๐ณ๐ฑ
homeshowdomain.nl
2026-08-01 21:59:47
(10 hours ago)
Auto-ban: >3000 req/min op 2026-08-01
Web App Attack
SSH
Hacking
๐บ๐ธ
TPI-Abuse
2026-08-01 17:27:35
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.185.61.36 (36.61.185.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.185.61.36 (36.61.185.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 13:27:28.201818 2026] [security2:error] [pid 7298:tid 7298] [client 35.185.61.36:51042] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "waycoradio.com"] [uri "/.env.example"] [unique_id "am4sgFHcsbV-CsalaGY9fwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-01 17:14:48
(14 hours ago)
[server.tmg.gr] httpd-config-scan: sites=www.crisis-management2020.eu; logs=/var/log/httpd/domains/c ...
show more
[server.tmg.gr] httpd-config-scan: sites=www.crisis-management2020.eu; logs=/var/log/httpd/domains/crisis-management2020.eu.log; samples=/.env.backup | /.env.bak | /.env.production
show less
Hacking
Web App Attack
๐ณ๐ฑ
i-turnradio.nl
2026-08-01 17:12:15
(14 hours ago)
2026-08-01 @ 19:12:15 (CET) ~ Blocked for trying to access: /.env.save
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-01 17:07:10
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.185.61.36 (36.61.185.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.185.61.36 (36.61.185.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 13:07:03.430235 2026] [security2:error] [pid 2430268:tid 2430268] [client 35.185.61.36:57328] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "redwingboot.com"] [uri "/.env.save"] [unique_id "am4nt9zc-_uMmw8wrLsiBAAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ด
jad-abuse
2026-08-01 16:37:06
(15 hours ago)
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: env_probe ...
show more
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: env_probe, source_backup. Observed by 1 sensor(s); 10 hits.
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-01 16:35:04
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.185.61.36 (36.61.185.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.185.61.36 (36.61.185.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 12:34:58.342242 2026] [security2:error] [pid 624574:tid 624574] [client 35.185.61.36:59824] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "gibraltar-boat-registration.com"] [uri "/.env.old"] [unique_id "am4gMjzBWvdBfCo7AQr61QAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
kosada.com
2026-08-01 16:24:55
(15 hours ago)
Web vulnerability probing: /.env.local
Web App Attack
๐ณ๐ฑ
i-turnradio.nl
2026-08-01 16:17:43
(15 hours ago)
2026-08-01 @ 18:17:42 (CET) ~ Blocked for trying to access: /.env.old
Web App Attack
๐บ๐ธ
mnsf
2026-08-01 16:05:26
(16 hours ago)
Abuse Detected (10)
Brute-Force
Web App Attack
๐ฉ๐ช
ger-stg-sifi1
2026-08-01 15:37:16
(16 hours ago)
(wordpress) Failed wordpress login using wp-login.php or xmlrpc.php
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-01 15:31:44
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.185.61.36 (36.61.185.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.185.61.36 (36.61.185.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 11:31:38.382330 2026] [security2:error] [pid 1269530:tid 1269530] [client 35.185.61.36:35772] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.haddadpharmacy.com.saadeh.ws"] [uri "/.env.prod"] [unique_id "am4RWhJ_155XhPeJVHlJlgAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
mail.avx.gr
2026-08-01 15:29:10
(16 hours ago)
Plesk Fail2Ban jail: Plesk-Web-Exploits. Evidence: 35.185.61.36 - - [01/Aug/2026:18:29:10 +0300] "GE ...
show more
Plesk Fail2Ban jail: Plesk-Web-Exploits. Evidence: 35.185.61.36 - - [01/Aug/2026:18:29:10 +0300] "GET /.env.production HTTP/1.1" 404 808 "-" "crusader-worker/1.0"
show less
Web App Attack
๐ซ๐ท
masterguru
2026-08-01 15:17:27
(16 hours ago)
Restricted File Access Attempt. Matched phrase ".env" at REQUEST_FILENAME. (930130-193)
Hacking
Web App Attack
๐จ๐ญ
4server
2026-08-01 15:13:39
(16 hours ago)
[SatAug0117:13:34.3272302026][security2:error][pid3990482:tid3990754][client35.185.61.36:0]ModSecuri ...
show more
[SatAug0117:13:34.3272302026][security2:error][pid3990482:tid3990754][client35.185.61.36:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\".env\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"365\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"cpanel.aidconsultancy.ch\"][uri\"/.env.example\"][unique_id\"am4NHpYu6GwSK1LT87JU1QAAAVI\"]
show less
Hacking
Web App Attack