgM171PV_7tYoPQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack