๐ณ๐ฑ
homeshowdomain.nl
2026-08-28 22:02:52
(2 days ago)
Auto-ban: >3000 req/min op 2026-08-28
Web App Attack
SSH
Hacking
๐ซ๐ท
dynamix
2026-08-28 16:37:24
(2 days ago)
Multiple WAF Violations
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-08-28 16:22:19
(2 days ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐ฎ๐ฉ
Burayot
2026-08-28 15:46:48
(2 days ago)
LF_MODSEC: (mod_security) mod_security (id:949110) triggered by 35.231.177.18 (US/United States/18.1 ...
show more
LF_MODSEC: (mod_security) mod_security (id:949110) triggered by 35.231.177.18 (US/United States/18.177.231.35.bc.googleusercontent.com): 2 in the last 3600 secs
show less
Web App Attack
๐ฉ๐ช
hero2026
2026-08-28 15:43:44
(2 days ago)
Blocked by Fail2ban
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-08-28 14:36:13
(3 days ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 14:21:18
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 35.231.177.18 (18.177.231.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.231.177.18 (18.177.231.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 10:21:12.259541 2026] [security2:error] [pid 13153:tid 13153] [client 35.231.177.18:43570] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "eurocs2.com"] [uri "/.env"] [unique_id "apGZWH0-ZUKERTDpdYAGoAAAACA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 13:39:25
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 35.231.177.18 (18.177.231.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.231.177.18 (18.177.231.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 09:39:20.667027 2026] [security2:error] [pid 2230:tid 2230] [client 35.231.177.18:42564] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "corangues.com"] [uri "/.env"] [unique_id "apGPiKOQZ5Q_E2niDEnpIgAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-08-28 13:05:59
(3 days ago)
Scanning/Probing (20)
Brute-Force
Web App Attack
๐ง๐ท
dominioz
2026-08-28 13:05:57
(3 days ago)
2026-08-28 13:05:13 GET /wp-config.php.bak - - 35.231.177.18 HTTP/1.1 crusader-worker/1.0 - 404 474
...
show more
2026-08-28 13:05:13 GET /wp-config.php.bak - - 35.231.177.18 HTTP/1.1 crusader-worker/1.0 - 404 474
2026-08-28 13:05:13 GET /.env.old - - 35.231.177.18 HTTP/1.1 crusader-worker/1.0 - 404 474
2026-08-28 13:05:13 GET /.env.bak - - 35.231.177.18 HTTP/1.1 crusader-worker/1.0 - 404 474
2026-08-28 13:05:13 GET /wp-config.php~ X-ARR-CACHE-HIT=0&X-ARR-LOG-ID=c87d4d01-769f-4e24-ab39-1b1aac739d07&SERVER-STATUS=404 - 35.231.177.18 HTTP/1.1 crusader-worker/1.0 - 404 1261
...
show less
Web App Attack
๐ซ๐ท
masterguru
2026-08-28 12:26:36
(3 days ago)
Restricted File Access Attempt. Matched phrase ".env" at REQUEST_FILENAME. (930130-201)
Hacking
Web App Attack
Anonymous
2026-08-28 11:51:52
(3 days ago)
[server.tmg.gr] httpd-config-scan: sites=www.crisis-management2021.eu; logs=/var/log/httpd/domains/c ...
show more
[server.tmg.gr] httpd-config-scan: sites=www.crisis-management2021.eu; logs=/var/log/httpd/domains/crisis-management2021.eu.log; samples=/.env.local | /.env.example | /.env.bak
show less
Hacking
Web App Attack
๐ซ๐ท
masterguru
2026-08-28 11:07:53
(3 days ago)
Attempt to access a backup or working file. Pattern match "\\\\. (920500-196)
Hacking
Anonymous
2026-08-28 10:50:01
(3 days ago)
suspicious request in access.log
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 10:46:42
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 35.231.177.18 (18.177.231.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.231.177.18 (18.177.231.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 06:46:35.503204 2026] [security2:error] [pid 3710:tid 3710] [client 35.231.177.18:56978] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "andrsn.com"] [uri "/.env"] [unique_id "apFnC7jjQHgrjvTSbDjCegAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack