🇲🇽
octageeks.com
2026-09-05 04:11:06
(10 hours ago)
Wordpress malicious attack:[octablocked]
Web App Attack
🇩🇪
palzer.IT
2026-09-04 17:35:56
(20 hours ago)
Fail2ban automatic report for plesk-apache-badbot: 35.229.224.163 - - [04/Sep/2026:19:35:41 +0200] G ...
show more
Fail2ban automatic report for plesk-apache-badbot: 35.229.224.163 - - [04/Sep/2026:19:35:41 +0200] GET /@fs/app/.env?raw?? [DOMAIN_REMOVED] 404 6603 [DOMAIN_REMOVED] Mozilla/5.0 (compatible; GPTBot/1.2; +[DOMAIN_REMOVED]
show less
Bad Web Bot
🇺🇸
rsa
2026-09-04 17:06:00
(21 hours ago)
excessive crawling ddos
DDoS Attack
Bad Web Bot
Web App Attack
🇩🇪
paissangroup
2026-09-04 14:46:10
(23 hours ago)
Multiple WAF Violations
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 14:38:49
(23 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.229.224.163 (163.224.229.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.229.224.163 (163.224.229.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 10:38:42.565803 2026] [security2:error] [pid 20481:tid 20481] [client 35.229.224.163:1154] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "dandemonium.net"] [uri "/@fs/../../.env"] [unique_id "aprX8q6vXGmbRuqbDOhtdAAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
Hazzard
2026-09-04 14:22:44
(23 hours ago)
(mod_security) mod_security triggered on hostname [redacted]): (CF_ENABLE)
SQL Injection
🇩🇪
FeG Deutschland
2026-09-04 14:12:04
(1 day ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 1247
Exploited Host
Web App Attack
🇩🇪
Vegascosmetics
2026-09-04 12:46:32
(1 day ago)
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after sensitive config/credentials exposure ...
show more
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after sensitive config/credentials exposure probe. Evidence: AttackPattern: /\.env (Match: /.env)
show less
Hacking
Brute-Force
Web App Attack
🇩🇪
BlueWire Hosting
2026-09-04 12:32:30
(1 day ago)
High-confidence malicious configuration/VCS probe
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 12:28:16
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.229.224.163 (163.224.229.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.229.224.163 (163.224.229.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 08:28:09.715243 2026] [security2:error] [pid 4368:tid 4368] [client 35.229.224.163:27098] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.title36.com"] [uri "/@fs/..%252f..%252f..%252f..%252f..%252fapp/.env"] [unique_id "apq5WdYVifd1Mjm3bH2nowAAACI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇵🇱
strefapi_com
2026-09-04 11:06:57
(1 day ago)
Brute-force, web
...
Hacking
Brute-Force
Web App Attack
🇫🇮
pixiekat
2026-09-04 10:50:10
(1 day ago)
[Fri Sep 04 11:50:02.225952 2026] [authz_core:error] [pid 965303:tid 965383] [client 35.229.224.163: ...
show more
[Fri Sep 04 11:50:02.225952 2026] [authz_core:error] [pid 965303:tid 965383] [client 35.229.224.163:43254] AH01630: client denied by server configuration: /mnt/HC_Volume_105148208/vhosts/baikal/html/
[Fri Sep 04 11:50:02.469883 2026] [authz_core:error] [pid 965303:tid 965402] [client 35.229.224.163:43254] AH01630: client denied by server configuration: /mnt/HC_Volume_105148208/vhosts/baikal/html/, referer: http://dav.spacecadetgrrl.me/
[Fri Sep 04 11:50:09.736044 2026] [authz_core:error] [pid 965303:tid 965420] [client 35.229.224.163:43288] AH01630: client denied by server configuration: /mnt/HC_Volume_105148208/vhosts/baikal/html/@fs
[Fri Sep 04 11:50:09.736044 2026] [authz_core:error] [pid 965304:tid 965395] [client 35.229.224.163:43412] AH01630: client denied by server configuration: /mnt/HC_Volume_105148208/vhosts/baikal/html/@fs
[Fri Sep 04 11:50:09.737984 2026] [authz_core:error] [pid 965304:tid 965393] [client 35.229.224.163:43272] AH01630: client denied by server configuration:
...
show less
Brute-Force
🇳🇱
ConsulHosting
2026-09-04 09:44:03
(1 day ago)
Excessive failed CAPTCHA attempts (CAPTCHA DoS)
Web App Attack
Anonymous
2026-09-04 09:28:39
(1 day ago)
Web application attack detected.
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 08:37:28
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.229.224.163 (163.224.229.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.229.224.163 (163.224.229.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 04:37:22.594817 2026] [security2:error] [pid 5295:tid 5295] [client 35.229.224.163:17588] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.starrmail.net"] [uri "/@fs/.env"] [unique_id "apqDQjpIxL7hn7NDcFh36wAAACE"]
show less
Brute-Force
Bad Web Bot
Web App Attack