π³π±
homeshowdomain.nl
2026-08-01 22:00:35
(3 hours ago)
Auto-ban: >3000 req/min op 2026-08-01
Web App Attack
SSH
Hacking
πΊπΈ
TPI-Abuse
2026-08-01 17:26:19
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.247.207.245 (245.207.247.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.247.207.245 (245.207.247.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 13:26:12.233101 2026] [security2:error] [pid 23461:tid 23461] [client 35.247.207.245:49698] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.creeation.onlyincanada-eh.com"] [uri "/.env.old"] [unique_id "am4sNFPkJGTWnuCFZQTUMgAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π²πΎ
Rizzy
2026-08-01 17:22:56
(7 hours ago)
Multiple WAF Violations
Brute-Force
Web App Attack
Anonymous
2026-08-01 17:20:51
(8 hours ago)
35.247.207.245 - - [02/Aug/2026:01:20:51 +0800] "GET /.env HTTP/1.1" 200 30687 "-" "crusader-worker/ ...
show more
35.247.207.245 - - [02/Aug/2026:01:20:51 +0800] "GET /.env HTTP/1.1" 200 30687 "-" "crusader-worker/1.0"
...
show less
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-01 17:07:51
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.247.207.245 (245.207.247.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.247.207.245 (245.207.247.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 13:07:43.176202 2026] [security2:error] [pid 508689:tid 508689] [client 35.247.207.245:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "camerabshk.365soft.top"] [uri "/.env.example"] [unique_id "am4n39Y5O2O_0qQuXp5-TgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπ¦
URAN Publishing Service
2026-08-01 16:58:36
(8 hours ago)
Multiple unauthorized connection attempts
Web App Attack
π©πͺ
neckaralb-admin.de
2026-08-01 16:33:31
(8 hours ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
Anonymous
2026-08-01 15:51:44
(9 hours ago)
PSCSERV WPSCAN 35.247.207.245
Bad Web Bot
Web App Attack
Anonymous
2026-08-01 15:39:06
(9 hours ago)
Bot / scanning and/or hacking attempts: GET /.env.prod HTTP/1.1, GET /.env.production HTTP/1.1, GET ...
show more
Bot / scanning and/or hacking attempts: GET /.env.prod HTTP/1.1, GET /.env.production HTTP/1.1, GET /.env.example HTTP/1.1, GET /.env.bak HTTP/1.1, GET /.env.backup HTTP/1.1
show less
Hacking
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-01 15:15:59
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.247.207.245 (245.207.247.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.247.207.245 (245.207.247.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 11:15:51.486283 2026] [security2:error] [pid 388329:tid 388357] [client 35.247.207.245:45382] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.acps.aafm.us"] [uri "/.env.old"] [unique_id "am4Np6_ZX0Ma0o1LUa_KvAAAANM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©π°
ScamAware
2026-08-01 14:25:06
(10 hours ago)
Detected by Cloudflare Security Events via WordPress automation. Detection: sensitive_files (Sensiti ...
show more
Detected by Cloudflare Security Events via WordPress automation. Detection: sensitive_files (Sensitive files, source control, config, and backups). Hits from same IP in last 60 minutes: 10. Unique request paths counted internally: 10. Cloudflare action: block. Cloudflare source: firewallCustom.
show less
Web App Attack
π«π·
masterguru
2026-08-01 14:12:59
(11 hours ago)
Restricted File Access Attempt. Matched phrase ".env" at REQUEST_FILENAME. (930130-201)
Hacking
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-01 14:07:48
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.247.207.245 (245.207.247.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.247.207.245 (245.207.247.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 10:07:42.865962 2026] [security2:error] [pid 709511:tid 709511] [client 35.247.207.245:59174] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "katisfaction.nl"] [uri "/.env.dev"] [unique_id "am39rkUHIAfpyKWAgJ-62wAAACM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π¨π¦
polycoda
2026-08-01 13:53:22
(11 hours ago)
AutoBlock: π― Vulnerability Scanner (Non Decay-Based)
Hacking
Web App Attack
π·πΊ
DZBOT
2026-08-01 13:40:49
(11 hours ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack