🇫🇷
IRISIO
2026-09-05 08:59:48
(5 hours ago)
scans/SQL injection/spam posts : 254 queries
Web App Attack
SQL Injection
🇧🇪
taivas.nl
2026-09-05 04:33:21
(9 hours ago)
Many_bad_calls
Web App Attack
🇳🇱
homeshowdomain.nl
2026-09-04 22:00:37
(16 hours ago)
Auto-ban: >3000 req/min op 2026-09-04
Web App Attack
SSH
Hacking
🇳🇱
Site.eu
2026-09-04 15:25:54
(22 hours ago)
Excessive multi-domain requests
Brute-Force
🇺🇸
TPI-Abuse
2026-09-04 15:07:43
(23 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.196.77.242 (242.77.196.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.196.77.242 (242.77.196.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 11:07:38.793597 2026] [security2:error] [pid 29025:tid 29025] [client 35.196.77.242:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.gibit.me"] [uri "/@fs/.env.local"] [unique_id "apreumiBM2o3IOjT2MJNgAAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
snappic
2026-09-04 15:07:02
(23 hours ago)
Scanning for config [GET /config.json.js] [Mozilla/5.0 (Macintosh; Intel Mac OS X 14_5) AppleWebKit/ ...
show more
Scanning for config [GET /config.json.js] [Mozilla/5.0 (Macintosh; Intel Mac OS X 14_5) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.5374.74 Safari/537.36 Edg/126.0.5374.74; compatible; Claude-User/1.0; [email protected] ]
show less
Bad Web Bot
Web App Attack
🇧🇪
taivas.nl
2026-09-04 13:02:11
(1 day ago)
Bad_requests
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-04 12:39:41
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.196.77.242 (242.77.196.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.196.77.242 (242.77.196.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 08:39:37.420049 2026] [security2:error] [pid 16820:tid 16820] [client 35.196.77.242:18968] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "atimeinhistory.andiamocomputers.com"] [uri "/@fs/app/.env"] [unique_id "apq8CTvNvuPb3xgNLOWRHQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 11:22:12
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.196.77.242 (242.77.196.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.196.77.242 (242.77.196.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 07:22:08.293783 2026] [security2:error] [pid 27715:tid 27715] [client 35.196.77.242:62464] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.ironsightsarmory.com"] [uri "/@fs/src/.env"] [unique_id "apqp4OIo0QN4NyNo7wK6lwAAAC8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 10:27:42
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.196.77.242 (242.77.196.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.196.77.242 (242.77.196.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 06:27:38.439767 2026] [security2:error] [pid 8043:tid 8043] [client 35.196.77.242:64514] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.pawlogix.com"] [uri "/@fs/.env.staging"] [unique_id "apqdGvEOnWr840KASp9xMgAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 10:11:23
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.196.77.242 (242.77.196.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.196.77.242 (242.77.196.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 06:11:19.389227 2026] [security2:error] [pid 28768:tid 28768] [client 35.196.77.242:54938] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.jamesallenwalker.com"] [uri "/@fs/..%252f..%252f..%252f..%252f..%252fapp/.env"] [unique_id "apqZR6KwOjMa3fDPt86fAgAAAEA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
middelkoopcc
2026-09-04 08:47:01
(1 day ago)
2026-09-04 10:45:00 GET /@fs/root/.env?raw?? [404] && 2026-09-04 10:45:00 GET /@fs/home/ec2-user/.aw ...
show more
2026-09-04 10:45:00 GET /@fs/root/.env?raw?? [404] && 2026-09-04 10:45:00 GET /@fs/home/ec2-user/.aws/credentials?raw?? [404] && 2026-09-04 10:45:00 GET /@fs/..%252f..%252f..%252f..%252f..%252froot/.env?raw?? [404] && 145 more within 20 minutes
show less
Web App Attack
🇩🇪
yitzhaq
2026-09-04 07:47:40
(1 day ago)
35.196.77.242 - - [04/Sep/2026:09:47:33 +0200] "GET /@fs/home/node/.aws/config?raw?? HTTP/1.1" 503 4 ...
show more
35.196.77.242 - - [04/Sep/2026:09:47:33 +0200] "GET /@fs/home/node/.aws/config?raw?? HTTP/1.1" 503 4663 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; [email])"
35.196.77.242 - - [04/Sep/2026:09:47:34 +0200] "GET /@fs/home/ubuntu/.aws/config?raw?? HTTP/1.1" 503 4663 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; Claude-User/1.0; [email]"
35.196.77.242 - - [04/Sep/2026:09:47:34 +0200] "GET /@fs/home/www-data/.aws/credentials?raw?? HTTP/1.1" 503 4663 "-" "Mozilla/5.0 (compatible; TelegramBot/1.0)"
35.196.77.242 - - [04/Sep/2026:09:47:35 +0200] "GET /@fs/..%252f..%252f..%252f..%252f..%252fapp/.env?raw?? HTTP/1.1" 503 4663 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; GrokBot/1.0; +https://x.ai/grokbot"
35.196.77.242 - - [04/Sep/2026:09:47:35 +0200] "GET /@fs/proc/self/environ?raw?? HTTP/1.1" 503 4663 "-" "Mozilla/5.0 (compatible; Claude-User/1.0; +https://www.anthropic.com/claude-user)"
35.196.77.242 - - [04/
show less
Web App Attack
Hacking
🇳🇱
ConsulHosting
2026-09-04 06:48:46
(1 day ago)
Automatically blocked due to distributed attack
Hacking
🇺🇸
dot.mg
2026-09-04 06:08:03
(1 day ago)
Bad behaviour
Web Spam