๐ท๐บ
DZBOT
2026-07-31 23:24:18
(6 minutes ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-31 23:13:22
(17 minutes ago)
(mod_security) mod_security (id:210492) triggered by 35.231.41.225 (225.41.231.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.231.41.225 (225.41.231.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 31 19:13:15.622972 2026] [security2:error] [pid 32609:tid 32609] [client 35.231.41.225:65332] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.southernreader.com"] [uri "/.env.development"] [unique_id "am0sC9o6z3hqyLHOL890RQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
consul.to
2026-07-31 23:07:53
(23 minutes ago)
Web attack/malicious scanning detected
Web App Attack
๐ซ๐ฎ
YF
2026-07-31 23:00:24
(30 minutes ago)
WordPress config file probe
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-31 22:57:31
(33 minutes ago)
(mod_security) mod_security (id:210492) triggered by 35.231.41.225 (225.41.231.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.231.41.225 (225.41.231.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 31 18:57:25.680164 2026] [security2:error] [pid 3961944:tid 3961944] [client 35.231.41.225:35558] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.kairoslogammakmur.com"] [uri "/.env.local"] [unique_id "am0oVYrF2KZRAZ0wC-5kFQAAACo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
Celtic
2026-07-31 22:38:59
(51 minutes ago)
Blocked by Fail2Ban with Jail (plesk-modsecurity)
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2026-07-31 22:32:00
(58 minutes ago)
(mod_security) mod_security (id:210492) triggered by 35.231.41.225 (225.41.231.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.231.41.225 (225.41.231.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 31 18:31:53.958845 2026] [security2:error] [pid 1110507:tid 1110507] [client 35.231.41.225:43838] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "pourier.net"] [uri "/.env"] [unique_id "am0iWeuHV4C4ZRLYDB_S3QAAAEo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-07-31 22:19:03
(1 hour ago)
Restricted File Access Attempt. Matched phrase ".aws/" at REQUEST_FILENAME. (930130-197)
Hacking
Web App Attack
๐ช๐ธ
alferez
2026-07-31 22:17:22
(1 hour ago)
Searching .(env|sql|zip|tar|rar) files
Hacking
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-31 22:16:50
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 35.231.41.225 (225.41.231.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.231.41.225 (225.41.231.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 31 18:16:47.108615 2026] [security2:error] [pid 885141:tid 885141] [client 35.231.41.225:20720] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.title28.com"] [uri "/.env.production"] [unique_id "am0ez3PoRtao5FWpvADm4AAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-07-31 21:59:27
(1 hour ago)
Auto-ban: >3000 req/min op 2026-07-31
Web App Attack
SSH
Hacking
๐บ๐ธ
TPI-Abuse
2026-07-31 21:57:37
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 35.231.41.225 (225.41.231.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.231.41.225 (225.41.231.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 31 17:57:30.796630 2026] [security2:error] [pid 3937161:tid 3937161] [client 35.231.41.225:34640] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.mohawk-ny.org"] [uri "/.env"] [unique_id "am0aSnC-VrDkDC4YxXCmmgAAAIo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-31 21:56:32
(1 hour ago)
Wordpress vulnerability scanning
...
Web App Attack
๐ซ๐ท
Octopuce
2026-07-31 21:55:31
(1 hour ago)
Aggressive web search of vulnerable pages: /api/.env /.env.local /app/.env /admin/.env /.env ...
Web App Attack
๐ฉ๐ช
updown.io
2026-07-31 21:45:32
(1 hour ago)
{"level":"info","ts":1785534316.5763128,"logger":"http.log.access.log1","msg":"handled request","req ...
show more
{"level":"info","ts":1785534316.5763128,"logger":"http.log.access.log1","msg":"handled request","request":{"remote_ip":"35.231.41.225","remote_port":"53832","client_ip":"35.231.41.225","proto":"HTTP/1.1","method":"GET","host":"status.equilibrium.gay","uri":"/","headers":{"Accept":["*/*"],"Accept-Encoding":["gzip"],"User-Agent":["Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/146.0.0.0 Safari/537.36"]}},"bytes_read":0,"user_id":"","duration":0.00007845,"size":0,"status":308,"resp_headers":{"Server":["Caddy"],"Connection":["close"],"Location":["https://status.equilibrium.gay/"],"Content-Type":[]}}
{"level":"info","ts":1785534331.6323166,"logger":"http.log.access.log1","msg":"handled request","request":{"remote_ip":"35.231.41.225","remote_port":"40656","client_ip":"35.231.41.225","proto":"HTTP/1.1","method":"GET","host":"status.equilibrium.gay","uri":"/backend/.env","headers":{"Accept-Language":["en-US,en;q=0.9"],"Accept-Encoding":["gzip"],"User-Agent":["Moz
...
show less
DDoS Attack
Web App Attack