🇳🇱
homeshowdomain.nl
2026-09-06 22:02:42
(22 minutes ago)
Auto-ban: >3000 req/min op 2026-09-06
Web App Attack
SSH
Hacking
🇺🇸
craudiovizai
2026-09-06 06:30:33
(15 hours ago)
Automated honeypot detection. honeypot against a Next.js application. Paths: /.env.production. Block ...
show more
Automated honeypot detection. honeypot against a Next.js application. Paths: /.env.production. Blocked at the edge.
show less
Web App Attack
Bad Web Bot
Anonymous
2026-09-06 04:35:16
(17 hours ago)
Failed login attempt detected by Fail2Ban in plesk-modsecurity jail
Exploited Host
🇺🇸
TPI-Abuse
2026-09-06 01:37:13
(20 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.235.117.65 (65.117.235.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.235.117.65 (65.117.235.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 21:37:09.635619 2026] [security2:error] [pid 3505775:tid 3505871] [client 35.235.117.65:42532] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mouawadarchitects.com"] [uri "/.env.local"] [unique_id "apzDxb8ERl7gWgWoAPLwCQAAAY0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 01:21:43
(21 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.235.117.65 (65.117.235.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.235.117.65 (65.117.235.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 21:21:37.142765 2026] [security2:error] [pid 30727:tid 30758] [client 35.235.117.65:38858] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sylvestconsulting.com"] [uri "/.env.example"] [unique_id "apzAIVyjTaewCShlwzfDKAAAAFU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
mnsf
2026-09-06 01:05:21
(21 hours ago)
Scanning/Probing (13)
Brute-Force
Web App Attack
🇩🇪
FeG Deutschland
2026-09-06 00:44:34
(21 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 12
Exploited Host
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 00:32:56
(21 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.235.117.65 (65.117.235.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.235.117.65 (65.117.235.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 20:32:49.710016 2026] [security2:error] [pid 29650:tid 29667] [client 35.235.117.65:33202] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "batonrougegazette.com"] [uri "/.env.backup"] [unique_id "apy0sTK_Ze3cnQ1SOdgrngAAAY4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
WeCloudit-Anti-Abuse
2026-09-06 00:15:09
(22 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
🇫🇷
dynamix
2026-09-06 00:09:26
(22 hours ago)
Multiple WAF Violations
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 23:49:54
(22 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.235.117.65 (65.117.235.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.235.117.65 (65.117.235.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 19:49:51.251610 2026] [security2:error] [pid 4259:tid 4259] [client 35.235.117.65:37340] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "herstonfarm.com"] [uri "/.env.prod"] [unique_id "apyqn1pA_9eYGqKnm72tPgAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 22:54:03
(23 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.235.117.65 (65.117.235.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.235.117.65 (65.117.235.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 18:53:56.467639 2026] [security2:error] [pid 28221:tid 28221] [client 35.235.117.65:59318] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.meridianranchdrc.org"] [uri "/wp-config.php.swp"] [unique_id "apydhKvbAbAFqh6olOylGgAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
e.fierstra
2026-09-05 22:15:38
(1 day ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
🇬🇧
Aetherweb Ark
2026-09-05 21:25:49
(1 day ago)
(mod_security) mod_security (id:949110) triggered by 35.235.117.65 (US/United States/65.117.235.35.b ...
show more
(mod_security) mod_security (id:949110) triggered by 35.235.117.65 (US/United States/65.117.235.35.bc.googleusercontent.com): N in the last X secs
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 21:06:03
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.235.117.65 (65.117.235.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.235.117.65 (65.117.235.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 17:05:54.956319 2026] [security2:error] [pid 14451:tid 14451] [client 35.235.117.65:52056] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "buffalogunsaz.com.compliancedepts.com"] [uri "/.env.production"] [unique_id "apyEMnkf4iGFfq3Gz3p-HgAAAC4"]
show less
Brute-Force
Bad Web Bot
Web App Attack