🇫🇷
✨
2026-08-29 02:30:11
(19 hours ago)
Domain : allavecchiapescheria.com
Rule : hack
2026-08-29 02:28:23 ***hidden-privacy*** GET /wp-confi ...
show more
Domain : allavecchiapescheria.com
Rule : hack
2026-08-29 02:28:23 ***hidden-privacy*** GET /wp-config.php.bak - 443 - 35.225.66.22 HTTP/1.1 crusader-worker/1.0 - allavecchiapescheria.com 404 0 2 444 113 156 - -
show less
Hacking
SQL Injection
Brute-Force
🇺🇸
TPI-Abuse
2026-08-29 01:34:32
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.225.66.22 (22.66.225.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.225.66.22 (22.66.225.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 21:34:26.149472 2026] [security2:error] [pid 11766:tid 11766] [client 35.225.66.22:50340] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.sprayrealty.com"] [uri "/.env.bak"] [unique_id "apI3Irl3A0FFHdf2wl4GXAAAACU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
masterguru
2026-08-29 00:41:34
(20 hours ago)
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 35.225.66.22 (US/United States/22.66. ...
show more
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 35.225.66.22 (US/United States/22.66.225.35.bc.googleusercontent.com): 2 in the last 3600 secs (0-196)
show less
Hacking
🇳🇿
Tripwire
2026-08-28 23:51:34
(21 hours ago)
Scanning for exploits - /.env.bak
Web App Attack
Anonymous
2026-08-28 23:39:17
(21 hours ago)
apache-auth
Brute-Force
Web App Attack
Anonymous
2026-08-28 23:09:57
(22 hours ago)
Auto-reported by Fail2Ban (NPM-Auth)
Web App Attack
🇩🇪
big-cloud.nl
2026-08-28 22:33:06
(22 hours ago)
Try to access /.env
Web App Attack
🇺🇸
TPI-Abuse
2026-08-28 22:19:25
(23 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.225.66.22 (22.66.225.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.225.66.22 (22.66.225.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 18:19:20.106268 2026] [security2:error] [pid 9778:tid 9778] [client 35.225.66.22:50272] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "eaglesnestbandb.com"] [uri "/.env.backup"] [unique_id "apIJaGDHYma0V6bc5rczKgAAAC8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
dynamix
2026-08-28 22:06:27
(23 hours ago)
Multiple WAF Violations
Web App Attack
🇳🇱
homeshowdomain.nl
2026-08-28 22:02:50
(23 hours ago)
Auto-ban: >3000 req/min op 2026-08-28
Web App Attack
SSH
Hacking
🇺🇸
TPI-Abuse
2026-08-28 21:52:43
(23 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.225.66.22 (22.66.225.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.225.66.22 (22.66.225.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 17:52:38.422277 2026] [security2:error] [pid 25914:tid 25914] [client 35.225.66.22:45152] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "derek-stites.com"] [uri "/.env.bak"] [unique_id "apIDJvuvtKxedLOYW12R5gAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
e.fierstra
2026-08-28 21:42:22
(23 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-28 21:01:48
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 35.225.66.22 (22.66.225.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 35.225.66.22 (22.66.225.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 17:01:41.966981 2026] [security2:error] [pid 19430:tid 19430] [client 35.225.66.22:0] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mail.sistememail.com|F|2"] [data ".log"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mail.sistememail.com"] [uri "/storage/logs/laravel.log"] [unique_id "apH3NWD5Q2VVcnxFJTxuXAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
WeCloudit-Anti-Abuse
2026-08-28 20:28:11
(1 day ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-08-28 19:44:43
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.225.66.22 (22.66.225.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.225.66.22 (22.66.225.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 15:44:35.079121 2026] [security2:error] [pid 31852:tid 31852] [client 35.225.66.22:43218] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.uniquetreasuresshops.com.uniquetreasuresshoppes.com"] [uri "/wp-config.php.bak"] [unique_id "apHlI5xyL885Ha7P0pcnWwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack