πΊπΈ
mnsf
2026-09-01 22:05:13
(1 day ago)
Scanning/Probing (20)
Brute-Force
Web App Attack
π³π±
homeshowdomain.nl
2026-09-01 22:00:19
(1 day ago)
Auto-ban: >3000 req/min op 2026-09-01
Web App Attack
SSH
Hacking
πΊπΈ
TPI-Abuse
2026-09-01 05:14:16
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.243.216.86 (86.216.243.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.243.216.86 (86.216.243.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 01:14:11.430910 2026] [security2:error] [pid 9653:tid 9670] [client 35.243.216.86:50100] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "broadmoordermatology.com"] [uri "/.env.old"] [unique_id "apZfI9BQc5QxbtcaYaHiGgAAAQ8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π§πΎ
lns.bz
2026-09-01 04:27:34
(1 day ago)
.env scanning [BY]
Web App Attack
π©πͺ
FD-IX
2026-09-01 04:12:47
(1 day ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
πΊπΈ
Charlesiv
2026-09-01 04:00:48
(1 day ago)
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Prot ...
show more
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Protocol: HTTP/1.1 (GET method)
Endpoint: /.ENV
Timestamp: 2026-09-01T02:53:12Z
Ray ID: a340fbbb6deb6d3d
UA: crusader-worker/1.0
show less
Bad Web Bot
π©πͺ
XICTRON
2026-09-01 03:20:06
(1 day ago)
ModSecurity rule violation detected by Fail2Ban
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-01 03:05:36
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.243.216.86 (86.216.243.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.243.216.86 (86.216.243.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 23:05:30.778492 2026] [security2:error] [pid 3601135:tid 3601290] [client 35.243.216.86:38506] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "paywithfortress.com"] [uri "/.env.dev"] [unique_id "apZA-jXTCLp4H1pGL-uF-wAAAEc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π¬π§
consul.to
2026-09-01 03:02:25
(1 day ago)
Web attack/malicious scanning detected
Web App Attack
πΈπͺ
vaia.cloud
2026-09-01 02:55:06
(1 day ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
π³π±
WeCloudit-Anti-Abuse
2026-09-01 02:50:41
(1 day ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
πΊπΈ
TPI-Abuse
2026-09-01 02:35:00
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.243.216.86 (86.216.243.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.243.216.86 (86.216.243.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 22:34:53.170955 2026] [security2:error] [pid 18061:tid 18061] [client 35.243.216.86:47556] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "backspaced.com.blockdredge.com"] [uri "/wp-config.php.bak"] [unique_id "apY5zdYy1bDsshr-6Hzb3QAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
e.fierstra
2026-09-01 00:55:58
(2 days ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
Anonymous
2026-09-01 00:45:02
(2 days ago)
suspicious request in access.log
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-01 00:19:19
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 35.243.216.86 (86.216.243.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.243.216.86 (86.216.243.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 20:19:11.570962 2026] [security2:error] [pid 22287:tid 22287] [client 35.243.216.86:42672] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.spicymilk.com"] [uri "/.env.production"] [unique_id "apYZ_xuAVOhptip5QEYSgQAAADM"]
show less
Brute-Force
Bad Web Bot
Web App Attack