🇳🇱
homeshowdomain.nl
2026-09-05 22:00:50
(5 days ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-09-04.
show less
Web App Attack
SSH
Hacking
🇳🇱
homeshowdomain.nl
2026-09-04 22:01:53
(6 days ago)
Auto-ban: >3000 req/min op 2026-09-04
Web App Attack
SSH
Hacking
🇺🇸
TPI-Abuse
2026-09-04 15:21:16
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 35.235.119.95 (95.119.235.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.235.119.95 (95.119.235.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 11:21:10.703534 2026] [security2:error] [pid 14871:tid 14871] [client 35.235.119.95:38296] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.artspacecleveland.com"] [uri "/.env"] [unique_id "aprh5g_0FmvTWAubH4PSZAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇮🇹
CoreTech srl
2026-09-04 15:03:56
(6 days ago)
cloudlinux2 fail2ban: 2026-09-04 16:59:48,614 fail2ban.actions [1594]: NOTICE [plesk-modsecu ...
show more
cloudlinux2 fail2ban: 2026-09-04 16:59:48,614 fail2ban.actions [1594]: NOTICE [plesk-modsecurity] Unban 34.64.254.12cloudlinux2 fail2ban: 2026-09-04 17:00:23,759 fail2ban.filter [1594]: INFO [plesk-modsecurity] Found 35.235.119.95 - 2026-09-04 17:00:23cloudlinux2 fail2ban: 2026-09-04 17:00:23,739 fail2ban.filter [1594]: INFO [plesk-modsecurity] Found 35.235.119.95 - 2026-09-04 17:00:23cloudlinux2 fail2ban: 2026-09-04 17:00:23,717 fail2ban.filter [1594]: INFO [plesk-modsecurity] Found 35.235.119.95 - 2026-09-04 17:00:23cloudlinux2 fail2ban: 2026-09-04 17:00:23,780 fail2ban.filter [1594]: INFO [plesk-modsecurity] Found 35.235.119.95 - 2026-09-04 17:00:23cloudlinux2 fail2ban: 2026-09-04 17:00:23,800 fail2ban.filter [1594]: INFO [plesk-modsecurity] Found 35.235.119.95 - 2026-09-04 17:00:23cloudlinux2 fail2ban: 2026-09-04 17:00:23,751 fail2ban.filter [1594]: INFO [plesk-modsecurity] Found 35.235.119.95 - 2026-09-04 17:00:23cloudlinux2 fail2b
show less
Brute-Force
🇺🇸
TPI-Abuse
2026-09-04 14:32:53
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 35.235.119.95 (95.119.235.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.235.119.95 (95.119.235.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 10:32:46.971142 2026] [security2:error] [pid 1353:tid 1353] [client 35.235.119.95:45370] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "decisiontrace.org"] [uri "/.env.old"] [unique_id "aprWjptHsIvXQZxWsZmAawAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 14:09:01
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 35.235.119.95 (95.119.235.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.235.119.95 (95.119.235.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 10:08:55.678259 2026] [security2:error] [pid 10001:tid 10001] [client 35.235.119.95:40744] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.mathewyoung.com"] [uri "/.env.dev"] [unique_id "aprQ9znf15A99lwNc502dwAAADE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
Vegascosmetics
2026-09-04 13:28:08
(6 days ago)
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after sensitive config/credentials exposure ...
show more
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after sensitive config/credentials exposure probe. Evidence: AttackPattern: /\.env (Match: /.env)
show less
Hacking
Brute-Force
Web App Attack
🇺🇸
paulo.apoloni
2026-09-04 13:23:39
(6 days ago)
35.235.119.95 - - [04/Sep/2026:10:23:38 -0300] "GET /.env.dev HTTP/1.1" 404 6461 "-" "crusader-worke ...
show more
35.235.119.95 - - [04/Sep/2026:10:23:38 -0300] "GET /.env.dev HTTP/1.1" 404 6461 "-" "crusader-worker/1.0"
35.235.119.95 - - [04/Sep/2026:10:23:38 -0300] "GET /.env HTTP/1.1" 404 6461 "-" "crusader-worker/1.0"
35.235.119.95 - - [04/Sep/2026:10:23:38 -0300] "GET /.env.backup HTTP/1.1" 404 6461 "-" "crusader-worker/1.0"
35.235.119.95 - - [04/Sep/2026:10:23:38 -0300] "GET /.env.save HTTP/1.1" 404 6461 "-" "crusader-worker/1.0"
35.235.119.95 - - [04/Sep/2026:10:23:38 -0300] "GET /.env.prod HTTP/1.1" 404 6461 "-" "crusader-worker/1.0"
...
show less
Web App Attack
🇺🇸
Rocky Mountain Bioengineering Symposium
2026-09-04 13:23:17
(6 days ago)
[Fri Sep 04 07:23:16.600742 2026] [authz_core:error] [pid 200880:tid 140668785628736] [client 35.235 ...
show more
[Fri Sep 04 07:23:16.600742 2026] [authz_core:error] [pid 200880:tid 140668785628736] [client 35.235.119.95:60284] AH01630: client denied by server configuration: /var/www/public_html/contest/wp-config.php.bak
[Fri Sep 04 07:23:16.602537 2026] [authz_core:error] [pid 200882:tid 140667560851008] [client 35.235.119.95:60360] AH01630: client denied by server configuration: /var/www/public_html/contest/.env.bak
[Fri Sep 04 07:23:16.628836 2026] [authz_core:error] [pid 201276:tid 140667636352576] [client 35.235.119.95:60350] AH01630: client denied by server configuration: /var/www/public_html/contest/wp-config.php.swp
...
show less
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-04 12:49:16
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 35.235.119.95 (95.119.235.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.235.119.95 (95.119.235.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 08:49:11.726964 2026] [security2:error] [pid 1142:tid 1142] [client 35.235.119.95:60640] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "megaandina.com"] [uri "/.env.dev"] [unique_id "apq-R9YEraAJX6t1uV1xgwAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
e.fierstra
2026-09-04 12:09:20
(6 days ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
🇺🇸
IndigoRidge
2026-09-04 10:36:50
(6 days ago)
[04/Sep/2026:06:36:49.045261 --0400] apqfQSqZelwBn3yzPFdmKAAAAwI 35.235.119.95 56616 205.233.18.17 7 ...
show more
[04/Sep/2026:06:36:49.045261 --0400] apqfQSqZelwBn3yzPFdmKAAAAwI 35.235.119.95 56616 205.233.18.17 7081
[04/Sep/2026:06:36:49.045623 --0400] apqfQSNPoMP6QBPm7ZdDEQAAAgs 35.235.119.95 56602 205.233.18.17 7081
[04/Sep/2026:06:36:49.046011 --0400] apqfQSNPoMP6QBPm7ZdDEAAAAg0 35.235.119.95 56594 205.233.18.17 7081
[04/Sep/2026:06:36:49.046332 --0400] apqfQSNPoMP6QBPm7ZdDDwAAAg8 35.235.119.95 56580 205.233.18.17 7081
[04/Sep/2026:06:36:49.048704 --0400] apqfQSNPoMP6QBPm7ZdDEgAAAgM 35.235.119.95 56630 205.233.18.17 7081
...
show less
Hacking
🇺🇸
TPI-Abuse
2026-09-04 10:14:02
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 35.235.119.95 (95.119.235.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.235.119.95 (95.119.235.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 06:13:56.029711 2026] [security2:error] [pid 11207:tid 11207] [client 35.235.119.95:42290] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jamestaylorart.com.ingberinteriors.com"] [uri "/wp-config.php.swp"] [unique_id "apqZ5Io-J2n157_0lDP3iQAAADw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
BlueWire Hosting
2026-09-04 10:11:39
(6 days ago)
Probing websites for vulnerabilities
Web App Attack
🇫🇷
stefaniak41500
2026-09-04 09:57:56
(6 days ago)
Shield Guard: Honeypot: /.env.save
Web App Attack