๐ณ๐ฑ
homeshowdomain.nl
2026-06-15 21:59:56
(1 day ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-06-14.
show less
Web App Attack
SSH
Hacking
๐ฉ๐ช
ecs.ge
2026-06-15 14:16:33
(2 days ago)
Automatic Fail2Ban report from jail plesk-modsecurity: multiple matching events detected.
Web App Attack
Hacking
๐ช๐ธ
robotstxt
2026-06-15 13:50:26
(2 days ago)
35.237.72.220 - - [15/Jun/2026:13:50:21 +0000] "GET /mailer.zip HTTP/1.1" 404 180 "-" "Mozilla/5.0 ( ...
show more
35.237.72.220 - - [15/Jun/2026:13:50:21 +0000] "GET /mailer.zip HTTP/1.1" 404 180 "-" "Mozilla/5.0 (Linux; Android 8.0.0; MI 6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/75.0.3770.101 Mobile Safari/537.36" "-"
35.237.72.220 - - [15/Jun/2026:13:50:21 +0000] "GET /mail.zip HTTP/1.1" 404 180 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_13_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/76.0.3803.0 Safari/537.36 Edg/76.0.174.0" "-"
35.237.72.220 - - [15/Jun/2026:13:50:25 +0000] "GET /mailer/sendgrid.js HTTP/1.1" 404 180 "-" "Mozilla/5.0 (Linux; Android 9; ASUS_X00QD) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/76.0.3809.111 Mobile Safari/537.36" "-"
35.237.72.220 - - [15/Jun/2026:13:50:25 +0000] "GET /mail/sendgrid.py HTTP/1.1" 404 180 "-" "Mozilla/5.0 (Windows NT 6.3; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/75.0.3770.142 Safari/537.36" "-"
35.237.72.220 - - [15/Jun/2026:13:50:25 +0000] "GET /mailer/sendgrid.php HTTP/1.1" 404 180 "-" "Mozilla/5.0 (Windows NT 6.1;
...
show less
Bad Web Bot
๐ง๐ท
SOC Blue Team
2026-06-15 13:26:01
(2 days ago)
IPs get by Hunting on SIEM
Phishing
Web Spam
Port Scan
Hacking
๐บ๐ธ
TPI-Abuse
2026-06-15 06:43:02
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 35.237.72.220 (220.72.237.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.237.72.220 (220.72.237.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 15 02:42:57.533834 2026] [security2:error] [pid 24517:tid 24517] [client 35.237.72.220:44344] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "fatlandtheplay.com"] [uri "/.env.demo"] [unique_id "ai-e8YfPxh_I_q8OZfE3LAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
OceanTreasure
2026-06-14 19:30:07
(2 days ago)
tcp/80; /.env* dotfile probe (R21): "GET /.env.dev" @ 2026-06-14T19:29:10Z
Web App Attack
Anonymous
2026-06-14 16:00:44
(2 days ago)
Aggressive web scan
Web App Attack
๐ฉ๐ช
updown.io
2026-06-14 07:50:48
(3 days ago)
{"level":"info","ts":1781423445.9677212,"logger":"http.log.access.log1","msg":"handled request","req ...
show more
{"level":"info","ts":1781423445.9677212,"logger":"http.log.access.log1","msg":"handled request","request":{"remote_ip":"35.237.72.220","remote_port":"36412","client_ip":"35.237.72.220","proto":"HTTP/1.1","method":"GET","host":"status.nzxt.com","uri":"/.env.dev","headers":{"Accept-Encoding":["gzip"],"Connection":["close"],"User-Agent":["Mozilla/5.0 (SymbianOS 9.4; Series60/5.0 NokiaN97-1/10.0.012; Profile/MIDP-2.1 Configuration/CLDC-1.1; en-us) AppleWebKit/525 (KHTML, like Gecko) WicKed/7.1.12344"],"Accept-Charset":["utf-8"]},"tls":{"resumed":false,"version":772,"cipher_suite":4865,"proto":"","server_name":"status.nzxt.com","ech":false}},"bytes_read":0,"user_id":"","duration":0.000086775,"size":0,"status":429,"resp_headers":{"Server":["Caddy"],"Alt-Svc":["h3=\":443\"; ma=2592000"],"Retry-After":["1"]}}
{"level":"info","ts":1781423445.968035,"logger":"http.log.access.log1","msg":"handled request","request":{"remote_ip":"35.237.72.220","remote_port":"36292","client_ip":"35.237.72.220","pr
...
show less
DDoS Attack
Web App Attack
๐ณ๐ฑ
wlt-blocker
2026-06-14 06:10:57
(3 days ago)
Unauthorized access to webpage admin
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-14 06:10:55
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 35.237.72.220 (220.72.237.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.237.72.220 (220.72.237.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 02:10:50.072968 2026] [security2:error] [pid 22537:tid 22537] [client 35.237.72.220:47388] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.thequakes.com"] [uri "/.env.prod.bak"] [unique_id "ai5F6s6pOM_jbgZoyyRM9gAAAFI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-14 04:24:43
(3 days ago)
Multiple web server 400 error codes from same source ip
Web App Attack
๐ฉ๐ช
maxpower
2026-06-14 03:40:52
(3 days ago)
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 35.237.72.220 (US/United States/220.72.2 ...
show more
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 35.237.72.220 (US/United States/220.72.237.35.bc.googleusercontent.com): 2 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 35.237.72.220 - - [14/Jun/2026:05:40:39 +0200] "GET /sendgrid.env HTTP/1.1" 404 31074 "-" "Mozilla/5.0 (Macintosh; U; Intel Mac OS X 10_7; en-us) AppleWebKit/534.20.8 (KHTML, like Gecko) Version/5.1 Safari/534.20.8" "-" host=www.avconsulenze.arkon.it
35.237.72.220 - - [14/Jun/2026:05:40:45 +0200] "GET /config/sendgrid.env HTTP/1.1" 404 0 "-" "Mozilla/5.0 (Linux; Android 7.0; PIC-AL00) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/76.0.3809.111 Mobile Safari/537.36" "-" host=www.avconsulenze.arkon.it
show less
Port Scan
๐ณ๐ฑ
Cloud86 B.V.
2026-06-13 21:52:02
(3 days ago)
categories: DDoS Attack
DDoS Attack
๐ฉ๐ช
Carl-T.
2026-04-27 08:41:00
(1 month ago)
Email Spam
Phishing
๐ณ๐ฑ
Cloud86 B.V.
2026-04-26 21:39:02
(1 month ago)
categories: Email Spam
Email Spam