🇳🇱
homeshowdomain.nl
2026-08-28 22:01:52
(16 hours ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-08-27.
show less
Web App Attack
SSH
Hacking
🇳🇱
homeshowdomain.nl
2026-08-27 22:01:25
(1 day ago)
Auto-ban: >3000 req/min op 2026-08-27
Web App Attack
SSH
Hacking
🇳🇱
JCB
2026-08-27 21:41:00
(1 day ago)
35.224.212.57 - - [27/Aug/2026:15:32:10 +0300] "GET /wp-config.php.swp HTTP/1.1" 404 456 "-" "crusad ...
show more
35.224.212.57 - - [27/Aug/2026:15:32:10 +0300] "GET /wp-config.php.swp HTTP/1.1" 404 456 "-" "crusader-worker/1.0"
35.224.212.57 - - [27/Aug/2026:15:32:10 +0300] "GET /storage/logs/laravel.log HTTP/1.1" 404 456 "-" "crusader-worker/1.0"
...
show less
Web App Attack
🇦🇺
Starburst SysOp Team
2026-08-27 20:17:37
(1 day ago)
Restricted File Access Attempt. Matched phrase ".env" at REQUEST_FILENAME. (930130-syd2-4)
Hacking
Web App Attack
🇩🇪
Gwyneth Llewelyn
2026-08-27 19:56:47
(1 day ago)
2026/08/27 20:56:36 [error] 380595#380595: *965654 access forbidden by rule, client: 35.224.212.57, ...
show more
2026/08/27 20:56:36 [error] 380595#380595: *965654 access forbidden by rule, client: 35.224.212.57, server: [redacted], request: "GET /.env HTTP/1.1", host: "[redacted]"
35.224.212.57 - - [27/Aug/2026:20:56:36 +0100] "GET /.env HTTP/1.1" 403 2599 "-" "crusader-worker/1.0"
2026/08/27 20:56:45 [error] 380595#380595: *965665 access forbidden by rule, client: 35.224.212.57, server: [redacted], request: "GET //.env HTTP/1.1", host: "[redacted]"
show less
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-08-27 18:45:45
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.224.212.57 (57.212.224.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.224.212.57 (57.212.224.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 14:45:38.068311 2026] [security2:error] [pid 1221:tid 1221] [client 35.224.212.57:44178] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ibook.micahgartman.com"] [uri "/.env.old"] [unique_id "apCF0iDWpcQTbPmfgI5L_gAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-27 18:36:50
(1 day ago)
[server.tmg.gr] httpd-config-scan: sites=www.pulmonaryhypertension2026.gr; logs=/var/log/httpd/domai ...
show more
[server.tmg.gr] httpd-config-scan: sites=www.pulmonaryhypertension2026.gr; logs=/var/log/httpd/domains/pulmonaryhypertension2026.gr.log; samples=/.env.example | /.env.save | /wp-config.php.swp
show less
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-08-27 18:15:17
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.224.212.57 (57.212.224.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.224.212.57 (57.212.224.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 14:15:11.798912 2026] [security2:error] [pid 28406:tid 28406] [client 35.224.212.57:44122] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.favorcakepaperco.com"] [uri "/.env.production"] [unique_id "apB-r44hkfg46dmUAqU64wAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-27 17:56:13
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.224.212.57 (57.212.224.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.224.212.57 (57.212.224.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 13:56:04.969715 2026] [security2:error] [pid 12283:tid 12283] [client 35.224.212.57:43172] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "rotentendales.com"] [uri "/.env.backup"] [unique_id "apB6NBq_4yywWS71Q8G_kwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-27 17:33:24
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.224.212.57 (57.212.224.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.224.212.57 (57.212.224.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 13:33:16.575096 2026] [security2:error] [pid 6512:tid 6512] [client 35.224.212.57:56488] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.itimetable21.com"] [uri "/.env.backup"] [unique_id "apB03EmQfdbKSqDl1uC3pgAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
WeCloudit-Anti-Abuse
2026-08-27 17:31:38
(1 day ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-08-27 16:44:35
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.224.212.57 (57.212.224.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.224.212.57 (57.212.224.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 12:44:31.078625 2026] [security2:error] [pid 21706:tid 21706] [client 35.224.212.57:47424] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.smog-check-pb-san-diego.smogsandiego.com"] [uri "/.env.local"] [unique_id "apBpb9bgpHUqp-YPevXBwwAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇷🇴
iulianh
2026-08-27 14:52:08
(1 day ago)
80,443
Brute-Force
SSH
🇺🇸
TPI-Abuse
2026-08-27 14:32:23
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.224.212.57 (57.212.224.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.224.212.57 (57.212.224.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 10:32:18.855257 2026] [security2:error] [pid 4593:tid 4593] [client 35.224.212.57:59298] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mosinn.is"] [uri "/.env.example"] [unique_id "apBKcn8uKzB2PQdqjYP_OAAAADA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
factor1
2026-08-27 14:31:45
(1 day ago)
CrowdSec at saturn Reports Abuse
Web App Attack