🇳🇱
homeshowdomain.nl
2026-09-08 22:03:58
(12 hours ago)
Auto-ban: >3000 req/min op 2026-09-08
Web App Attack
SSH
Hacking
🇧🇪
cmbplf
2026-09-08 20:40:19
(13 hours ago)
475 requests with url.path *.config/*
219 requests with url.path *.ssh/*
Brute-Force
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-08 19:21:07
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.198.231.118 (118.231.198.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.198.231.118 (118.231.198.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 15:20:58.809068 2026] [security2:error] [pid 6552:tid 6552] [client 35.198.231.118:9836] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.tablerockfriends.com"] [uri "/@fs/.env"] [unique_id "aqBgGnuUaqTMQDaJyiDXZAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 18:55:53
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.198.231.118 (118.231.198.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.198.231.118 (118.231.198.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 14:55:47.352747 2026] [security2:error] [pid 4076383:tid 4076383] [client 35.198.231.118:64892] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.pscc.com"] [uri "/@fs/.env"] [unique_id "aqBaM4NBdQRDnvAS3l3t3QAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
ConsulHosting
2026-09-08 18:53:32
(15 hours ago)
Excessive failed CAPTCHA attempts (CAPTCHA DoS)
Web App Attack
🇫🇷
Octopuce
2026-09-08 18:42:04
(15 hours ago)
Aggressive web search of vulnerable pages: /assets../.env /v2/.env /app/.env /_nuxt/../.env /img../. ...
show more
Aggressive web search of vulnerable pages: /assets../.env /v2/.env /app/.env /_nuxt/../.env /img../.env ...
show less
Web App Attack
🇩🇪
maxpower
2026-09-08 18:40:26
(15 hours ago)
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 35.198.231.118 (SG/Singapore/118.231.198 ...
show more
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 35.198.231.118 (SG/Singapore/118.231.198.35.bc.googleusercontent.com): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 35.198.231.118 - - [08/Sep/2026:20:40:22 +0200] "GET /@fs/root/.aws/credentials?raw?? HTTP/2.0" 200 4826 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; Bytespider; +https://zhanzhang.toutiao.com/" "35.198.231.118" host=villapardi.it
show less
Port Scan
🇪🇸
pipeline.es
2026-09-08 18:33:35
(15 hours ago)
Web scanning / probing for vulnerable paths | URL: /@fs/usr/src/app/.env?raw?? | Evidence: microsite ...
show more
Web scanning / probing for vulnerable paths | URL: /@fs/usr/src/app/.env?raw?? | Evidence: microsites.grupoeuropa.com 35.198.231.118 - - [08/Sep/2026:20:32:31 +0200] \"GET /@fs/usr/src/app/.env?raw?? HTTP/1.1\" 404 - \"-\" \"Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Google-Extended/1.0; +http://www.google.com/bot.html)\" GEOIP_COUNTRY_CODE=SG | ASN: GOOGLE-CLOUD-PLATFORM | Country: SG
show less
Port Scan
Web App Attack
🇫🇷
dynamix
2026-09-08 18:16:03
(16 hours ago)
Multiple WAF Violations
Web App Attack
Anonymous
2026-09-08 17:36:32
(16 hours ago)
Multiple web server 400 error codes from same source ip
Web App Attack
🇩🇪
FD-IX
2026-09-08 17:07:48
(17 hours ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 16:50:45
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.198.231.118 (118.231.198.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.198.231.118 (118.231.198.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 12:50:42.054323 2026] [security2:error] [pid 3385:tid 3385] [client 35.198.231.118:43502] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "shopliddlesports.liddlesports.com"] [uri "/@fs/../.env"] [unique_id "aqA84kxhymH_4AfDl37rSQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇱🇹
Evag Touf
2026-09-08 16:28:56
(17 hours ago)
(mod_security) mod_security triggered on hostname [redacted] 35.198.231.118 (SG/Singapore/118.231.19 ...
show more
(mod_security) mod_security triggered on hostname [redacted] 35.198.231.118 (SG/Singapore/118.231.198.35.bc.googleusercontent.com)
show less
SQL Injection
🇺🇸
TPI-Abuse
2026-09-08 16:01:33
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.198.231.118 (118.231.198.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.198.231.118 (118.231.198.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 12:01:25.249595 2026] [security2:error] [pid 21504:tid 21504] [client 35.198.231.118:20606] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mrappliancefl.com"] [uri "/@fs/src/.env"] [unique_id "aqAxVQOA9Q-aE1tF0VwV7AAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
big-cloud.nl
2026-09-08 15:42:26
(18 hours ago)
Try to access /portal/@fs/src/.env?raw??
Web App Attack