๐ณ๐ฑ
homeshowdomain.nl
2026-08-27 22:00:51
(7 hours ago)
Auto-ban: >3000 req/min op 2026-08-27
Web App Attack
SSH
Hacking
๐ฉ๐ช
factor1
2026-08-27 21:38:04
(8 hours ago)
CrowdSec at thor Reports Abuse
Web App Attack
๐ฉ๐ช
Teufel100
2026-08-27 20:16:27
(9 hours ago)
ModSecurity rejected a query
Brute-Force
Hacking
Web App Attack
๐ฉ๐ช
ISPLtd
2026-08-27 19:12:54
(10 hours ago)
Aug 27 16:12:53 35.239.36.136 TCP SPT=42998 DPT=80 SYN
Aug 27 16:12:53 35.239.36.136 TCP SPT=42966 D ...
show more
Aug 27 16:12:53 35.239.36.136 TCP SPT=42998 DPT=80 SYN
Aug 27 16:12:53 35.239.36.136 TCP SPT=42966 DPT=80 SYN
Aug 27 16:12:53 35.239.36.136 TCP SPT=42982 DPT=80 SYN
...
show less
DDoS Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 18:55:22
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.239.36.136 (136.36.239.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.239.36.136 (136.36.239.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 14:55:18.060887 2026] [security2:error] [pid 3364194:tid 3364252] [client 35.239.36.136:57492] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.saludmyg.com.neotienda.com"] [uri "/.env.prod"] [unique_id "apCIFq85zknR9x3xKGoa_AAAAU0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 18:14:03
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.239.36.136 (136.36.239.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.239.36.136 (136.36.239.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 14:13:54.707164 2026] [security2:error] [pid 21760:tid 21760] [client 35.239.36.136:33786] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kenirving.com"] [uri "/.env.bak"] [unique_id "apB-YvThZdQs6cWqYizs9QAAACc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
macrob
2026-08-27 18:09:00
(11 hours ago)
2026/08/27 18:08:58 [error] 2898860#2898860: *527390219 access forbidden by rule, client: 35.239.36. ...
show more
2026/08/27 18:08:58 [error] 2898860#2898860: *527390219 access forbidden by rule, client: 35.239.36.136, server: binixo.ro, request: "GET /.env.old HTTP/1.1", host: "a.binixo.ro"
2026/08/27 18:08:58 [error] 2898860#2898860: *527390220 access forbidden by rule, client: 35.239.36.136, server: binixo.ro, request: "GET /.env.production HTTP/1.1", host: "a.binixo.ro"
2026/08/27 18:08:58 [error] 2898862#2898862: *527390222 access forbidden by rule, client: 35.239.36.136, server: binixo.ro, request: "GET /.env.local HTTP/1.1", host: "a.binixo.ro"
...
show less
Web App Attack
๐ซ๐ฎ
paissangroup
2026-08-27 17:49:14
(11 hours ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 17:09:34
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.239.36.136 (136.36.239.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.239.36.136 (136.36.239.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 13:09:28.638119 2026] [security2:error] [pid 2498:tid 2498] [client 35.239.36.136:34520] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.acmax.com"] [uri "/.env.backup"] [unique_id "apBvSBQUev7pYtoi-fjakgAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
YF
2026-08-27 17:01:20
(12 hours ago)
WordPress config file probe
Web App Attack
๐ง๐ช
voormedia
2026-08-27 16:44:46
(13 hours ago)
Accessed trap at '/.env'
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-08-27 15:57:09
(13 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
๐ฉ๐ช
LRob
2026-08-27 15:47:43
(13 hours ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /wp-config.php.swp (+11 more) | 2026-08-27 15:47 UTC
show less
Hacking
Web App Attack
๐ซ๐ฎ
as211431.net
2026-08-27 15:47:36
(13 hours ago)
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET metho ...
show more
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET method)
Endpoint: /.env/
UA: crusader-worker/1.0
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐บ๐ธ
jkhorvath.com
2026-08-27 15:45:41
(14 hours ago)
Request for URL /.env.old
Phishing
Brute-Force
Web App Attack