🇳🇱
homeshowdomain.nl
2026-09-07 21:59:10
(34 minutes ago)
Auto-ban: >3000 req/min op 2026-09-07
Web App Attack
SSH
Hacking
🇺🇸
TPI-Abuse
2026-09-07 20:48:10
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 35.252.201.142 (142.201.252.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.252.201.142 (142.201.252.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 16:48:03.276256 2026] [security2:error] [pid 2389997:tid 2389997] [client 35.252.201.142:1832] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "procurement.ic1.biz"] [uri "/@fs/../../.env"] [unique_id "ap8jA6DGalYsUuqXa03zdAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 20:32:28
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.252.201.142 (142.201.252.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.252.201.142 (142.201.252.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 16:32:23.761055 2026] [security2:error] [pid 9646:tid 9646] [client 35.252.201.142:24976] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.cinemastation.video"] [uri "/@fs/.env"] [unique_id "ap8fV9P_XA0nJtexmuZtaAAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
mnsf
2026-09-07 20:05:20
(2 hours ago)
Too many Status 40X (15)
Brute-Force
Web App Attack
🇬🇧
consul.to
2026-09-07 20:02:52
(2 hours ago)
Web attack/malicious scanning detected
Web App Attack
🇩🇪
big-cloud.nl
2026-09-07 19:57:54
(2 hours ago)
Try to access /@fs/..%252f..%252f..%252f..%252f..%252froot/.env?raw??
Web App Attack
🇩🇪
FeG Deutschland
2026-09-07 19:33:53
(2 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 1247
Exploited Host
Web App Attack
Anonymous
2026-09-07 19:26:58
(3 hours ago)
GET /@fs/.env.development?raw?? HTTP/1.1
...
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 19:26:19
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.252.201.142 (142.201.252.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.252.201.142 (142.201.252.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 15:26:14.437552 2026] [security2:error] [pid 3339:tid 3339] [client 35.252.201.142:22034] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.puckerbackbikini.com"] [uri "/@fs/root/.env"] [unique_id "ap8P1h95xKNCvmj2Y1XTbAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
rdpguard.com
2026-09-07 19:00:29
(3 hours ago)
RdpGuard detected brute-force attempt on HTTP
Brute-Force
Anonymous
2026-09-07 18:47:47
(3 hours ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
🇳🇱
Savvii
2026-09-07 18:24:24
(4 hours ago)
20 attempts against mh-misbehave-ban on redirect
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 18:18:25
(4 hours ago)
(mod_security) mod_security (id:949110) triggered by 35.252.201.142 (142.201.252.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:949110) triggered by 35.252.201.142 (142.201.252.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 14:18:17.903707 2026] [security2:error] [pid 26254:tid 26254] [client 35.252.201.142:39736] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 20)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "www.gatewayacoustics.com"] [uri "/@fs/..%2f..%2f..%2f..%2f..%2froot/.env"] [unique_id "ap7_6Z3eNtftKxBLY7lGZQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 17:38:42
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.252.201.142 (142.201.252.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.252.201.142 (142.201.252.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 13:38:34.230951 2026] [security2:error] [pid 23715:tid 23715] [client 35.252.201.142:20734] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.foros2cn.vientodelevante.es"] [uri "/@fs/.env"] [unique_id "ap72mk2IyDbhy92tIPjr6gAAAC8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
e.fierstra
2026-09-07 17:17:37
(5 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack