π³π±
homeshowdomain.nl
2026-08-27 22:01:27
(7 hours ago)
Auto-ban: >3000 req/min op 2026-08-27
Web App Attack
SSH
Hacking
Anonymous
2026-08-27 21:18:49
(7 hours ago)
Web App Attack
π«π·
HerrWolf
2026-08-27 21:15:05
(7 hours ago)
CrowdSec Detection: crowdsecurity/http-probing
Web App Attack
π³π±
tmiland
2026-08-27 20:57:08
(8 hours ago)
(nginx_404) Dot directory Honeypot Trap 35.227.100.140 (US/United States/140.100.227.35.bc.googleuse ...
show more
(nginx_404) Dot directory Honeypot Trap 35.227.100.140 (US/United States/140.100.227.35.bc.googleusercontent.com): 2 in the last 3600 secs; IP: 35.227.100.140; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 35.227.100.140 - - [27/Aug/2026:22:57:06 +0200] "GET /.env.production HTTP/1.1" 404 2992 "-" "crusader-worker/1.0" 35.227.100.140 - - [27/Aug/2026:22:57:06 +0200] "GET /.env.save HTTP/1.1" 404 2992 "-" "crusader-worker/1.0"
show less
Brute-Force
πΊπΈ
TPI-Abuse
2026-08-27 19:19:25
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.227.100.140 (140.100.227.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.227.100.140 (140.100.227.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 15:19:20.283589 2026] [security2:error] [pid 505:tid 505] [client 35.227.100.140:53636] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.lacycustombuilt.com"] [uri "/.env.example"] [unique_id "apCNuF-kbU7VW96XnkTScgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
mnsf
2026-08-27 19:05:39
(10 hours ago)
Abuse Detected (9)
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-27 18:03:10
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.227.100.140 (140.100.227.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.227.100.140 (140.100.227.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 14:03:04.479059 2026] [security2:error] [pid 14516:tid 14516] [client 35.227.100.140:60670] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.playerpianocare.player-care.com"] [uri "/.env.bak"] [unique_id "apB72E0XIIsZ_m2V3XrzxQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
IloGus
2026-08-27 18:00:57
(11 hours ago)
WAF repeated trigger detected by Fail2Ban in plesk-modsecurity jail
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-27 17:46:37
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.227.100.140 (140.100.227.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.227.100.140 (140.100.227.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 13:46:32.403699 2026] [security2:error] [pid 28967:tid 28967] [client 35.227.100.140:49776] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.angelicatrombo.gregorii.com"] [uri "/.env.backup"] [unique_id "apB3-NOeR2Q3tNuzt0YIaAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-27 17:45:41
(11 hours ago)
[ssd5.kdns.gr] httpd-config-scan: logs=/var/log/httpd/access_log; samples=/wp-config.php.swp | /wp-c ...
show more
[ssd5.kdns.gr] httpd-config-scan: logs=/var/log/httpd/access_log; samples=/wp-config.php.swp | /wp-config.php.bak | /actuator/env
show less
Hacking
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-27 17:22:31
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.227.100.140 (140.100.227.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.227.100.140 (140.100.227.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 13:22:23.591498 2026] [security2:error] [pid 32714:tid 32714] [client 35.227.100.140:38182] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cashforjunkcars.info"] [uri "/.env.example"] [unique_id "apByT-XEqMeHhC0p45wH9QAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-27 15:32:17
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.227.100.140 (140.100.227.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.227.100.140 (140.100.227.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 11:32:13.120065 2026] [security2:error] [pid 13912:tid 13912] [client 35.227.100.140:57126] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "fundingworkingcapital.com"] [uri "/.env.local"] [unique_id "apBYfUpSSrect58vWHMzxwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-27 14:55:09
(14 hours ago)
(NGINX) Security rule triggered from 35.227.100.140 (US/United States/140.100.227.35.bc.googleuserco ...
show more
(NGINX) Security rule triggered from 35.227.100.140 (US/United States/140.100.227.35.bc.googleusercontent.com): 5 in the last 3600 secs
show less
Web App Attack
π«π·
Little Iguana
2026-08-27 14:44:24
(14 hours ago)
Attempt to hack Wordpress Login, XMLRPC or other login
Hacking
π³π±
e.fierstra
2026-08-27 14:03:09
(15 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack