π³π±
homeshowdomain.nl
2026-09-16 21:59:22
(38 minutes ago)
Auto-ban: >3000 req/min op 2026-09-16
Web App Attack
SSH
Hacking
π©πͺ
LRob
2026-09-16 17:43:08
(4 hours ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /.git/config (+3 more) | 2026-09-16 17:43 UTC
show less
Hacking
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-16 17:30:14
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.194.121.42 (42.121.194.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.194.121.42 (42.121.194.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 13:29:44.133791 2026] [security2:error] [pid 31417:tid 31417] [client 35.194.121.42:60064] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.bluemarineboats.com.greenlight.us"] [uri "/.git/config"] [unique_id "aqrSCG45jcGlsetO8r7eqAAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
SLSLLC
2026-09-16 16:51:03
(5 hours ago)
35.194.121.42 - - [16/Sep/2026:16:51:02 +0000] "GET /.env HTTP/2.0" 403 1921 "-" "Mozilla/5.0 (Macin ...
show more
35.194.121.42 - - [16/Sep/2026:16:51:02 +0000] "GET /.env HTTP/2.0" 403 1921 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Brute-Force
Web App Attack
π©πͺ
todix
2026-09-16 14:43:43
(7 hours ago)
WebAttack or semilar from 35.194.121.42
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-16 14:38:19
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.194.121.42 (42.121.194.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.194.121.42 (42.121.194.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 10:38:15.427984 2026] [security2:error] [pid 19921:tid 19921] [client 35.194.121.42:57940] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.blogs.melton.space"] [uri "/.git/config"] [unique_id "aqqp1xZnq8c6VvL-S-LEuQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-16 14:05:03
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.194.121.42 (42.121.194.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.194.121.42 (42.121.194.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 10:04:58.602329 2026] [security2:error] [pid 4198:tid 4198] [client 35.194.121.42:53112] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.blog.tulsatvmemories.com"] [uri "/.git/config"] [unique_id "aqqiCgUBPrrmTbzZhMp53AAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π«π·
largo-it.net
2026-09-16 13:17:41
(9 hours ago)
[16/Sep/2026:15:17:39.135] HTTP 404 - GET /.env.local
[16/Sep/2026:15:17:39.386] HTTP 404 - GET /.en ...
show more
[16/Sep/2026:15:17:39.135] HTTP 404 - GET /.env.local
[16/Sep/2026:15:17:39.386] HTTP 404 - GET /.env.production
[16/Sep/2026:15:17:39.638] HTTP 404 - GET /.env.staging
[16/Sep/2026:15:17:39.890] HTTP 404 - GET /.env.development
[16/Sep/2026:15:17:40.144] HTTP 404 - GET /.env.test
[16/Sep/2026:15:17:40.398] HTTP 404 - GET /.env.remote
[16/Sep/2026:15:17:40.651] HTTP 404 - GET /.env.bak
[16/Sep/2026:15:17:40.902] HTTP 404 - GET /.env.backup
show less
Hacking
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-16 13:14:04
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.194.121.42 (42.121.194.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.194.121.42 (42.121.194.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 09:13:59.419744 2026] [security2:error] [pid 19406:tid 19423] [client 35.194.121.42:49864] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.blog.juantrece.com"] [uri "/.git/config"] [unique_id "aqqWF3FyyJRQrflL08d3NQAAAM4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-16 12:49:39
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.194.121.42 (42.121.194.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.194.121.42 (42.121.194.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 08:49:34.669036 2026] [security2:error] [pid 24542:tid 24542] [client 35.194.121.42:47874] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.blog.didemozbek.com.pist.org.tr"] [uri "/.git/config"] [unique_id "aqqQXoYKnaSP9PhD77vQOgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-16 12:22:45
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.194.121.42 (42.121.194.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.194.121.42 (42.121.194.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 08:22:40.744148 2026] [security2:error] [pid 2623929:tid 2623929] [client 35.194.121.42:34974] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.bulmacasozlugu.lobibilisim.com"] [uri "/.git/config"] [unique_id "aqqKENc4tZqGpqFJNoLRoAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΏπ¦
conure.sh
2026-09-16 11:31:03
(11 hours ago)
csagent: score 20.0: secrets grab x2; 1 domain(s) in 2s
Web App Attack
π§πΎ
lns.bz
2026-09-16 10:11:19
(12 hours ago)
Too many 404 requests [BY]
Web App Attack
π¬π§
consul.to
2026-09-16 09:34:38
(13 hours ago)
Web attack/malicious scanning detected
Web App Attack
π©πͺ
4server
2026-09-16 09:22:38
(13 hours ago)
[WedSep1611:22:33.4498972026][security2:error][pid373261:tid373317][client35.194.121.42:0]ModSecurit ...
show more
[WedSep1611:22:33.4498972026][security2:error][pid373261:tid373317][client35.194.121.42:0]ModSecurity:Accessdeniedwithcode403\(phase2\).Patternmatch\"\(\?:\\\\\\\\\$\(\?:\\\\\\\\\(\(\?:\\\\\\\\\(.\*\\\\\\\\\)\|.\*\)\\\\\\\\\)\|\\\\\\\\{.\*\\\\\\\\}\)\|[\<\>]\\\\\\\\\(.\*\\\\\\\\\)\)\"atARGS:0.[file\"/etc/apache2/conf.d/modsec_rules/10_asl_rules.conf\"][line\"396\"][id\"393655\"][rev\"17\"][msg\"Atomicorp.comWAFRules:PossibleRemoteCommandExecution:UnixShellExpressionFound\"][data\"MatchedData:\$\(\(41\*271\)\)foundwithinARGS:0:{then:\$1:__proto__:thenstatus:resolved_modelreason:-1value:{then:\$b1337}_response:{_prefix:varres=process.mainmodule.require\(child_process\).execsync\(echo\$\(\(41\*271\)\)\|base64-w0\).tostring\(\).trim\(\)throwobject.assign\(newerror\(next_redirect\){digest:\`next_redirectpush/login\?a=\${res}307\`}\)_chunks:\$q2_formdata:{get:\$1:constructor:constructor}}}\"][tag\"attack-rce\"][hostname\"www.buletti-panettoni.ch\"][uri\"/\"][unique_id\"aqpf2TslR5pf1y9MsKAVZAAAAFQ\"]
show less
Port Scan
Brute-Force
Web App Attack