๐ณ๐ฑ
homeshowdomain.nl
2026-09-01 22:00:19
(5 hours ago)
Auto-ban: >3000 req/min op 2026-09-01
Web App Attack
SSH
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-01 13:51:27
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.190.149.111 (111.149.190.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.190.149.111 (111.149.190.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 09:51:22.890207 2026] [security2:error] [pid 7649:tid 7649] [client 35.190.149.111:38618] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.vc1.com"] [uri "/.env.example"] [unique_id "apbYWmaNnh35dPY8_SdNyQAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-01 13:50:06
(13 hours ago)
2026/09/01 13:50:03 [error] 2115103#2115103: *137907 [client 35.190.149.111] ModSecurity: Access den ...
show more
2026/09/01 13:50:03 [error] 2115103#2115103: *137907 [client 35.190.149.111] ModSecurity: Access denied with code 403 (phase 2). Matched "Operator `Ge' with parameter `5' against variable `TX:BLOCKING_INBOUND_ANOMALY_SCORE' (Value: `5' ) [file "/usr/local/owasp-modsecurity-crs-4.11.0/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "222"] [id "949110"] [rev ""] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [data ""] [severity "0"] [ver "OWASP_CRS/4.29.0"] [maturity "0"] [accuracy "0"] [tag "anomaly-evaluation"] [tag "OWASP_CRS"] [hostname "cpcalendars.royalealmond.com"] [uri "/.env.local"] [unique_id "178827060318.863219"] [ref ""], client: 35.190.149.111, server: srv.ingeltechgh.com, request: "GET /.env.local HTTP/1.1", host: "cpcalendars.royalealmond.com"
2026/09/01 13:50:03 [error] 2115103#2115103: *137906 [client 35.190.149.111] ModSecurity: Access denied with code 403 (phase 2). Matched "Operator `Ge' with parameter `5' against variable `TX:BLOCKING_INBOUND_ANOMALY_SCORE' (V
...
show less
Brute-Force
๐ฌ๐ง
consul.to
2026-09-01 13:13:18
(14 hours ago)
Web attack/malicious scanning detected
Web App Attack
๐ซ๐ท
Mickmick21
2026-09-01 13:12:12
(14 hours ago)
35.190.149.111 - - [01/Sep/2026:15:12:12 +0200] "GET /.env.prod HTTP/1.1" 418 0 "-" "crusader-worker ...
show more
35.190.149.111 - - [01/Sep/2026:15:12:12 +0200] "GET /.env.prod HTTP/1.1" 418 0 "-" "crusader-worker/1.0"
...
show less
Port Scan
Web App Attack
๐ฉ๐ช
Marc
2026-09-01 13:02:28
(14 hours ago)
35.190.149.111 - - [01/Sep/2026:15:02:28 +0200] "GET /actuator/env HTTP/1.1" 404 4618 "-" "crusader- ...
show more
35.190.149.111 - - [01/Sep/2026:15:02:28 +0200] "GET /actuator/env HTTP/1.1" 404 4618 "-" "crusader-worker/1.0" 35.190.149.111 - - [01/Sep/2026:15:02:28 +0200] "GET /_ignition/health-check HTTP/1.1" 404 4617 "-" "crusader-worker/1.0" 35.190.149.111 - - [01/Sep/2026:15:02:28 +0200] "GET /storage/logs/laravel.log HTTP/1.1" 404 4617 "-" "crusader-worker/1.0"
show less
Brute-Force
๐ฉ๐ช
raph
2026-09-01 12:54:24
(14 hours ago)
[Wordpress] crawler /wp-admin/*, /wp-content/*, etc.
Bad Web Bot
Web App Attack
Anonymous
2026-09-01 12:50:02
(14 hours ago)
suspicious request in access.log
Web App Attack
๐ซ๐ท
masterguru
2026-09-01 12:32:23
(14 hours ago)
Restricted File Access Attempt. Matched phrase ".env" at REQUEST_FILENAME. (930130-201)
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 12:27:29
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.190.149.111 (111.149.190.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.190.149.111 (111.149.190.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 08:27:22.135889 2026] [security2:error] [pid 23069:tid 23069] [client 35.190.149.111:45670] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cayman-boat-registration.com.boatregistrationdelaware.com"] [uri "/.env.bak"] [unique_id "apbEqvV9VQ-WRUuUhEYj1wAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 12:12:27
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.190.149.111 (111.149.190.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.190.149.111 (111.149.190.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 08:12:22.157470 2026] [security2:error] [pid 20737:tid 20737] [client 35.190.149.111:39416] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "deanfountain.com"] [uri "/.env.local"] [unique_id "apbBJr_xzHI-VuzFnU7MawAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-09-01 12:05:37
(15 hours ago)
Scanning/Probing (20)
Brute-Force
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-09-01 11:20:29
(16 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐ฉ๐ช
4server
2026-09-01 10:58:14
(16 hours ago)
[TueSep0112:58:09.4130842026][security2:error][pid4075409:tid4075445][client35.190.149.111:0]ModSecu ...
show more
[TueSep0112:58:09.4130842026][security2:error][pid4075409:tid4075445][client35.190.149.111:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Patternmatch\"\(\?i\)\(\?:/\(\?:\^\|/\)\\\\\\\\.\(env\|git\|svn\|hg\|DS_Store\)\|/\(\?:wp-config\|\\\\\\\\.htaccess\|\\\\\\\\.htpasswd\)\|\\\\\\\\.\(\?:sql\|bak\|old\|log\)\$\)\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"156\"][id\"960720\"][msg\"Forbiddenfileaccessattempt\"][severity\"CRITICAL\"][hostname\"webmail.ecosuber.com\"][uri\"/wp-config.php~\"][unique_id\"apavwQOMxCQ8V14NNBay2gAAAEA\"]
show less
Port Scan
Brute-Force
Web App Attack
๐ฉ๐ช
ecs.ge
2026-09-01 10:51:58
(16 hours ago)
Automatic Fail2Ban report from jail plesk-modsecurity: multiple matching events detected.
Web App Attack
Hacking