🇩🇪
neckaralb-admin.de
2026-09-08 05:01:07
(2 hours ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
🇩🇪
FD-IX
2026-09-08 03:25:52
(4 hours ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
🇳🇱
homeshowdomain.nl
2026-09-07 21:59:28
(9 hours ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-09-06.
show less
Web App Attack
SSH
Hacking
🇬🇧
Apache
2026-09-06 15:49:54
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 35.247.193.0 (BR/Brazil/0.193.247.35.bc.googleu ...
show more
(mod_security) mod_security (id:210730) triggered by 35.247.193.0 (BR/Brazil/0.193.247.35.bc.googleusercontent.com): 5 in the last 300 secs (CF_ENABLE)
show less
Brute-Force
Web App Attack
🇺🇸
Starburst SysOp Team
2026-09-06 06:24:33
(2 days ago)
Host header is a numeric IP address. Pattern match "(?:^( (920350-mnz6-4)
Hacking
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-06 03:35:32
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 35.247.193.0 (0.193.247.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.247.193.0 (0.193.247.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 23:35:28.476128 2026] [security2:error] [pid 7283:tid 7283] [client 35.247.193.0:35364] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "portraitartisans.vittariadesign.com"] [uri "/wp-config.php.bak"] [unique_id "apzfgLsYckOfaI_bchoi4AAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 02:57:32
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 35.247.193.0 (0.193.247.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.247.193.0 (0.193.247.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 22:57:27.114592 2026] [security2:error] [pid 25374:tid 25374] [client 35.247.193.0:60326] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.ceitampa.com"] [uri "/.env.local"] [unique_id "apzWlwLHBy91E2xtePXC-gAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 02:31:23
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 35.247.193.0 (0.193.247.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.247.193.0 (0.193.247.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 22:31:17.264191 2026] [security2:error] [pid 14601:tid 14601] [client 35.247.193.0:41046] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "siriusturbo.com.greenlight.us"] [uri "/.env.save"] [unique_id "apzQdQUJ1CNvYsTsW8FQqwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
e.fierstra
2026-09-06 02:29:24
(2 days ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
Anonymous
2026-09-06 02:28:03
(2 days ago)
Bot / scanning and/or hacking attempts: GET /.env.old HTTP/1.1, GET /wp-config.php.swp HTTP/1.1, GET ...
show more
Bot / scanning and/or hacking attempts: GET /.env.old HTTP/1.1, GET /wp-config.php.swp HTTP/1.1, GET /.env.dev HTTP/1.1, GET /crusader-404-probe HTTP/1.1, GET /env HTTP/1.1, GET /wp-config.php~ HTTP/1.1, GET /.env.example HTTP/1.1
show less
Hacking
Web App Attack
🇺🇸
Gabriel Camargo
2026-09-06 01:31:01
(2 days ago)
35.247.193.0 - - [05/Sep/2026:20:31:00 -0500] "GET /.env HTTP/1.1" 301 178 "-" "crusader-worker/1.0" ...
show more
35.247.193.0 - - [05/Sep/2026:20:31:00 -0500] "GET /.env HTTP/1.1" 301 178 "-" "crusader-worker/1.0"
35.247.193.0 - - [05/Sep/2026:20:31:00 -0500] "GET /env HTTP/1.1" 301 178 "-" "crusader-worker/1.0"
35.247.193.0 - - [05/Sep/2026:20:31:00 -0500] "GET /.env.example HTTP/1.1" 301 178 "-" "crusader-worker/1.0"
...
show less
Brute-Force
SSH
🇺🇸
TPI-Abuse
2026-09-06 00:49:01
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 35.247.193.0 (0.193.247.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.247.193.0 (0.193.247.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 20:48:57.301119 2026] [security2:error] [pid 27873:tid 27873] [client 35.247.193.0:53076] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.floorswedo.com"] [uri "/.env.local"] [unique_id "apy4efcG7OSmv89zISi5JAAAAEY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 00:23:53
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 35.247.193.0 (0.193.247.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.247.193.0 (0.193.247.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 20:23:48.619304 2026] [security2:error] [pid 9163:tid 9163] [client 35.247.193.0:60092] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "lidart.org"] [uri "/wp-config.php.bak"] [unique_id "apyylFpfwuJX2uk1-8jf4wAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 22:38:50
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 35.247.193.0 (0.193.247.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.247.193.0 (0.193.247.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 18:38:43.118409 2026] [security2:error] [pid 20352:tid 20352] [client 35.247.193.0:59304] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "gallery.l3l4.com"] [uri "/.env.example"] [unique_id "apyZ89l5iRNvJ4QEAOGrXgAAAC8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
homeshowdomain.nl
2026-09-05 22:01:25
(2 days ago)
Auto-ban: >3000 req/min op 2026-09-05
Web App Attack
SSH
Hacking