🇧🇾
lns.bz
2026-09-05 07:26:29
(13 hours ago)
Too many 404 requests [BY]
Web App Attack
🇳🇱
homeshowdomain.nl
2026-09-04 21:59:21
(23 hours ago)
Auto-ban: >3000 req/min op 2026-09-04
Web App Attack
SSH
Hacking
🇮🇹
mgarofano80
2026-09-04 15:21:39
(1 day ago)
Brute-Force
Web App Attack
🇫🇷
ISPLtd
2026-09-04 14:38:46
(1 day ago)
Sep 4 11:38:45 35.238.203.42 TCP SPT=45662 DPT=80 SYN
Sep 4 11:38:45 35.238.203.42 TCP SPT=45638 D ...
show more
Sep 4 11:38:45 35.238.203.42 TCP SPT=45662 DPT=80 SYN
Sep 4 11:38:45 35.238.203.42 TCP SPT=45638 DPT=80 SYN
Sep 4 11:38:45 35.238.203.42 TCP SPT=45646 DPT=80 SYN
...
show less
DDoS Attack
Anonymous
2026-09-04 14:20:02
(1 day ago)
suspicious request in access.log
Web App Attack
🇩🇪
LRob
2026-09-04 13:48:42
(1 day ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /.env.local (+12 more) | 2026-09-04 13:48 UTC
show less
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 13:29:03
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.238.203.42 (42.203.238.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.238.203.42 (42.203.238.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 09:28:58.891529 2026] [security2:error] [pid 22785:tid 22785] [client 35.238.203.42:54980] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "southernislands.com"] [uri "/.env"] [unique_id "aprHmtwfoS6QHWozbh1CbQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇸🇪
vaia.cloud
2026-09-04 13:20:01
(1 day ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
🇺🇸
leasj
2026-09-04 12:50:58
(1 day ago)
Observed Scanned 12 known-sensitive endpoint(s), e.g.: /.env.production, /.env.local, /.env, /.env.p ...
show more
Observed Scanned 12 known-sensitive endpoint(s), e.g.: /.env.production, /.env.local, /.env, /.env.prod, /actuator/env.
show less
Hacking
Bad Web Bot
Web App Attack
🇮🇪
AutosOnShow
2026-09-04 12:45:07
(1 day ago)
blocked for webapp attack | path requested: / | seen at 2026-09-04 12:44:32.986 |
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 12:01:29
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.238.203.42 (42.203.238.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.238.203.42 (42.203.238.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 08:01:22.864864 2026] [security2:error] [pid 5655:tid 5655] [client 35.238.203.42:54416] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "tacanicsa.ppichardocigars.com"] [uri "/.env.bak"] [unique_id "apqzEpWoO2UWEaU6Uje-mgAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 11:44:53
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.238.203.42 (42.203.238.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.238.203.42 (42.203.238.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 07:44:45.397492 2026] [security2:error] [pid 31118:tid 31118] [client 35.238.203.42:43654] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.grancanariaholidays.com"] [uri "/.env.backup"] [unique_id "apqvLXcFDnMBA8iaWs5kkAAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
Bedios GmbH
2026-09-04 10:06:52
(1 day ago)
Login credentials theft attempt
Hacking
🇺🇸
TPI-Abuse
2026-09-04 10:04:07
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.238.203.42 (42.203.238.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.238.203.42 (42.203.238.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 06:04:02.748376 2026] [security2:error] [pid 21660:tid 21660] [client 35.238.203.42:48746] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.ufcmusic.com"] [uri "/wp-config.php.swp"] [unique_id "apqXklVky7tXQEx6nWE9_AAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 09:13:01
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.238.203.42 (42.203.238.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.238.203.42 (42.203.238.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 05:12:56.946957 2026] [security2:error] [pid 11644:tid 11644] [client 35.238.203.42:34504] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "xtrl.danged.com"] [uri "/wp-config.php.swp"] [unique_id "apqLmPL20SmYlrsw26JzvgAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack