π³π±
Mangelot Hosting
2026-09-01 23:31:38
(16 hours ago)
(modsecurity) srv103 ModSecurity 35.203.73.64 (CA/Canada/64.73.203.35.bc.googleusercontent.com): 30 ...
show more
(modsecurity) srv103 ModSecurity 35.203.73.64 (CA/Canada/64.73.203.35.bc.googleusercontent.com): 30 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs:
show less
Web App Attack
π³π±
homeshowdomain.nl
2026-09-01 22:01:00
(18 hours ago)
Auto-ban: >3000 req/min op 2026-09-01
Web App Attack
SSH
Hacking
πΊπΈ
TPI-Abuse
2026-09-01 13:50:21
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.203.73.64 (64.73.203.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.203.73.64 (64.73.203.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 09:50:07.920749 2026] [security2:error] [pid 31275:tid 31275] [client 35.203.73.64:36610] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.linfischer.com"] [uri "/.env.prod"] [unique_id "apbYD1J6strtwz6Rd9VPPAAAACg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
XICTRON
2026-09-01 13:05:05
(1 day ago)
ModSecurity rule violation detected by Fail2Ban
Web App Attack
π¨πΏ
akac
2026-09-01 13:01:11
(1 day ago)
Web vulnerability scanning: HTTP/1.1 GET /actuator/configprops
Hacking
Brute-Force
Bad Web Bot
Web App Attack
π¬π§
Aetherweb Ark
2026-09-01 12:29:04
(1 day ago)
(mod_security) mod_security (id:949110) triggered by 35.203.73.64 (CA/Canada/64.73.203.35.bc.googleu ...
show more
(mod_security) mod_security (id:949110) triggered by 35.203.73.64 (CA/Canada/64.73.203.35.bc.googleusercontent.com): N in the last X secs
show less
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-01 10:56:00
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.203.73.64 (64.73.203.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.203.73.64 (64.73.203.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 06:55:52.155237 2026] [security2:error] [pid 12565:tid 12565] [client 35.203.73.64:35936] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.itaxcenter.com"] [uri "/.env.production"] [unique_id "apavOA0UnP8muzetc6eUSgAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
maxxsense
2026-09-01 10:20:17
(1 day ago)
35.203.73.64 (CA/Canada/64.73.203.35.bc.googleusercontent.com), more than 10 Apache 403 hits
Hacking
π¨π¦
SoteriaCovenant
2026-09-01 09:43:21
(1 day ago)
Automated probe: /.env.save on Soteria Global infrastructure. No vulnerable software present.
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-01 09:38:11
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.203.73.64 (64.73.203.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.203.73.64 (64.73.203.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 05:38:04.122065 2026] [security2:error] [pid 30359:tid 30359] [client 35.203.73.64:53464] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "spiritcountry.cc"] [uri "/.env"] [unique_id "apac_I_xcFdmAmlAtLeuMQAAACE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
LRob
2026-09-01 09:14:40
(1 day ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /wp-config.php.bak (+12 more) | 2026-09-01 09:14 UTC
show less
Hacking
Web App Attack
π©πͺ
sdos.es
2026-09-01 08:44:45
(1 day ago)
"URL file extension is restricted by policy - .backup"
Web App Attack
π©πͺ
Vegascosmetics
2026-09-01 08:31:05
(1 day ago)
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after PHP/CMS/webshell exploit probe (possi ...
show more
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after PHP/CMS/webshell exploit probe (possible exploited host). Evidence: AttackPattern: /wp-config\.php (Match: /wp-config.php)
show less
Hacking
Exploited Host
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-01 07:44:52
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.203.73.64 (64.73.203.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.203.73.64 (64.73.203.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 03:44:44.764388 2026] [security2:error] [pid 8265:tid 8265] [client 35.203.73.64:53842] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ftp.baker15.com"] [uri "/.env.production"] [unique_id "apaCbEWzWINN8E0Hmk_RagAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΈπͺ
vaia.cloud
2026-09-01 07:10:05
(1 day ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack