๐ณ๐ฑ
homeshowdomain.nl
2026-09-08 22:00:54
(1 week ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-09-07.
show less
Web App Attack
SSH
Hacking
๐ณ๐ฑ
homeshowdomain.nl
2026-09-07 22:00:44
(1 week ago)
Auto-ban: >3000 req/min op 2026-09-07
Web App Attack
SSH
Hacking
๐บ๐ธ
WellSpring
2026-09-07 20:47:09
(1 week ago)
env leak on 401.today/@fs/var/www/.env โ WellSpr.ing/NetSentinel civic-AI security layer
Web App Attack
๐ง๐ช
cmbplf
2026-09-07 20:02:42
(1 week ago)
330 requests with url.path *credentials.json
Brute-Force
Bad Web Bot
Anonymous
2026-09-07 19:55:13
(1 week ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
๐ฉ๐ช
big-cloud.nl
2026-09-07 19:29:40
(1 week ago)
Try to access /@fs/root/.env?raw??
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-07 19:18:59
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 35.202.243.25 (25.243.202.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.202.243.25 (25.243.202.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 15:18:51.923647 2026] [security2:error] [pid 8074:tid 8074] [client 35.202.243.25:36716] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sedemo.xyz"] [uri "/@fs/..%252f..%252f..%252f..%252f..%252froot/.env"] [unique_id "ap8OG_UF1uJPmbIu_MEXfQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-07 18:29:40
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 35.202.243.25 (25.243.202.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.202.243.25 (25.243.202.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 14:29:31.785409 2026] [security2:error] [pid 14404:tid 14404] [client 35.202.243.25:29692] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.vaxd.org"] [uri "/@fs/.env.production"] [unique_id "ap8Ci1yNiynayjfRp_jC-wAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
Origon
2026-09-07 18:21:55
(1 week ago)
http-probing - IP: 35.202.243.25 - time="2026-09-07T20:21:54+02:00" level=info msg="(555f66b4f6a745 ...
show more
http-probing - IP: 35.202.243.25 - time="2026-09-07T20:21:54+02:00" level=info msg="(555f66b4f6a74558bc11e3f93469658es8App0Mcc0TKEeje/crowdsec) crowdsecurity/http-probing by ip 35.202.243.25 (US/396982) : 4h ban on Ip 35.202.243.25" module=db
show less
Web App Attack
๐ฉ๐ช
Hazzard
2026-09-07 18:17:42
(1 week ago)
(mod_security) mod_security triggered on hostname [redacted]): (CF_ENABLE)
SQL Injection
๐ฉ๐ช
maxpower
2026-09-07 18:06:37
(1 week ago)
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 35.202.243.25 (US/United States/25.243.2 ...
show more
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 35.202.243.25 (US/United States/25.243.202.35.bc.googleusercontent.com): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 35.202.243.25 - - [07/Sep/2026:20:06:35 +0200] "GET /@fs/root/.aws/credentials.backup?raw?? HTTP/1.1" 200 11941 "-" "Mozilla/5.0 (Windows NT 10.0; rv:105.12) Gecko/20100101 Firefox/105.12; compatible; Perplexity-User/1.0; +https://perplexity.ai/perplexity-user" "-" host=lifequalitybb.com
show less
Port Scan
๐ซ๐ท
Octopuce
2026-09-07 17:26:23
(1 week ago)
Aggressive web search of vulnerable pages: /.env.local /.docker/.env /assets../.env /img../.env /v2/ ...
show more
Aggressive web search of vulnerable pages: /.env.local /.docker/.env /assets../.env /img../.env /v2/.env ...
show less
Web App Attack
๐ซ๐ท
Omar Martรญnez
2026-09-07 17:06:21
(1 week ago)
[Mon Sep 07 11:06:02.689336 2026] [core:error] [pid 2387534:tid 139863982593600] [client 35.202.243. ...
show more
[Mon Sep 07 11:06:02.689336 2026] [core:error] [pid 2387534:tid 139863982593600] [client 35.202.243.25:8738] AH10244: invalid URI path (/@fs/../../.env?raw??)
[Mon Sep 07 11:06:19.783178 2026] [core:error] [pid 2387533:tid 139863428937280] [client 35.202.243.25:29796] AH10244: invalid URI path (/@fs/../../../../../app/.env?raw??)
...
show less
Phishing
Email Spam
Blog Spam
๐บ๐ธ
TPI-Abuse
2026-09-07 17:05:50
(1 week ago)
(mod_security) mod_security (id:949110) triggered by 35.202.243.25 (25.243.202.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:949110) triggered by 35.202.243.25 (25.243.202.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 13:05:44.036313 2026] [security2:error] [pid 6500:tid 6500] [client 35.202.243.25:9116] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 20)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "krupaandsons.com"] [uri "/@fs/..%2f..%2f..%2f..%2f..%2froot/.env"] [unique_id "ap7u6E-frneSpLKKkp1JawAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
VHosting
2026-09-07 16:45:04
(1 week ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack