๐ณ๐ฑ
homeshowdomain.nl
2026-08-01 21:59:44
(9 hours ago)
Auto-ban: >3000 req/min op 2026-08-01
Web App Attack
SSH
Hacking
๐ซ๐ฎ
mnazibo
2026-08-01 18:00:07
(13 hours ago)
Date: 01/Aug/2026 20:08:00 | Reported IP: 35.221.82.99 mod_security | id: 930130 | JP/group.my_domai ...
show more
Date: 01/Aug/2026 20:08:00 | Reported IP: 35.221.82.99 mod_security | id: 930130 | JP/group.my_domain/- | Connections: 8 | Blocked: Permanent Block: [LF_MODSEC] | URIs: /.env.backup; /.env.bak; /.env.dev; /.env.example; /.env.local; /.env.old; /.env.production; /.env.save | Logs: Restricted File Access Attempt
show less
SQL Injection
Brute-Force
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-08-01 17:33:20
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.221.82.99 (99.82.221.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.221.82.99 (99.82.221.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 13:33:12.478283 2026] [security2:error] [pid 1094142:tid 1094142] [client 35.221.82.99:39026] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "hazardrecords.org"] [uri "/.env"] [unique_id "am4t2IKp3pbnTiS1F5CKJwAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
webanyone
2026-08-01 17:31:02
(13 hours ago)
WAF repeated trigger detected by Fail2Ban in plesk-modsecurity jail
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-01 16:52:27
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.221.82.99 (99.82.221.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.221.82.99 (99.82.221.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 12:52:22.117301 2026] [security2:error] [pid 1014458:tid 1014458] [client 35.221.82.99:48044] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "medicalexchangeasinc.com.hellomdinc.com"] [uri "/.env.old"] [unique_id "am4kRiUk0mF-UBVPBSUrqgAAACw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
big-cloud.nl
2026-08-01 16:38:03
(14 hours ago)
Try to access /.env
Web App Attack
๐ฉ๐ช
Bedios GmbH
2026-08-01 16:32:06
(14 hours ago)
Login credentials theft attempt
Hacking
๐บ๐ธ
TPI-Abuse
2026-08-01 16:12:21
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.221.82.99 (99.82.221.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.221.82.99 (99.82.221.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 12:12:14.456004 2026] [security2:error] [pid 901013:tid 901016] [client 35.221.82.99:48832] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "web21.dnchosting.com"] [uri "/.env.dev"] [unique_id "am4a3smyhF6OCaa2rrPwDQAAAME"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ธ๐ช
vaia.cloud
2026-08-01 15:40:02
(15 hours ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-01 15:35:04
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.221.82.99 (99.82.221.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.221.82.99 (99.82.221.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 11:34:58.475981 2026] [security2:error] [pid 74771:tid 74771] [client 35.221.82.99:52756] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ppc.wisk.org"] [uri "/.env.dev"] [unique_id "am4SIvOYYmiU-NUtUjQnwAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
Inartis
2026-08-01 14:52:31
(16 hours ago)
35.221.82.99 - - [01/Aug/2026:16:52:29 +0200] "GET /.env HTTP/1.1" 404 47123 "-" "crusader-worker/1. ...
show more
35.221.82.99 - - [01/Aug/2026:16:52:29 +0200] "GET /.env HTTP/1.1" 404 47123 "-" "crusader-worker/1.0"
35.221.82.99 - - [01/Aug/2026:16:52:29 +0200] "GET /.env.production HTTP/1.1" 404 47123 "-" "crusader-worker/1.0"
35.221.82.99 - - [01/Aug/2026:16:52:29 +0200] "GET /.env.bak HTTP/1.1" 404 47123 "-" "crusader-worker/1.0"
...
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-08-01 14:24:48
(17 hours ago)
Multiple unauthorized connection attempts
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-01 14:08:08
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.221.82.99 (99.82.221.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.221.82.99 (99.82.221.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 10:08:00.941848 2026] [security2:error] [pid 14038:tid 14038] [client 35.221.82.99:55256] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.ble.zunosaki.com"] [uri "/.env.production"] [unique_id "am39wNWteeUzfgrGPNK6YgAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
consul.to
2026-08-01 13:57:25
(17 hours ago)
Web attack/malicious scanning detected
Web App Attack
Anonymous
2026-08-01 13:35:03
(17 hours ago)
suspicious request in access.log
Web App Attack