🇳🇱
homeshowdomain.nl
2026-09-06 21:59:51
(11 hours ago)
Auto-ban: >3000 req/min op 2026-09-06
Web App Attack
SSH
Hacking
🇫🇷
Kraften
2026-09-06 09:02:06
(1 day ago)
Web noscript attack
...
Web Spam
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 03:39:04
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.230.172.233 (233.172.230.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.230.172.233 (233.172.230.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 23:38:59.468700 2026] [security2:error] [pid 25607:tid 25607] [client 35.230.172.233:48186] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "lct.lbee.com"] [uri "/.env.prod"] [unique_id "apzgUyXpuvEofERyJmvUNwAAAGQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-06 03:15:16
(1 day ago)
Multiple web server 400 error codes from same source ip
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 02:59:49
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.230.172.233 (233.172.230.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.230.172.233 (233.172.230.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 22:59:44.679834 2026] [security2:error] [pid 4289:tid 4289] [client 35.230.172.233:39526] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.groz.net"] [uri "/.env.save"] [unique_id "apzXILE-fHZnv-Z_D3jPjAAAACI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 01:45:03
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.230.172.233 (233.172.230.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.230.172.233 (233.172.230.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 21:44:57.412537 2026] [security2:error] [pid 6124:tid 6124] [client 35.230.172.233:53022] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ftp.sandpointidaho.com"] [uri "/.env.example"] [unique_id "apzFmbS-G3_yxidRM-oiHgAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-06 01:17:03
(1 day ago)
Bot / scanning and/or hacking attempts: GET /.env.old HTTP/1.1, GET /.env.example HTTP/1.1
Hacking
Web App Attack
🇫🇮
YF
2026-09-06 00:31:21
(1 day ago)
WordPress config file probe
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 00:22:24
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.230.172.233 (233.172.230.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.230.172.233 (233.172.230.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 20:22:20.036987 2026] [security2:error] [pid 11646:tid 11697] [client 35.230.172.233:60642] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "lapulperiagirona.com"] [uri "/.env.local"] [unique_id "apyyPMhY564o5wKLIwi3NQAAAQA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-06 00:10:12
(1 day ago)
[osotir.org] httpd-config-scan: logs=/var/log/httpd/access_log; samples=/.env.backup | /.env.local | ...
show more
[osotir.org] httpd-config-scan: logs=/var/log/httpd/access_log; samples=/.env.backup | /.env.local | /actuator/env
show less
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 23:57:45
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.230.172.233 (233.172.230.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.230.172.233 (233.172.230.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 19:57:38.360443 2026] [security2:error] [pid 27812:tid 27812] [client 35.230.172.233:46096] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.citystreetsalon.com"] [uri "/wp-config.php.bak"] [unique_id "apyscpL8mKaWXlc6MpOLJQAAAFY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
raph
2026-09-05 23:22:16
(1 day ago)
[DOT FILES] crawler *.env*, .git*, .config*, etc.
Bad Web Bot
Web App Attack
🇺🇸
mnsf
2026-09-05 23:06:29
(1 day ago)
Scanning/Probing (20)
Brute-Force
Web App Attack
🇺🇸
Red Five
2026-09-05 22:58:28
(1 day ago)
FortiGate IPS blocked high-confidence malicious activity.
Web App Attack
🇳🇱
e.fierstra
2026-09-05 22:56:47
(1 day ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack