๐ณ๐ฑ
homeshowdomain.nl
2026-09-01 22:00:50
(1 day ago)
Auto-ban: >3000 req/min op 2026-09-01
Web App Attack
SSH
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-01 11:12:26
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.234.38.138 (138.38.234.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.234.38.138 (138.38.234.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 07:12:22.066492 2026] [security2:error] [pid 23255:tid 23255] [client 35.234.38.138:48152] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "welleracore.com.darkcodedesign.net"] [uri "/.env.production"] [unique_id "apazFlG7dYZRrxhDj7MRdwAAADU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
MatCat
2026-09-01 11:05:11
(1 day ago)
Banned by fail2ban: apache-webprobe
Port Scan
Bad Web Bot
๐ท๐ด
clauss
2026-09-01 11:04:42
(1 day ago)
35.234.38.138 - - [01/Sep/2026:14:04:42 +0300] "GET /.env.local HTTP/1.1" 404 5750 "-" "crusader-wor ...
show more
35.234.38.138 - - [01/Sep/2026:14:04:42 +0300] "GET /.env.local HTTP/1.1" 404 5750 "-" "crusader-worker/1.0"
35.234.38.138 - - [01/Sep/2026:14:04:42 +0300] "GET /.env.example HTTP/1.1" 404 5750 "-" "crusader-worker/1.0"
...
show less
Web App Attack
๐ฉ๐ช
thesimonmanuel
2026-09-01 09:45:11
(1 day ago)
35.234.38.138 - - [01/Sep/2026:15:15:11 +0530] "GET /.env.old HTTP/2.0" 404 146 "-" "crusader-worker ...
show more
35.234.38.138 - - [01/Sep/2026:15:15:11 +0530] "GET /.env.old HTTP/2.0" 404 146 "-" "crusader-worker/1.0" "35.234.38.138"
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 09:38:48
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.234.38.138 (138.38.234.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.234.38.138 (138.38.234.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 05:38:42.454631 2026] [security2:error] [pid 30417:tid 30417] [client 35.234.38.138:49942] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "skyesongtollers.com"] [uri "/.env"] [unique_id "apadIvrkA7oUjntDIDNf8gAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
ALPHANET
2026-09-01 08:50:30
(1 day ago)
web exploits
Hacking
Exploited Host
Web App Attack
๐ฉ๐ช
raph
2026-09-01 08:50:29
(1 day ago)
[Wordpress] crawler /wp-admin/*, /wp-content/*, etc.
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-09-01 07:33:01
(1 day ago)
Restricted File Access Attempt. Matched phrase ".env" at REQUEST_FILENAME. (930130-193)
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 07:04:36
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.234.38.138 (138.38.234.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.234.38.138 (138.38.234.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 03:04:32.104488 2026] [security2:error] [pid 27239:tid 27239] [client 35.234.38.138:56028] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ferienwohnungen-eva.com"] [uri "/wp-config.php.bak"] [unique_id "apZ5AAQqmNulLS2HKj0SagAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-09-01 06:57:37
(1 day ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐ฌ๐ง
Apache
2026-09-01 06:12:27
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.234.38.138 (TW/Taiwan/138.38.234.35.bc.googl ...
show more
(mod_security) mod_security (id:210492) triggered by 35.234.38.138 (TW/Taiwan/138.38.234.35.bc.googleusercontent.com): 5 in the last 300 secs
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 06:03:19
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.234.38.138 (138.38.234.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.234.38.138 (138.38.234.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 02:03:08.826367 2026] [security2:error] [pid 19188:tid 19188] [client 35.234.38.138:42156] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.eatinnola.com"] [uri "/.env.save"] [unique_id "apZqnGiMsfGW-Fdd2j8EhAAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FD-IX
2026-09-01 05:06:39
(1 day ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
๐ซ๐ท
ISPLtd
2026-09-01 04:40:10
(1 day ago)
Sep 1 06:40:07 35.234.38.138 TCP SPT=50060 DPT=80 SYN
Sep 1 06:40:07 35.234.38.138 TCP SPT=50056 D ...
show more
Sep 1 06:40:07 35.234.38.138 TCP SPT=50060 DPT=80 SYN
Sep 1 06:40:07 35.234.38.138 TCP SPT=50056 DPT=80 SYN
Sep 1 06:40:07 35.234.38.138 TCP SPT=50074 DPT=80 SYN
...
show less
DDoS Attack