๐ณ๐ฑ
homeshowdomain.nl
2026-09-22 21:59:34
(4 hours ago)
Auto-ban: >3000 req/min op 2026-09-22
Web App Attack
SSH
Hacking
Anonymous
2026-09-22 16:35:02
(10 hours ago)
suspicious request in access.log
Web App Attack
๐ซ๐ท
dynamix
2026-09-22 15:57:43
(10 hours ago)
Multiple WAF Violations
Web App Attack
๐ฉ๐ช
ghostwarriors
2026-09-22 15:50:19
(10 hours ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 15:31:55
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.220.193.72 (72.193.220.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.220.193.72 (72.193.220.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 11:31:50.021258 2026] [security2:error] [pid 8877:tid 8877] [client 35.220.193.72:59394] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "neconebooks.com"] [uri "/.env.local"] [unique_id "arKfZk3JMOQGfZNaCiPnuQAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
yitzhaq
2026-09-22 15:23:06
(11 hours ago)
35.220.193.72 - - [22/Sep/2026:17:22:50 +0200] "GET /wp-config.php~ HTTP/1.1" 303 4555 "-" "crusader ...
show more
35.220.193.72 - - [22/Sep/2026:17:22:50 +0200] "GET /wp-config.php~ HTTP/1.1" 303 4555 "-" "crusader-worker/1.0"
35.220.193.72 - - [22/Sep/2026:17:22:50 +0200] "GET /wp-config.php.bak HTTP/1.1" 303 4561 "-" "crusader-worker/1.0"
35.220.193.72 - - [22/Sep/2026:17:22:50 +0200] "GET /wp-config.php~ HTTP/1.1" 404 4448 "-" "crusader-worker/1.0"
35.220.193.72 - - [22/Sep/2026:17:22:50 +0200] "GET /wp-config.php.bak HTTP/1.1" 404 4447 "-" "crusader-worker/1.0"
35.220.193.72 - - [22/Sep/2026:17:22:50 +0200] "GET /.env.dev HTTP/1.1" 404 4447 "-" "crusader-worker/1.0"
35.220.193.72 - - [22/Sep/2026:17:22:50 +0200] "GET /actuator/configprops HTTP/1.1" 404 4446 "-" "crusader-worker/1.0"
35.220.193.72 - - [22/Sep/2026:17:22:50 +0200] "GET /wp-config.php.swp HTTP/1.1" 404 4446 "-" "crusader-worker/1.0"
35.220.193.72 - - [22/Sep/2026:17:22:50 +0200] "GET /.env.old HTTP/1.1" 404 4447 "-" "crusader-worker/1.0"
35.220.193.72 - - [22/Sep/2026:17:22:50 +0200] "GET /.env.prod HTTP/1.1" 404 4448 "-" "crusad
show less
Web App Attack
Brute-Force
๐ฉ๐ช
Hazzard
2026-09-22 14:52:36
(11 hours ago)
(mod_security) mod_security triggered on hostname [redacted]): (CF_ENABLE)
SQL Injection
Anonymous
2026-09-22 14:39:34
(11 hours ago)
[ns41.kdns.gr] httpd-config-scan: sites=www.loida.digitalproject.gr; logs=/var/log/httpd/domains/dig ...
show more
[ns41.kdns.gr] httpd-config-scan: sites=www.loida.digitalproject.gr; logs=/var/log/httpd/domains/digitalproject.gr.loida.log; samples=/.env.local | /.env.prod | /.env.dev
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 14:31:54
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.220.193.72 (72.193.220.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.220.193.72 (72.193.220.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 10:31:50.483269 2026] [security2:error] [pid 9743:tid 9743] [client 35.220.193.72:37182] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "limobusrichmond.com"] [uri "/.env.bak"] [unique_id "arKRVrJuV53wN9iuwLBzpwAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-22 14:20:27
(12 hours ago)
SIEM ALERT AUTO REPORT
Email Spam
๐ฒ๐พ
Rizzy
2026-09-22 14:04:05
(12 hours ago)
Multiple WAF Violations
Brute-Force
Web App Attack
๐ฌ๐ง
consul.to
2026-09-22 13:03:29
(13 hours ago)
Web attack/malicious scanning detected
Web App Attack
๐ซ๐ท
COMAITE
2026-09-22 13:00:10
(13 hours ago)
Suspicious URL access.
Web App Attack
๐ฉ๐ช
dbmwebdesign
2026-09-22 12:35:03
(14 hours ago)
WAF repeated trigger detected by Fail2Ban in plesk-modsecurity jail
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 12:18:39
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.220.193.72 (72.193.220.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.220.193.72 (72.193.220.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 08:18:34.704472 2026] [security2:error] [pid 25310:tid 25310] [client 35.220.193.72:33310] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "dev.handyrehab.com"] [uri "/.env.old"] [unique_id "arJyGgFeYE11cnRn0y3fjgAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack