🇳🇱
homeshowdomain.nl
2026-09-04 22:00:44
(20 hours ago)
Auto-ban: >3000 req/min op 2026-09-04
Web App Attack
SSH
Hacking
🇺🇸
TPI-Abuse
2026-09-04 15:16:15
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.229.158.215 (215.158.229.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.229.158.215 (215.158.229.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 11:16:08.890585 2026] [security2:error] [pid 9885:tid 9885] [client 35.229.158.215:34780] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.sneedvillefarmersmarket.com"] [uri "/.env"] [unique_id "aprguBoI-2Pt0wOj14hwogAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 14:12:21
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.229.158.215 (215.158.229.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.229.158.215 (215.158.229.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 10:12:14.555211 2026] [security2:error] [pid 31887:tid 31887] [client 35.229.158.215:44644] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.inspiringindividualindustry.com"] [uri "/.env.production"] [unique_id "aprRvjFAnNzklv90pHk-vAAAAEM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
itsolon
2026-09-04 14:08:57
(1 day ago)
[04/Sep/2026:16:08:57 +0200] 178853093773.215354 35.229.158.215 45540 217.154.7.177 443
[04/Sep/2026 ...
show more
[04/Sep/2026:16:08:57 +0200] 178853093773.215354 35.229.158.215 45540 217.154.7.177 443
[04/Sep/2026:16:08:57 +0200] 17885309370.587188 35.229.158.215 45554 217.154.7.177 443
[04/Sep/2026:16:08:57 +0200] 178853093753.825679 35.229.158.215 45580 217.154.7.177 443
[04/Sep/2026:16:08:57 +0200] 178853093742.933289 35.229.158.215 45474 217.154.7.177 443
[04/Sep/2026:16:08:57 +0200] 178853093780.084302 35.229.158.215 45524 217.154.7.177 443
...
show less
Port Scan
Hacking
Brute-Force
Web App Attack
🇩🇪
maxpower
2026-09-04 13:32:08
(1 day ago)
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 35.229.158.215 (TW/Taiwan/215.158.229.35 ...
show more
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 35.229.158.215 (TW/Taiwan/215.158.229.35.bc.googleusercontent.com): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 35.229.158.215 - - [04/Sep/2026:15:32:03 +0200] "GET /wp-config.php.bak HTTP/1.1" 403 146 "-" "crusader-worker/1.0" "-" host=spazioitaliaarteinmovimento.it
show less
Port Scan
🇩🇪
FD-IX
2026-09-04 13:29:06
(1 day ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
🇫🇷
masterguru
2026-09-04 11:15:35
(1 day ago)
Restricted File Access Attempt. Matched phrase ".env" at REQUEST_FILENAME. (930130-195)
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 10:15:19
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.229.158.215 (215.158.229.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.229.158.215 (215.158.229.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 06:15:12.923972 2026] [security2:error] [pid 15507:tid 15507] [client 35.229.158.215:36662] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jamesrobertparish.com"] [uri "/.env.dev"] [unique_id "apqaMAMB46S-CICGxyh98gAAACg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
netclix.gr
2026-09-04 09:57:19
(1 day ago)
(mod_security) mod_security triggered on hostname [redacted] 35.229.158.215 (TW/Taiwan/215.158.229.3 ...
show more
(mod_security) mod_security triggered on hostname [redacted] 35.229.158.215 (TW/Taiwan/215.158.229.35.bc.googleusercontent.com): (CF_ENABLE)
show less
SQL Injection
🇸🇪
vaia.cloud
2026-09-04 09:55:01
(1 day ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
🇳🇱
WeCloudit-Anti-Abuse
2026-09-04 08:29:53
(1 day ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
🇳🇱
MyGlobalFlowers
2026-09-04 08:08:44
(1 day ago)
Multiple WAF Violations
Web App Attack
Anonymous
2026-09-04 07:45:24
(1 day ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-04 07:44:29
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.229.158.215 (215.158.229.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.229.158.215 (215.158.229.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 03:44:24.689388 2026] [security2:error] [pid 32596:tid 32596] [client 35.229.158.215:43530] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ftp.colorwize.com"] [uri "/wp-config.php~"] [unique_id "app22Ncrka9io0ylDxvWHQAAAD4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
BlueWire Hosting
2026-09-04 07:23:26
(1 day ago)
High-confidence malicious configuration/VCS probe
Web App Attack