🇳🇱
homeshowdomain.nl
2026-09-08 22:03:07
(12 hours ago)
Auto-ban: >3000 req/min op 2026-09-08
Web App Attack
SSH
Hacking
🇺🇸
TPI-Abuse
2026-09-08 09:15:50
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.252.154.180 (180.154.252.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.252.154.180 (180.154.252.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 05:15:42.822719 2026] [security2:error] [pid 12717:tid 12717] [client 35.252.154.180:60960] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.von-s.com"] [uri "/wp-config.php.swp"] [unique_id "ap_SPk6FW_fT2WDCfLE-ogAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-08 06:36:05
(1 day ago)
Bot / scanning and/or hacking attempts: GET / HTTP/1.1, GET /.env/ HTTP/1.1
Hacking
Web App Attack
Anonymous
2026-09-08 06:20:11
(1 day ago)
Bot / seems abusive / Apache connections: 39
DDoS Attack
Web Spam
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 05:15:55
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.252.154.180 (180.154.252.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.252.154.180 (180.154.252.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 01:15:50.570695 2026] [security2:error] [pid 26703:tid 26703] [client 35.252.154.180:49470] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.paintriver.com"] [uri "/wp-config.php.bak"] [unique_id "ap-aBj9VPbtliTn_fBCHJgAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
iNetWorker
2026-09-08 02:20:32
(1 day ago)
trolling for resource vulnerabilities
Web App Attack
🇫🇷
SpaceHost-Server
2026-09-06 22:20:56
(2 days ago)
Brute-Force
Web App Attack
Anonymous
2026-09-06 06:28:08
(3 days ago)
[news.tmg.gr] httpd-config-scan: logs=/var/log/httpd/access_log; samples=/.env | /.env.production | ...
show more
[news.tmg.gr] httpd-config-scan: logs=/var/log/httpd/access_log; samples=/.env | /.env.production | /.env.local
show less
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 03:22:06
(3 days ago)
(mod_security) mod_security (id:949110) triggered by 35.252.154.180 (180.154.252.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:949110) triggered by 35.252.154.180 (180.154.252.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 23:22:01.172672 2026] [security2:error] [pid 16906:tid 16906] [client 35.252.154.180:55876] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "dcagroupusa.com"] [uri "/.env.save"] [unique_id "apzcWURLeMXPygszWjyEJwAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 02:20:46
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 35.252.154.180 (180.154.252.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.252.154.180 (180.154.252.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 22:20:41.437990 2026] [security2:error] [pid 25141:tid 25141] [client 35.252.154.180:53774] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "coloradocultured.com"] [uri "/.env.prod"] [unique_id "apzN-dqcFEEpnYB9GgMWtgAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
mnsf
2026-09-06 02:05:25
(3 days ago)
Scanning/Probing (20)
Brute-Force
Web App Attack
🇩🇪
macrob
2026-09-06 01:32:28
(3 days ago)
2026/09/06 01:32:27 [error] 1902783#1902783: *561181959 access forbidden by rule, client: 35.252.154 ...
show more
2026/09/06 01:32:27 [error] 1902783#1902783: *561181959 access forbidden by rule, client: 35.252.154.180, server: fn.binixo.es, request: "GET /.env.save HTTP/2.0", host: "mx01.fastcredit.net.ua"
2026/09/06 01:32:27 [error] 1902786#1902786: *561181961 access forbidden by rule, client: 35.252.154.180, server: fn.binixo.es, request: "GET /.env.dev HTTP/2.0", host: "mx01.fastcredit.net.ua"
2026/09/06 01:32:27 [error] 1902783#1902783: *561181962 access forbidden by rule, client: 35.252.154.180, server: fn.binixo.es, request: "GET /.env.example HTTP/2.0", host: "mx01.fastcredit.net.ua"
...
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 01:24:21
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 35.252.154.180 (180.154.252.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.252.154.180 (180.154.252.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 21:24:13.528752 2026] [security2:error] [pid 29967:tid 29967] [client 35.252.154.180:41132] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "tiesidebikinis.com"] [uri "/.env"] [unique_id "apzAvQryjqvNnaqIQf6zNwAAAD8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
Nevermind
2026-09-06 01:15:51
(3 days ago)
35.252.154.180 - - [06/Sep/2026:03:15:51 +0200] "GET /.env.save HTTP/1.1" 403 5663 "-" "crusader-wor ...
show more
35.252.154.180 - - [06/Sep/2026:03:15:51 +0200] "GET /.env.save HTTP/1.1" 403 5663 "-" "crusader-worker/1.0"
35.252.154.180 - - [06/Sep/2026:03:15:51 +0200] "GET /.env.prod HTTP/1.1" 403 5663 "-" "crusader-worker/1.0"
35.252.154.180 - - [06/Sep/2026:03:15:51 +0200] "GET /.env.old HTTP/1.1" 403 5663 "-" "crusader-worker/1.0"
35.252.154.180 - - [06/Sep/2026:03:15:51 +0200] "GET /wp-config.php~ HTTP/1.1" 403 5663 "-" "crusader-worker/1.0"
...
show less
Web App Attack
🇫🇷
dynamix
2026-09-06 00:15:39
(3 days ago)
Multiple WAF Violations
Web App Attack