🇳🇱
homeshowdomain.nl
2026-09-04 22:03:12
(15 hours ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-09-03.
show less
Web App Attack
SSH
Hacking
🇲🇾
Rizzy
2026-09-04 15:05:33
(22 hours ago)
Multiple WAF Violations
Brute-Force
Web App Attack
Anonymous
2026-09-04 15:02:12
(22 hours ago)
Bot / seems abusive / Apache connections: 26
DDoS Attack
Web Spam
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 14:10:57
(23 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.204.251.40 (40.251.204.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.204.251.40 (40.251.204.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 10:10:49.205553 2026] [security2:error] [pid 25948:tid 25948] [client 35.204.251.40:37958] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kln.ne.jp"] [uri "/@fs/root/.env"] [unique_id "aprRaTt4MO-NYFrkvZ-UbwAAADU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 13:47:21
(23 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.204.251.40 (40.251.204.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.204.251.40 (40.251.204.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 09:47:13.510242 2026] [security2:error] [pid 10804:tid 11076] [client 35.204.251.40:20986] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "dba.center"] [uri "/@fs/root/.env"] [unique_id "aprL4Xe6a7HOMWDEtBx_BwAAAVg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
iNetWorker
2026-09-04 13:37:08
(1 day ago)
trolling for resource vulnerabilities
Web App Attack
🇬🇧
thetomtaylor.co.uk
2026-09-04 12:52:02
(1 day ago)
Fail2Ban - [WAF]ModSecurity rule violation on modsecurity ... [wa01,wa02]
Hacking
SQL Injection
Web App Attack
🇬🇧
Aetherweb Ark
2026-09-04 12:50:13
(1 day ago)
(mod_security) mod_security (id:949110) triggered by 35.204.251.40 (40.251.204.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:949110) triggered by 35.204.251.40 (40.251.204.35.bc.googleusercontent.com): N in the last X secs
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 11:14:44
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.204.251.40 (40.251.204.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.204.251.40 (40.251.204.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 07:14:36.735950 2026] [security2:error] [pid 4034:tid 4034] [client 35.204.251.40:24256] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.varnadorefamily.com"] [uri "/@fs/src/.env"] [unique_id "apqoHJ_nkBQez7XmiRlxawAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
maxpower
2026-09-04 11:05:32
(1 day ago)
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 35.204.251.40 (40.251.204.35.bc.googleus ...
show more
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 35.204.251.40 (40.251.204.35.bc.googleusercontent.com): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 35.204.251.40 - - [04/Sep/2026:13:05:31 +0200] "GET /@fs/root/.aws/credentials.bak?raw?? HTTP/1.1" 200 11930 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko; compatible; TelegramBot/1.0) Chrome/148.0.4622.56 Safari/537.36 Edg/148.0.4622.56" "-" host=qzarfoodandfun.eu.gessoart.it
show less
Port Scan
🇳🇱
e.fierstra
2026-09-04 10:42:34
(1 day ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
🇬🇧
thetomtaylor.co.uk
2026-09-04 10:08:00
(1 day ago)
Fail2Ban - [WEB]Custom exploit pattern detected on customexploits ... [ice01,ice02,wa01,wa02]
Hacking
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 09:46:23
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.204.251.40 (40.251.204.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.204.251.40 (40.251.204.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 05:46:15.422595 2026] [security2:error] [pid 15118:tid 15118] [client 35.204.251.40:62642] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.proyectando.com"] [uri "/@fs/root/.env"] [unique_id "apqTZ_UbFpPiTTI2jVYsMwAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
IRISIO
2026-09-04 09:14:07
(1 day ago)
scans/SQL injection/spam posts : 647 queries
Web App Attack
SQL Injection
🇦🇹
penguin-solutions.at
2026-09-04 07:49:58
(1 day ago)
Excessive 403/404 errors
...
Brute-Force
Web App Attack