🇳🇱
homeshowdomain.nl
2026-09-04 22:01:50
(7 hours ago)
Auto-ban: >3000 req/min op 2026-09-04
Web App Attack
SSH
Hacking
🇺🇸
TPI-Abuse
2026-09-04 15:14:47
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.203.64.246 (246.64.203.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.203.64.246 (246.64.203.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 11:14:40.123738 2026] [security2:error] [pid 21344:tid 21344] [client 35.203.64.246:58158] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "crystaljohns.com.my-spec.com"] [uri "/wp-config.php~"] [unique_id "aprgYFQrSOp1KYKy9jrk9QAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
Hazzard
2026-09-04 15:00:42
(14 hours ago)
(mod_security) mod_security triggered on hostname [redacted]): (CF_ENABLE)
SQL Injection
Anonymous
2026-09-04 14:58:07
(14 hours ago)
[da.kdns.gr] httpd-config-scan: sites=www.pikoulis.gr; logs=/var/log/httpd/domains/pikoulis.gr.log; ...
show more
[da.kdns.gr] httpd-config-scan: sites=www.pikoulis.gr; logs=/var/log/httpd/domains/pikoulis.gr.log; samples=/.env.production | /.env.bak | /.env.local
show less
Hacking
Web App Attack
🇫🇷
dynamix
2026-09-04 14:53:43
(14 hours ago)
Multiple WAF Violations
Web App Attack
Anonymous
2026-09-04 14:15:02
(15 hours ago)
suspicious request in access.log
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 14:07:56
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.203.64.246 (246.64.203.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.203.64.246 (246.64.203.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 10:07:48.896383 2026] [security2:error] [pid 4355:tid 4366] [client 35.203.64.246:35850] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.thedowntonstory.com"] [uri "/.env"] [unique_id "aprQtMKZoYaNsgIbwhu-LQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 13:43:33
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.203.64.246 (246.64.203.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.203.64.246 (246.64.203.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 09:43:26.582119 2026] [security2:error] [pid 26446:tid 26446] [client 35.203.64.246:40850] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "icl1.org"] [uri "/.env.bak"] [unique_id "aprK_j3fM4dSWfBU9dNwSwAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
WeCloudit-Anti-Abuse
2026-09-04 13:27:16
(16 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
Anonymous
2026-09-04 13:27:10
(16 hours ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
🇩🇪
FD-IX
2026-09-04 13:25:40
(16 hours ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 13:18:18
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.203.64.246 (246.64.203.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.203.64.246 (246.64.203.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 09:18:12.938870 2026] [security2:error] [pid 12684:tid 12684] [client 35.203.64.246:51096] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "stuartpearson.net"] [uri "/.env.local"] [unique_id "aprFFAl9q377vYOz_8K1JAAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
maxpower
2026-09-04 13:16:27
(16 hours ago)
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 35.203.64.246 (CA/Canada/246.64.203.35.b ...
show more
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 35.203.64.246 (CA/Canada/246.64.203.35.bc.googleusercontent.com): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 35.203.64.246 - - [04/Sep/2026:15:16:25 +0200] "GET /wp-config.php.bak HTTP/1.1" 403 146 "-" "crusader-worker/1.0" "-" host=stefanomarchegiani.com
show less
Port Scan
🇬🇧
Aetherweb Ark
2026-09-04 12:33:04
(17 hours ago)
(mod_security) mod_security (id:949110) triggered by 35.203.64.246 (CA/Canada/246.64.203.35.bc.googl ...
show more
(mod_security) mod_security (id:949110) triggered by 35.203.64.246 (CA/Canada/246.64.203.35.bc.googleusercontent.com): N in the last X secs
show less
Web App Attack
🇩🇪
FeG Deutschland
2026-09-04 12:31:03
(17 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack