π«π·
service Informatique
2026-08-28 04:00:37
(12 minutes ago)
GET /wp-config
Web App Attack
π©πͺ
bazter.pro
2026-08-27 22:02:52
(6 hours ago)
Fail2Ban: plesk-bot-aggressive - 15 failures
Port Scan
Bad Web Bot
Web App Attack
π³π±
homeshowdomain.nl
2026-08-27 22:01:58
(6 hours ago)
Auto-ban: >3000 req/min op 2026-08-27
Web App Attack
SSH
Hacking
π¨π
ALPHANET
2026-08-27 21:46:24
(6 hours ago)
web exploits
Hacking
Exploited Host
Web App Attack
π§π·
noconex
2026-08-27 21:10:09
(7 hours ago)
Wazuh Alert | Rule ID: 110100 | Desc: Suricata: Exploit (ET WEB_SERVER Tilde in URI - potential .php ...
show more
Wazuh Alert | Rule ID: 110100 | Desc: Suricata: Exploit (ET WEB_SERVER Tilde in URI - potential .php~ source disclosure vulnerability) 35.193.0.223
show less
Port Scan
Brute-Force
SSH
πΊπΈ
leasj
2026-08-27 20:54:44
(7 hours ago)
Observed Scanned 15 known-sensitive endpoint(s), e.g.: /.env.backup, /.env.dev, /.env.save, /actuato ...
show more
Observed Scanned 15 known-sensitive endpoint(s), e.g.: /.env.backup, /.env.dev, /.env.save, /actuator/env, /actuator/configprops.
show less
Hacking
Bad Web Bot
Web App Attack
Anonymous
2026-08-27 18:44:06
(9 hours ago)
Banned by Fail2Ban on server
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-27 18:08:39
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.193.0.223 (223.0.193.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.193.0.223 (223.0.193.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 14:08:34.136902 2026] [security2:error] [pid 23922:tid 24030] [client 35.193.0.223:38746] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jakob-and-lotta.com"] [uri "/.env"] [unique_id "apB9InqMvx2qG4D9bQettAAAAlA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-27 17:22:17
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.193.0.223 (223.0.193.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.193.0.223 (223.0.193.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 13:22:11.579103 2026] [security2:error] [pid 3885:tid 3885] [client 35.193.0.223:60574] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.fcc.robotrodeo.net"] [uri "/.env"] [unique_id "apByQ11KWBPpHsQF53-DYQAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
mieg
2026-08-27 17:13:43
(10 hours ago)
Web vulnerability probing
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-27 16:55:42
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.193.0.223 (223.0.193.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.193.0.223 (223.0.193.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 12:55:35.850579 2026] [security2:error] [pid 5316:tid 5316] [client 35.193.0.223:50782] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "erinrusso.com"] [uri "/.env.prod"] [unique_id "apBsB6eWw1BHdhtFXblZLwAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
BlueWire Hosting
2026-08-27 15:52:43
(12 hours ago)
Aggressive scanning resulting into 404
Bad Web Bot
πΊπΈ
TPI-Abuse
2026-08-27 15:37:10
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.193.0.223 (223.0.193.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.193.0.223 (223.0.193.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 11:37:04.868932 2026] [security2:error] [pid 16304:tid 16304] [client 35.193.0.223:36000] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.air-comfort-inc.sophcomp.com"] [uri "/.env.backup"] [unique_id "apBZoDWb-8crD4ya-0iJYwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
big-cloud.nl
2026-08-27 15:33:51
(12 hours ago)
Try to access /.env
Web App Attack
π©πͺ
ISPLtd
2026-08-27 15:27:32
(12 hours ago)
Aug 27 12:27:31 35.193.0.223 TCP SPT=46154 DPT=80 SYN
Aug 27 12:27:31 35.193.0.223 TCP SPT=46174 DPT ...
show more
Aug 27 12:27:31 35.193.0.223 TCP SPT=46154 DPT=80 SYN
Aug 27 12:27:31 35.193.0.223 TCP SPT=46174 DPT=80 SYN
Aug 27 12:27:31 35.193.0.223 TCP SPT=46242 DPT=80 SYN
Aug 27
...
show less
DDoS Attack