๐ณ๐ฑ
homeshowdomain.nl
2026-09-22 22:01:01
(3 days ago)
Auto-ban: >3000 req/min op 2026-09-22
Web App Attack
SSH
Hacking
๐บ๐ธ
factor1
2026-09-22 17:04:33
(3 days ago)
CrowdSec at sherman Reports Abuse
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 16:43:10
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 35.244.52.171 (171.52.244.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.244.52.171 (171.52.244.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 12:43:02.200358 2026] [security2:error] [pid 11948:tid 11948] [client 35.244.52.171:43948] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "restlesseye.com"] [uri "/.env.old"] [unique_id "arKwFumOE_jywQGbbkstAQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-09-22 16:19:28
(3 days ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
๐บ๐ธ
JustMeHere
2026-09-22 16:09:45
(3 days ago)
[Tue Sep 22 12:09:40.471342 2026] [security2:error] [pid 806:tid 976] [client 35.244.52.171:49110] M ...
show more
[Tue Sep 22 12:09:40.471342 2026] [security2:error] [pid 806:tid 976] [client 35.244.52.171:49110] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:blocking_inbound_anomaly_score. [file "/etc/httpd/modsecurity.d/activated_rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "233"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [ver "OWASP_CRS/4.15.0"] [tag "anomaly-evaluation"] [tag "OWASP_CRS"] [hostname "php.yorknation.com"] [uri "/.env.local"] [unique_id "arKoRCpp51l8JcCV6LdidgAAAJU"]
...
show less
Web App Attack
๐ธ๐ช
vaia.cloud
2026-09-22 15:30:03
(3 days ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
Anonymous
2026-09-22 14:48:57
(3 days ago)
๐จ Repeated automated attempts to access prohibited paths and exploit known web application vulnerabi ...
show more
๐จ Repeated automated attempts to access prohibited paths and exploit known web application vulnerabilities.
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 14:47:26
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 35.244.52.171 (171.52.244.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.244.52.171 (171.52.244.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 10:47:20.647533 2026] [security2:error] [pid 15754:tid 15754] [client 35.244.52.171:53020] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.computer-advisors.com"] [uri "/wp-config.php.swp"] [unique_id "arKU-Gr1L0wlAOj9VOrY3wAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
neckaralb-admin.de
2026-09-22 14:26:01
(3 days ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-22 14:22:26
(3 days ago)
[ti-24al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-24al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 35.244.52.171 - - [22/Sep/2026:16:22:13 +0200] "GET /.env HTTP/2.0" 301 318 "-" "crusader-worker/1.0"
...
show less
Bad Web Bot
Web App Attack
๐จ๐ญ
leo1305
2026-09-22 14:03:21
(3 days ago)
CrowdSec detection | scenario: http-sensitive-files
Web App Attack
Exploited Host
Anonymous
2026-09-22 13:28:27
(3 days ago)
๐ฅ Web application attack detected. Vulnerability scanning and exploitation attempts identified.
Web App Attack
๐ง๐ช
Saec
2026-09-22 13:25:36
(3 days ago)
Jarvis auto-ban: Honeypot /.env.backup via ghost.saec.me [IN] ASN:Google LLC
Port Scan
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 12:48:31
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 35.244.52.171 (171.52.244.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.244.52.171 (171.52.244.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 08:48:27.087053 2026] [security2:error] [pid 12667:tid 12667] [client 35.244.52.171:51110] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "englishmagic.us"] [uri "/wp-config.php.swp"] [unique_id "arJ5GypASZWwX_hebqqt0gAAACA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
consul.to
2026-09-22 12:09:03
(3 days ago)
Web attack/malicious scanning detected
Web App Attack