๐ณ๐ฑ
homeshowdomain.nl
2026-09-01 21:59:16
(2 days ago)
Auto-ban: >3000 req/min op 2026-09-01
Web App Attack
SSH
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-01 08:32:21
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 35.234.178.70 (70.178.234.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.234.178.70 (70.178.234.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 04:32:16.759390 2026] [security2:error] [pid 12433:tid 12433] [client 35.234.178.70:60410] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "microbikinitop.com"] [uri "/.env.save"] [unique_id "apaNkKwiMHphY5fWOOMRKwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FD-IX
2026-09-01 08:22:41
(2 days ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-09-01 08:05:52
(2 days ago)
Scanning/Probing (20)
Brute-Force
Web App Attack
๐ฉ๐ช
wpadm4
2026-09-01 07:26:21
(2 days ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 07:10:37
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 35.234.178.70 (70.178.234.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.234.178.70 (70.178.234.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 03:10:32.546302 2026] [security2:error] [pid 1911:tid 1911] [client 35.234.178.70:45646] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "musicfreakcentral.jamworldmovements.com"] [uri "/.env.production"] [unique_id "apZ6aLwpK7Zrqat4gZTfwAAAACM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-01 06:12:45
(2 days ago)
(config_exploit_scan) Configuratie Scanner / Nep GPTBot 35.234.178.70 (US/United States/70.178.234.3 ...
show more
(config_exploit_scan) Configuratie Scanner / Nep GPTBot 35.234.178.70 (US/United States/70.178.234.35.bc.googleusercontent.com): 3 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 35.234.178.70 - - [01/Sep/2026:08:12:41 +0200] "GET /.env.old HTTP/1.1" 406 4831 "-" "crusader-worker/1.0"
35.234.178.70 - - [01/Sep/2026:08:12:41 +0200] "GET /.env HTTP/1.1" 406 4830 "-" "crusader-worker/1.0"
35.234.178.70 - - [01/Sep/2026:08:12:41 +0200] "GET /.env.production HTTP/1.1" 406 4830 "-" "crusader-worker/1.0"
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-09-01 06:07:59
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 35.234.178.70 (70.178.234.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.234.178.70 (70.178.234.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 02:07:51.692881 2026] [security2:error] [pid 8959:tid 8959] [client 35.234.178.70:53316] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.rjhills.com"] [uri "/.env.example"] [unique_id "apZrt3TO_8SNkOgU-iiiRAAAAGc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
consul.to
2026-09-01 05:44:03
(2 days ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 05:16:36
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 35.234.178.70 (70.178.234.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.234.178.70 (70.178.234.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 01:16:28.501544 2026] [security2:error] [pid 16410:tid 16410] [client 35.234.178.70:44932] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "brandoncomputergeeks.com"] [uri "/wp-config.php.swp"] [unique_id "apZfrKbIgsjYPG5avz3dpQAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
raph
2026-09-01 04:45:55
(2 days ago)
[Wordpress] crawler /wp-admin/*, /wp-content/*, etc.
Bad Web Bot
Web App Attack
Anonymous
2026-09-01 04:30:02
(2 days ago)
suspicious request in access.log
Web App Attack
๐ณ๐ฑ
MyGlobalFlowers
2026-09-01 04:28:20
(2 days ago)
Multiple WAF Violations
Web App Attack
๐ฉ๐ช
IVski.com
2026-09-01 02:59:55
(2 days ago)
IVski WAF | Sensitive file probe - looking for exposed .env and .git config
DDoS Attack
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-01 02:42:51
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 35.234.178.70 (70.178.234.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.234.178.70 (70.178.234.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 22:42:44.616932 2026] [security2:error] [pid 28575:tid 28584] [client 35.234.178.70:52512] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.stephaniemoody.com"] [uri "/.env.production"] [unique_id "apY7pEqCN7_eadEqktdPZQAAAEc"]
show less
Brute-Force
Bad Web Bot
Web App Attack