🇳🇱
homeshowdomain.nl
2026-09-04 22:02:19
(1 day ago)
Auto-ban: >3000 req/min op 2026-09-04
Web App Attack
SSH
Hacking
🇺🇸
TPI-Abuse
2026-09-04 15:17:42
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.189.9.132 (132.9.189.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.189.9.132 (132.9.189.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 11:17:35.759414 2026] [security2:error] [pid 17975:tid 17975] [client 35.189.9.132:51686] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.tylerdroneservices.com"] [uri "/.env.dev"] [unique_id "aprhD9dUSw41RHiYXFxfMQAAADc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 13:35:33
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.189.9.132 (132.9.189.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.189.9.132 (132.9.189.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 09:35:25.834510 2026] [security2:error] [pid 13604:tid 13604] [client 35.189.9.132:41254] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "feaverslane.com"] [uri "/.env.example"] [unique_id "aprJHdKRSgND0F1slqjovQAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
paissangroup
2026-09-04 13:33:25
(1 day ago)
Multiple WAF Violations
Web App Attack
🇩🇪
Melle
2026-09-04 13:26:16
(1 day ago)
Blocked by CrowdSec | Scenario: crowdsecurity/http-sensitive-files | 35.189.9.132 triggered 5 events ...
show more
Blocked by CrowdSec | Scenario: crowdsecurity/http-sensitive-files | 35.189.9.132 triggered 5 events | Detected: 2026-09-04T13:26:15.262693907Z
show less
Web App Attack
Hacking
🇸🇪
vaia.cloud
2026-09-04 11:30:02
(1 day ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
🇩🇪
McClay
2026-09-04 11:14:35
(1 day ago)
HTTP-404 spam:35.189.9.132 - - [04/Sep/2026:13:14:34 +0200] "GET /_ignition/health-check HTTP/1.1" 4 ...
show more
HTTP-404 spam:35.189.9.132 - - [04/Sep/2026:13:14:34 +0200] "GET /_ignition/health-check HTTP/1.1" 404 5009 "-" "crusader-worker/1.0"
35.189.9.132 - - [04/Sep/2026:13:14:35 +0200] "GET /wp-config.php.swp HTTP/1.1" 404 5010 "-" "crusader-worker/1.0"
35.189.9.132 - - [04/Sep/2026:13:14:35 +0200] "GET /.env.prod HTTP/1.1" 404 5008 "-" "crusader-worker/1.0"
35.189.9.132 - - [04/Sep/2026:13:14:35 +0200] "GET /actuator/env HTTP/1.1" 404 5008 "-" "crusader-worker/1.0"
35.189.9.132 - - [04/Sep/2026:13:14:35 +0200] "GET /actuator/configprops HTTP/1.1" 404 5009 "-" "crusader-worker/1.0"
35.189.9.132 - - [04/Sep/2026:13:14:35 +0200] "GET /wp-config.php.bak HTTP/1.1" 404 5009 "-" "crusader-worker/1.0"
35.189.9.132 - - [04/Sep/2026:13:14:35 +0200] "GET /env HTTP/1.1" 404 5010 "-" "crusader-worker/1.0"
35.189.9.132 - - [04/Sep/2026:13:14:35 +0200] "GET /.env.bak HTTP/1.1" 404 5009 "-" "crusader-worker/1.0"
35.189.9.132 - - [04/Sep/2026:13:14:35 +0200] "GET /.env HTTP/1.1" 404 5008 "-" "crusader-worker/1.0"
35.189
...
show less
Web App Attack
🇫🇷
masterguru
2026-09-04 09:19:13
(1 day ago)
Restricted File Access Attempt. Matched phrase ".env" at REQUEST_FILENAME. (930130-193)
Hacking
Web App Attack
Anonymous
2026-09-04 08:54:13
(1 day ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
Anonymous
2026-09-04 08:40:45
(1 day ago)
(config_exploit_scan) Configuratie Scanner / Nep GPTBot 35.189.9.132 (AU/Australia/132.9.189.35.bc.g ...
show more
(config_exploit_scan) Configuratie Scanner / Nep GPTBot 35.189.9.132 (AU/Australia/132.9.189.35.bc.googleusercontent.com): 3 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 35.189.9.132 - - [04/Sep/2026:10:40:42 +0200] "GET /.env.production HTTP/1.1" 406 4830 "-" "crusader-worker/1.0"
35.189.9.132 - - [04/Sep/2026:10:40:42 +0200] "GET /.env.prod HTTP/1.1" 406 4830 "-" "crusader-worker/1.0"
35.189.9.132 - - [04/Sep/2026:10:40:42 +0200] "GET /.env.backup HTTP/1.1" 406 4829 "-" "crusader-worker/1.0"
show less
Port Scan
🇨🇭
zynex
2026-09-04 08:17:38
(1 day ago)
URL Probing: /wp-config.php.bak
Web App Attack
🇨🇦
polycoda
2026-09-04 08:14:10
(1 day ago)
AutoBlock: 🎯 Vulnerability Scanner (Non Decay-Based)
Hacking
Web App Attack
Anonymous
2026-09-04 08:11:03
(1 day ago)
Bot / scanning and/or hacking attempts: GET /wp-config.php.swp HTTP/1.1, GET /.env.production HTTP/1 ...
show more
Bot / scanning and/or hacking attempts: GET /wp-config.php.swp HTTP/1.1, GET /.env.production HTTP/1.1, GET /storage/logs/laravel.log HTTP/1.1, GET /env HTTP/1.1, GET /.env.save HTTP/1.1
show less
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 08:05:55
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.189.9.132 (132.9.189.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.189.9.132 (132.9.189.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 04:05:47.684607 2026] [security2:error] [pid 11999:tid 11999] [client 35.189.9.132:53868] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "dutchgreenrecycling.com"] [uri "/.env.local"] [unique_id "app727lJo2SE-7WocEyGAAAAADQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-04 07:36:45
(1 day ago)
35.189.9.132 - - [04/Sep/2026:09:36:41 +0200] "GET /.env.local HTTP/1.1" 403 164 "-" "crusader-worke ...
show more
35.189.9.132 - - [04/Sep/2026:09:36:41 +0200] "GET /.env.local HTTP/1.1" 403 164 "-" "crusader-worker/1.0"
35.189.9.132 - - [04/Sep/2026:09:36:41 +0200] "GET /.env HTTP/1.1" 403 164 "-" "crusader-worker/1.0"
35.189.9.132 - - [04/Sep/2026:09:36:41 +0200] "GET /_ignition/health-check HTTP/1.1" 404 164 "-" "crusader-worker/1.0"
35.189.9.132 - - [04/Sep/2026:09:36:41 +0200] "GET /.env.backup HTTP/1.1" 403 164 "-" "crusader-worker/1.0"
35.189.9.132 - - [04/Sep/2026:09:36:41 +0200] "GET /actuator/env HTTP/1.1" 404 164 "-" "crusader-worker/1.0"
35.189.9.132 - - [04/Sep/2026:09:36:41 +0200] "GET /.env.production HTTP/1.1" 403 164 "-" "crusader-worker/1.0"
35.189.9.132 - - [04/Sep/2026:09:36:41 +0200] "GET /.env.example HTTP/1.1" 403 164 "-" "crusader-worker/1.0"
35.189.9.132 - - [04/Sep/2026:09:36:41 +0200] "GET /.env.old HTTP/1.1" 403 164 "-" "crusader-worker/1.0"
35.189.9.132 - - [04/Sep/2026:09:36:41 +0200] "GET /wp-config.php~ HTTP/1.1" 403 164 "-" "crusader-worker/1.0"
35.189.9.132 - - [0
...
show less
Bad Web Bot
Web App Attack