🇳🇱
homeshowdomain.nl
2026-09-09 21:59:19
(1 week ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-09-08.
show less
Web App Attack
SSH
Hacking
🇬🇧
openstrike.co.uk
2026-09-09 05:14:38
(1 week ago)
132 attacks on env grabbing URLs (type 2), PHP URLs, env grabbing URLs, VC URLs, config grabbing URL ...
show more
132 attacks on env grabbing URLs (type 2), PHP URLs, env grabbing URLs, VC URLs, config grabbing URLs (type 2), password/key grabbing URLs:
GET /@fs/proc/self/cwd/.azure/credentials?raw?? HTTP/1.1
GET /pi.php HTTP/1.1
GET /app/.env.local HTTP/1.1
GET /.git/config HTTP/1.1
GET /app/config.json HTTP/1.1
GET /.ssh/id_ed25519 HTTP/1.1
show less
Hacking
Web App Attack
🇳🇱
homeshowdomain.nl
2026-09-08 22:03:09
(1 week ago)
Auto-ban: >3000 req/min op 2026-09-08
Web App Attack
SSH
Hacking
🇩🇪
FD-IX
2026-09-08 12:52:35
(1 week ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
🇪🇸
librebit
2026-09-08 12:27:55
(1 week ago)
Bad guys doing bad things, bad crawling
Bad Web Bot
Anonymous
2026-09-08 12:12:00
(1 week ago)
Excessive crawling/scraping. Vulnerable file probing.
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 10:28:17
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 35.233.156.233 (233.156.233.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.233.156.233 (233.156.233.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 06:28:10.049854 2026] [security2:error] [pid 453:tid 453] [client 35.233.156.233:48966] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.paguilar.com"] [uri "/@fs/..%252f..%252f..%252f..%252f..%252froot/.env"] [unique_id "ap_jOpoj6iAHvyeS3HkavgAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
BlueWire Hosting
2026-09-08 09:17:27
(1 week ago)
High-confidence malicious configuration/VCS probe
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 08:27:07
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 35.233.156.233 (233.156.233.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.233.156.233 (233.156.233.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 04:27:01.771594 2026] [security2:error] [pid 11035:tid 11035] [client 35.233.156.233:33600] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.popowich.net"] [uri "/@fs/src/.env"] [unique_id "ap_G1Yq7kcnsXeqFau_POAAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
FeG Deutschland
2026-09-08 08:25:55
(1 week ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 1247
Exploited Host
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 07:21:44
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 35.233.156.233 (233.156.233.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.233.156.233 (233.156.233.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 03:21:39.154668 2026] [security2:error] [pid 1983:tid 1983] [client 35.233.156.233:23832] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.scottcampbellconstruction.com"] [uri "/@fs/root/.env"] [unique_id "ap-3g1EWZHaH5HU7pL0ZTAAAACE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 06:35:20
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 35.233.156.233 (233.156.233.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.233.156.233 (233.156.233.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 02:35:13.166414 2026] [security2:error] [pid 16388:tid 16388] [client 35.233.156.233:42426] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "myclub.oxfordgliding.com"] [uri "/@fs/src/.env"] [unique_id "ap-sobs-s8TiqH0D3Kq_vwAAACg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
Site.eu
2026-09-08 06:20:15
(1 week ago)
Excessive multi-domain requests
Brute-Force
🇫🇷
masterguru
2026-09-08 05:50:35
(1 week ago)
Restricted File Access Attempt. Matched phrase "/@fs/" at REQUEST_FILENAME. (930130-197)
Hacking
Web App Attack
Anonymous
2026-09-08 05:30:20
(1 week ago)
Multiple web server 400 error codes from same source ip
Web App Attack