🇳🇱
i-turnradio.nl
2026-08-30 00:43:51
(3 hours ago)
2026-08-30 02:43:51 (CET) ~ Blocked by abusescan risk assessment
Web App Attack
🇳🇱
homeshowdomain.nl
2026-08-29 22:01:16
(5 hours ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-08-28.
show less
Web App Attack
SSH
Hacking
Anonymous
2026-08-29 04:32:08
(23 hours ago)
Failed login attempt detected by Fail2Ban in plesk-modsecurity jail
Exploited Host
Anonymous
2026-08-29 02:48:25
(1 day ago)
GET /.env.old HTTP/1.1
...
Web App Attack
🇺🇸
TPI-Abuse
2026-08-29 01:48:54
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.243.136.237 (237.136.243.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.243.136.237 (237.136.243.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 21:48:43.288560 2026] [security2:error] [pid 29304:tid 29304] [client 35.243.136.237:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.wiszen.org"] [uri "/.env.old"] [unique_id "apI6eyLyYlO6vdXL3yY26QAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-29 01:13:41
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.243.136.237 (237.136.243.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.243.136.237 (237.136.243.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 21:13:35.284521 2026] [security2:error] [pid 106473:tid 106480] [client 35.243.136.237:46632] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "condominium-property-management.com"] [uri "/wp-config.php.bak"] [unique_id "apIyPwT0nhezPdooEOmd9AAAAMM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
arsonist
2026-08-29 00:50:39
(1 day ago)
This IP accessed the path /.env.local, which is banned. Powered by ListenCaddy
Bad Web Bot
Web App Attack
Anonymous
2026-08-29 00:25:44
(1 day ago)
35.243.136.237 - - [29/Aug/2026:02:25:43 +0200] "GET /.env HTTP/1.1" 403 6499 "-" "crusader-worker/1 ...
show more
35.243.136.237 - - [29/Aug/2026:02:25:43 +0200] "GET /.env HTTP/1.1" 403 6499 "-" "crusader-worker/1.0"
35.243.136.237 - - [29/Aug/2026:02:25:43 +0200] "GET /.env.save HTTP/1.1" 403 6499 "-" "crusader-worker/1.0"
...
show less
Web App Attack
🇲🇾
Rizzy
2026-08-29 00:00:15
(1 day ago)
Multiple WAF Violations
Brute-Force
Web App Attack
Anonymous
2026-08-28 23:47:59
(1 day ago)
35.243.136.237 - - [28/Aug/2026:23:47:59 +0000] "GET /.env.production HTTP/1.1" 404 4907 "-" "crusad ...
show more
35.243.136.237 - - [28/Aug/2026:23:47:59 +0000] "GET /.env.production HTTP/1.1" 404 4907 "-" "crusader-worker/1.0"
...
show less
Bad Web Bot
Web App Attack
Anonymous
2026-08-28 22:55:11
(1 day ago)
(config_exploit_scan) Configuratie Scanner / Nep GPTBot 35.243.136.237 (US/United States/237.136.243 ...
show more
(config_exploit_scan) Configuratie Scanner / Nep GPTBot 35.243.136.237 (US/United States/237.136.243.35.bc.googleusercontent.com): 3 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 35.243.136.237 - - [29/Aug/2026:00:55:07 +0200] "GET /.env.bak HTTP/1.1" 406 4830 "-" "crusader-worker/1.0"
35.243.136.237 - - [29/Aug/2026:00:55:07 +0200] "GET /.env.old HTTP/1.1" 406 4831 "-" "crusader-worker/1.0"
35.243.136.237 - - [29/Aug/2026:00:55:07 +0200] "GET /.env.local HTTP/1.1" 406 4831 "-" "crusader-worker/1.0"
show less
Port Scan
Anonymous
2026-08-28 22:10:15
(1 day ago)
| Suspicious URL access.
Web App Attack
Hacking
SQL Injection
🇳🇱
homeshowdomain.nl
2026-08-28 21:59:25
(1 day ago)
Auto-ban: >3000 req/min op 2026-08-28
Web App Attack
SSH
Hacking
🇺🇸
TPI-Abuse
2026-08-28 21:59:10
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.243.136.237 (237.136.243.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.243.136.237 (237.136.243.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 17:59:02.497626 2026] [security2:error] [pid 25084:tid 25084] [client 35.243.136.237:60328] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.favorcakepaperco.com"] [uri "/.env.example"] [unique_id "apIEppEuYH37HAYWxljrCwAAACM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-28 20:51:46
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.243.136.237 (237.136.243.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.243.136.237 (237.136.243.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 16:51:41.142199 2026] [security2:error] [pid 26156:tid 26156] [client 35.243.136.237:58226] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.kingstoneproperties.sendalawyerletter.com"] [uri "/.env"] [unique_id "apH03Xx8QpSEdGm_RiKZ_wAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack