🇳🇱
homeshowdomain.nl
2026-09-04 22:00:33
(7 hours ago)
Auto-ban: >3000 req/min op 2026-09-04
Web App Attack
SSH
Hacking
🇺🇸
TPI-Abuse
2026-09-04 15:20:41
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.240.152.217 (217.152.240.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.240.152.217 (217.152.240.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 11:20:35.930079 2026] [security2:error] [pid 23698:tid 23698] [client 35.240.152.217:57754] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.sandecs.com"] [uri "/.env.bak"] [unique_id "aprhw76Ma_u7__qpPu5RwwAAACw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 14:08:04
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.240.152.217 (217.152.240.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.240.152.217 (217.152.240.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 10:08:00.723749 2026] [security2:error] [pid 728:tid 728] [client 35.240.152.217:52118] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.ohiobabe.com"] [uri "/.env.production"] [unique_id "aprQwDqcQ-OXgeLyeWL2ggAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 13:22:13
(16 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.240.152.217 (217.152.240.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.240.152.217 (217.152.240.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 09:22:08.303704 2026] [security2:error] [pid 5639:tid 5639] [client 35.240.152.217:55924] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||clip24.net.sislau.net|F|2"] [data ".log"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "clip24.net.sislau.net"] [uri "/storage/logs/laravel.log"] [unique_id "aprGAFlU122CEID1aTVBFQAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 12:30:25
(17 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.240.152.217 (217.152.240.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.240.152.217 (217.152.240.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 08:30:19.172447 2026] [security2:error] [pid 19992:tid 19992] [client 35.240.152.217:45616] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||zimbra.madkatty.com|F|2"] [data ".log"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "zimbra.madkatty.com"] [uri "/storage/logs/laravel.log"] [unique_id "apq526LyfxVHC3mQ8iZwJQAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 10:43:18
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.240.152.217 (217.152.240.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.240.152.217 (217.152.240.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 06:43:13.090952 2026] [security2:error] [pid 19489:tid 19489] [client 35.240.152.217:38910] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "lifelonglearner.science"] [uri "/.env.example"] [unique_id "apqgwYzAQQxQ7_TnEsJfcgAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
Keith Beucler
2026-09-04 10:12:19
(19 hours ago)
K5 Services fail2ban jail nginx-k5-web-probes detected high-confidence web abuse. Local web ban appl ...
show more
K5 Services fail2ban jail nginx-k5-web-probes detected high-confidence web abuse. Local web ban applied. Categories: 19,21.
show less
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 10:01:45
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.240.152.217 (217.152.240.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.240.152.217 (217.152.240.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 06:01:37.640598 2026] [security2:error] [pid 30489:tid 30489] [client 35.240.152.217:60454] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.casademunt.com"] [uri "/.env.production"] [unique_id "apqXAa7_ShkMToNZJxqlRgAAAC8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇪🇸
el-brujo
2026-09-04 09:37:02
(19 hours ago)
Cloudflare WAF: Request Path: /%2eenv Request Query: Host: gpu.elhacker.net userAgent: crusader-wor ...
show more
Cloudflare WAF: Request Path: /%2eenv Request Query: Host: gpu.elhacker.net userAgent: crusader-worker/1.0 Action: block Source: firewallManaged ASN Description: Google LLC Country: SG Method: GET Timestamp: 2026-09-04T09:37:02Z ruleId: 23548ee2b36547a1be09bb2c0550c529. Report generated by Cloudflare-WAF-to-AbuseIPDB.
show less
Hacking
SQL Injection
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 09:25:15
(20 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.240.152.217 (217.152.240.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.240.152.217 (217.152.240.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 05:25:10.646846 2026] [security2:error] [pid 24500:tid 24500] [client 35.240.152.217:43182] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.pcsyportatiles.com"] [uri "/.env.dev"] [unique_id "apqOdgM75LiMVlYKaGR2TAAAADA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇨🇭
4server
2026-09-04 08:31:06
(21 hours ago)
[FriSep0410:31:00.3994642026][security2:error][pid4048227:tid4048507][client35.240.152.217:0]ModSecu ...
show more
[FriSep0410:31:00.3994642026][security2:error][pid4048227:tid4048507][client35.240.152.217:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\".env\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"610\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"mail.creazione-siti-ticino.ch\"][uri\"/.env.dev\"][unique_id\"apqBxHrZd9ebVcXJqjZgZQAAAQ8\"]
show less
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 08:29:03
(21 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.240.152.217 (217.152.240.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.240.152.217 (217.152.240.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 04:28:58.201602 2026] [security2:error] [pid 28478:tid 28478] [client 35.240.152.217:53934] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.von-s.com"] [uri "/.env.save"] [unique_id "apqBSqXoXK7_zJ43wxgHAgAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-04 08:20:33
(21 hours ago)
(config_exploit_scan) Configuratie Scanner / Nep GPTBot 35.240.152.217 (SG/Singapore/217.152.240.35. ...
show more
(config_exploit_scan) Configuratie Scanner / Nep GPTBot 35.240.152.217 (SG/Singapore/217.152.240.35.bc.googleusercontent.com): 3 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 35.240.152.217 - - [04/Sep/2026:10:20:30 +0200] "GET /.env.bak HTTP/1.1" 406 4830 "-" "crusader-worker/1.0"
35.240.152.217 - - [04/Sep/2026:10:20:30 +0200] "GET /.env.old HTTP/1.1" 406 4831 "-" "crusader-worker/1.0"
35.240.152.217 - - [04/Sep/2026:10:20:30 +0200] "GET /.env.backup HTTP/1.1" 406 4829 "-" "crusader-worker/1.0"
show less
Port Scan
🇫🇷
dynamix
2026-09-04 08:16:56
(21 hours ago)
Multiple WAF Violations
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 07:44:26
(21 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.240.152.217 (217.152.240.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.240.152.217 (217.152.240.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 03:44:20.998416 2026] [security2:error] [pid 7590:tid 7606] [client 35.240.152.217:38964] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ftp.inkandthreadllc.com"] [uri "/.env.dev"] [unique_id "app21BHAoQGRWaCyWYWIqgAAAQ4"]
show less
Brute-Force
Bad Web Bot
Web App Attack