🇳🇱
homeshowdomain.nl
2026-08-29 22:01:32
(1 hour ago)
Auto-ban: >3000 req/min op 2026-08-29
Web App Attack
SSH
Hacking
🇩🇪
psauxit
2026-08-29 20:21:49
(2 hours ago)
Fail2Ban - NGINX heavily bad-bot, possible vulnerability scanning and excessive crawling/scraping
Bad Web Bot
Web App Attack
Hacking
Web Spam
Anonymous
2026-08-29 18:50:54
(4 hours ago)
XSS Attempt
Hacking
🇫🇮
paissangroup
2026-08-29 13:27:56
(9 hours ago)
Multiple WAF Violations
Web App Attack
🇺🇸
TPI-Abuse
2026-08-29 10:54:22
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.221.212.112 (112.212.221.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.221.212.112 (112.212.221.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 06:54:14.679352 2026] [security2:error] [pid 6958:tid 6958] [client 35.221.212.112:58660] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.abneyfoundation.org"] [uri "/@fs/.env"] [unique_id "apK6VrLG-e-Zjv2HnK1KvAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-29 10:14:22
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.221.212.112 (112.212.221.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.221.212.112 (112.212.221.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 06:14:14.915512 2026] [security2:error] [pid 571:tid 571] [client 35.221.212.112:19090] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.openheartwellness.com"] [uri "/@fs/root/.env"] [unique_id "apKw9trYfxoOfSeAkESncQAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇧🇷
noconex
2026-08-29 09:21:08
(13 hours ago)
Wazuh Alert | Rule ID: 110100 | Desc: Suricata: Exploit (ET WEB_SPECIFIC_APPS Vite Arbitrary File Re ...
show more
Wazuh Alert | Rule ID: 110100 | Desc: Suricata: Exploit (ET WEB_SPECIFIC_APPS Vite Arbitrary File Read Via raw parameter (CVE-2025-30208)) 35.221.212.112
show less
Port Scan
Brute-Force
SSH
Anonymous
2026-08-29 09:05:47
(14 hours ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
🇺🇸
factor1
2026-08-29 08:42:33
(14 hours ago)
CrowdSec at churndash Reports Abuse
Web App Attack
Anonymous
2026-08-29 08:05:02
(15 hours ago)
35.221.212.112 - - [29/Aug/2026:10:04:02 +0200] "GET HTTP/1.1" 403 1852 "-" "Mozilla/5.0 (Windows N ...
show more
35.221.212.112 - - [29/Aug/2026:10:04:02 +0200] "GET HTTP/1.1" 403 1852 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:143.17) Gecko/20100101 Firefox/143.17; compatible; ChatGPT-User/1.0; +https://openai.com/bot"
show less
Web Spam
Blog Spam
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-08-29 07:46:30
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.221.212.112 (112.212.221.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.221.212.112 (112.212.221.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 03:46:26.570501 2026] [security2:error] [pid 32171:tid 32252] [client 35.221.212.112:47878] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.oftv.xyz"] [uri "/@fs/..%252f..%252f..%252f..%252f..%252froot/.env"] [unique_id "apKOUoxx2nDuXBTwmDBt2wAAANM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-29 07:30:10
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.221.212.112 (112.212.221.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.221.212.112 (112.212.221.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 03:30:03.540951 2026] [security2:error] [pid 28247:tid 28247] [client 35.221.212.112:1460] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.pointillistic.com"] [uri "/@fs/.env"] [unique_id "apKKe2S3PxIqNDw5l_DIKwAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
e.fierstra
2026-08-29 07:19:40
(15 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
🇮🇹
mediarama.com
2026-08-29 07:08:20
(15 hours ago)
Banned by Fail2Ban
Web App Attack
🇺🇸
TPI-Abuse
2026-08-29 06:49:15
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.221.212.112 (112.212.221.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.221.212.112 (112.212.221.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 02:49:10.246625 2026] [security2:error] [pid 17316:tid 17316] [client 35.221.212.112:50024] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.sacoriverjazz.org"] [uri "/@fs/app/.env"] [unique_id "apKA5ijWzXdVGSHnq5zmWAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack