๐ณ๐ฑ
homeshowdomain.nl
2026-08-01 21:59:08
(2 hours ago)
Auto-ban: >3000 req/min op 2026-08-01
Web App Attack
SSH
Hacking
๐บ๐ธ
TPI-Abuse
2026-08-01 17:11:05
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.220.149.2 (2.149.220.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.220.149.2 (2.149.220.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 13:10:56.865091 2026] [security2:error] [pid 5040:tid 5040] [client 35.220.149.2:55804] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "economy-cleaners.walkerweb.com"] [uri "/.env.dev"] [unique_id "am4ooNGYKDI2tN05UbKUJQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-01 17:00:04
(7 hours ago)
suspicious request in access.log
Web App Attack
๐ต๐ซ
www.gregorymariani.com
2026-08-01 16:10:31
(8 hours ago)
35.220.149.2 - - [01/Aug/2026:16:10:30 +0000] "GET /.env HTTP/1.1" 404 4036 "-" "crusader-worker/1.0 ...
show more
35.220.149.2 - - [01/Aug/2026:16:10:30 +0000] "GET /.env HTTP/1.1" 404 4036 "-" "crusader-worker/1.0" 399 0.010 [default-techdata-service-80] [] 10.244.7.82:3000 4036 0.010 404 97e46fb2eb59919734ae8da5d669b9df
35.220.149.2 - - [01/Aug/2026:16:10:30 +0000] "GET /.env.prod HTTP/1.1" 404 4036 "-" "crusader-worker/1.0" 404 0.017 [default-techdata-service-80] [] 10.244.7.82:3000 4036 0.017 404 6369d7f61403244df77232816acfd8b8
35.220.149.2 - - [01/Aug/2026:16:10:30 +0000] "GET /.env.backup HTTP/1.1" 404 4036 "-" "crusader-worker/1.0" 406 0.033 [default-techdata-service-80] [] 10.244.7.82:3000 4036 0.033 404 b049536ee635fbba92c7b90abb44e595
35.220.149.2 - - [01/Aug/2026:16:10:30 +0000] "GET /.env.local HTTP/1.1" 404 4036 "-" "crusader-worker/1.0" 405 0.024 [default-techdata-service-80] [] 10.244.7.82:3000 4036 0.024 404 060803a6605870fed40baadcb8cfce86
35.220.149.2 - - [01/Aug/2026:16:10:30 +0000] "GET /.env.save HTTP/1.1" 404 4038 "-" "crusader-worker/1.0" 404 0.031 [default-techdata-service
...
show less
Web App Attack
๐ฒ๐พ
Rizzy
2026-08-01 16:01:40
(8 hours ago)
Multiple WAF Violations
Brute-Force
Web App Attack
๐ซ๐ท
COMAITE
2026-08-01 15:52:12
(8 hours ago)
Suspicious URL access.
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-01 15:44:48
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.220.149.2 (2.149.220.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.220.149.2 (2.149.220.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 11:44:42.485637 2026] [security2:error] [pid 576197:tid 576197] [client 35.220.149.2:52218] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.styxtake2.grayhost.net"] [uri "/.env.example"] [unique_id "am4UalvM_z9kqMfivATu4AAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
billfor
2026-08-01 15:43:31
(8 hours ago)
35.220.149.2 - - [01/Aug/2026:11:43:24 -0400] "GET /.env.production HTTP/1.1" 404 0 "-" "crusader-wo ...
show more
35.220.149.2 - - [01/Aug/2026:11:43:24 -0400] "GET /.env.production HTTP/1.1" 404 0 "-" "crusader-worker/1.0"
show less
Web App Attack
๐ซ๐ฎ
23p02732
2026-08-01 15:40:22
(8 hours ago)
Mailserver and mailaccount attacks
Brute-Force
Bad Web Bot
Exploited Host
Web App Attack
๐ณ๐ฑ
SysAdmin Dylan
2026-08-01 15:11:42
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.220.149.2 (HK/Hong Kong/2.149.220.35.bc.goog ...
show more
(mod_security) mod_security (id:210492) triggered by 35.220.149.2 (HK/Hong Kong/2.149.220.35.bc.googleusercontent.com): 10 in the last 3600 secs
show less
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-08-01 15:00:06
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.220.149.2 (2.149.220.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.220.149.2 (2.149.220.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 10:59:56.856580 2026] [security2:error] [pid 21993:tid 21993] [client 35.220.149.2:57424] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "almudenastrust.com"] [uri "/.env.old"] [unique_id "am4J7BHmAPRTIaHV9JljHwAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-01 14:23:27
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.220.149.2 (2.149.220.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.220.149.2 (2.149.220.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 10:23:21.213565 2026] [security2:error] [pid 519999:tid 520020] [client 35.220.149.2:60418] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.fiefseigneur.com.aafm.us"] [uri "/.env.old"] [unique_id "am4BWXzSukvczWW5hLFmRgAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-01 13:39:03
(10 hours ago)
Bot / scanning and/or hacking attempts: GET /.env.production HTTP/1.1, GET /.env.bak HTTP/1.1, GET / ...
show more
Bot / scanning and/or hacking attempts: GET /.env.production HTTP/1.1, GET /.env.bak HTTP/1.1, GET /.env.dev HTTP/1.1, GET /.env.local HTTP/1.1, GET /.env.example HTTP/1.1, GET /.env HTTP/1.1, GET /.env.prod HTTP/1.1, GET /.env.save HTTP/1.1, GET /.env.backup HTTP/1.1, GET /.env.old HTTP/1.1
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-01 13:33:01
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.220.149.2 (2.149.220.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.220.149.2 (2.149.220.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 09:32:53.991639 2026] [security2:error] [pid 2010731:tid 2010731] [client 35.220.149.2:42796] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "undergroundh2o.com"] [uri "/.env.save"] [unique_id "am31haMzzTMmkZCzcZ__hwAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-01 12:21:16
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.220.149.2 (2.149.220.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.220.149.2 (2.149.220.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 08:21:09.980404 2026] [security2:error] [pid 23962:tid 23962] [client 35.220.149.2:57626] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "themarshalls.tv"] [uri "/.env.production"] [unique_id "am3ktTqlXQHZzV_HLU537QAAACU"]
show less
Brute-Force
Bad Web Bot
Web App Attack