๐ณ๐ฑ
homeshowdomain.nl
2026-09-01 21:59:20
(19 hours ago)
Auto-ban: >3000 req/min op 2026-09-01
Web App Attack
SSH
Hacking
๐ณ๐ฑ
e.fierstra
2026-09-01 13:01:04
(1 day ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 11:14:21
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.198.12.206 (206.12.198.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.198.12.206 (206.12.198.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 07:14:15.710579 2026] [security2:error] [pid 3395:tid 3395] [client 35.198.12.206:47748] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "whitmarshinc.com"] [uri "/.env.backup"] [unique_id "apazh0PsXD0fk_6znG8s4wAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 10:55:27
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.198.12.206 (206.12.198.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.198.12.206 (206.12.198.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 06:55:21.047636 2026] [security2:error] [pid 226452:tid 226484] [client 35.198.12.206:49490] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ozworkshop.com"] [uri "/.env.save"] [unique_id "apavGd8rDBwRmC-l-5guegAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
lns.bz
2026-09-01 10:47:29
(1 day ago)
Too many 404 requests [DOOZ]
Web App Attack
๐ฉ๐ช
XICTRON
2026-09-01 10:20:04
(1 day ago)
ModSecurity rule violation detected by Fail2Ban
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 09:31:34
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.198.12.206 (206.12.198.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.198.12.206 (206.12.198.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 05:31:28.109697 2026] [security2:error] [pid 3348:tid 3348] [client 35.198.12.206:36086] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "spacerecording.com"] [uri "/.env.bak"] [unique_id "apabcOJmVGaFNz9qe49BhgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ด
jad-abuse
2026-09-01 08:51:06
(1 day ago)
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: env_probe ...
show more
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: env_probe, scanner_ua, source_backup, actuator, ignition_debug, config_backup. Observed by 1 sensor(s); 42 hits.
show less
Hacking
Web App Attack
๐บ๐ธ
Rocky Mountain Bioengineering Symposium
2026-09-01 07:53:05
(1 day ago)
[Tue Sep 01 01:53:05.599145 2026] [authz_core:error] [pid 110660:tid 140667602781760] [client 35.198 ...
show more
[Tue Sep 01 01:53:05.599145 2026] [authz_core:error] [pid 110660:tid 140667602781760] [client 35.198.12.206:33526] AH01630: client denied by server configuration: /var/www/horde/wp-config.php~
[Tue Sep 01 01:53:05.604607 2026] [authz_core:error] [pid 110661:tid 140670127015488] [client 35.198.12.206:33572] AH01630: client denied by server configuration: /var/www/horde/wp-config.php.swp
[Tue Sep 01 01:53:05.607223 2026] [authz_core:error] [pid 110661:tid 140667569243712] [client 35.198.12.206:33624] AH01630: client denied by server configuration: /var/www/horde/wp-config.php.bak
...
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-01 07:39:20
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.198.12.206 (206.12.198.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.198.12.206 (206.12.198.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 03:39:17.621722 2026] [security2:error] [pid 26030:tid 26030] [client 35.198.12.206:46974] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "yukitex.net"] [uri "/.env.example"] [unique_id "apaBJXL1nUNRgt6i5x6YsQAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ท
dominioz
2026-09-01 05:07:40
(1 day ago)
2026-09-01 05:06:48 GET /.env.production - - 35.198.12.206 HTTP/1.1 crusader-worker/1.0 - 404 5308
2 ...
show more
2026-09-01 05:06:48 GET /.env.production - - 35.198.12.206 HTTP/1.1 crusader-worker/1.0 - 404 5308
2026-09-01 05:06:48 GET /.env.bak - - 35.198.12.206 HTTP/1.1 crusader-worker/1.0 - 404 5149
2026-09-01 05:06:48 GET /wp-config.php.bak - - 35.198.12.206 HTTP/1.1 crusader-worker/1.0 - 404 5167
2026-09-01 05:06:48 GET /.env.old - - 35.198.12.206 HTTP/1.1 crusader-worker/1.0 - 404 5149
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 04:35:48
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.198.12.206 (206.12.198.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.198.12.206 (206.12.198.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 00:35:43.531577 2026] [security2:error] [pid 31846:tid 31846] [client 35.198.12.206:47612] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "hotpay.co"] [uri "/.env.backup"] [unique_id "apZWHxu7BeeUx0S4y2XIwQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-09-01 04:24:01
(1 day ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐จ๐ญ
zynex
2026-09-01 04:20:00
(1 day ago)
URL Probing: /wp-config.php.bak
Web App Attack
๐จ๐ฆ
polycoda
2026-09-01 04:01:59
(1 day ago)
AutoBlock: ๐ฏ Vulnerability Scanner (Non Decay-Based)
Hacking
Web App Attack