๐ณ๐ฑ
homeshowdomain.nl
2026-09-01 21:59:55
(15 hours ago)
Auto-ban: >3000 req/min op 2026-09-01
Web App Attack
SSH
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-01 14:06:36
(23 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.231.88.200 (200.88.231.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.231.88.200 (200.88.231.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 10:06:29.902381 2026] [security2:error] [pid 20577:tid 20577] [client 35.231.88.200:39286] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.sanesoftware.com"] [uri "/.env.old"] [unique_id "apbb5ag8NJzn-6-qELKvDAAAACE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 13:47:25
(23 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.231.88.200 (200.88.231.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.231.88.200 (200.88.231.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 09:47:19.187377 2026] [security2:error] [pid 31849:tid 31849] [client 35.231.88.200:47968] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.xirin.net"] [uri "/.env.save"] [unique_id "apbXZ3V6-GdbA8ZxMBJhlwAAAB8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FD-IX
2026-09-01 12:59:03
(1 day ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-09-01 12:03:16
(1 day ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-01 11:08:31
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.231.88.200 (200.88.231.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.231.88.200 (200.88.231.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 07:08:24.214992 2026] [security2:error] [pid 22240:tid 22364] [client 35.231.88.200:52724] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.love-spells-magic.com"] [uri "/.env.backup"] [unique_id "apayKJKd78aQczgxaEJTFQAAAIE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 10:02:34
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.231.88.200 (200.88.231.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.231.88.200 (200.88.231.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 06:02:30.401225 2026] [security2:error] [pid 23877:tid 23877] [client 35.231.88.200:45486] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "fireteam.faith"] [uri "/.env.local"] [unique_id "apaitpy0BuzqAjeemye9WwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ธ๐ช
vaia.cloud
2026-09-01 09:45:06
(1 day ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 09:40:44
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.231.88.200 (200.88.231.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.231.88.200 (200.88.231.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 05:40:39.965563 2026] [security2:error] [pid 9941:tid 9941] [client 35.231.88.200:46972] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "solporpoise.com"] [uri "/.env.example"] [unique_id "apadl0SjSst0tF8RTaoaggAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
leo1305
2026-09-01 09:23:46
(1 day ago)
CrowdSec detection | scenario: http-probing
Port Scan
Web App Attack
๐ฑ๐บ
SiteXL
2026-09-01 08:51:28
(1 day ago)
Automated Fail2Ban detection: malicious activity observed; source IP was banned.
Bad Web Bot
Web App Attack
๐ฎ๐น
clamehost.it
2026-09-01 07:51:04
(1 day ago)
Automatic report - Brute Force attack using this IP address
Brute-Force
๐ฉ๐ช
big-cloud.nl
2026-09-01 07:47:43
(1 day ago)
Try to access /.env
Web App Attack
๐ฉ๐ช
ddobko
2026-09-01 07:45:34
(1 day ago)
Bad Web Bot
Web App Attack
Anonymous
2026-09-01 06:05:06
(1 day ago)
WAF repeated trigger detected by Fail2Ban
Web App Attack