๐ณ๐ฑ
homeshowdomain.nl
2026-08-27 22:00:44
(10 hours ago)
Auto-ban: >3000 req/min op 2026-08-27
Web App Attack
SSH
Hacking
๐ง๐พ
lns.bz
2026-08-27 19:10:41
(13 hours ago)
.env scanning [BY]
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 18:57:30
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.254.166.215 (215.166.254.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.254.166.215 (215.166.254.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 14:57:23.829796 2026] [security2:error] [pid 22141:tid 22141] [client 35.254.166.215:58732] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "infinitynull.net"] [uri "/.env.backup"] [unique_id "apCIk7S4CdOID5HjKtpWuQAAAC4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ท
Peregrine
2026-08-27 18:32:24
(14 hours ago)
Fail2Ban Jail: tomcat-404 | Evidence: - 35.254.166.215 - - [27/Aug/2026:15:32:15 -0300] "GET /wp-con ...
show more
Fail2Ban Jail: tomcat-404 | Evidence: - 35.254.166.215 - - [27/Aug/2026:15:32:15 -0300] "GET /wp-config.php.swp HTTP/1.1" 404 414
- 35.254.166.215 - - [27/Aug/2026:15:32:15 -0300] "GET /env HTTP/1.1" 404 414
- 35.254.166.215 - - [27/Aug/2026:15:32:15 -0300] "GET /actuator/env HTTP/1.1" 404 414
- 35.254.166.215 - - [27/Aug/2026:15:32:15 -0300] "GET /_ignition/health-check HTTP/1.1" 404 414
- 35.254.166.215 - - [27/Aug/2026:15:32:15 -0300] "GET /actuator/configprops HTTP/1.1" 404 414
- 35.254.166.215 - - [27/Aug/2026:15:32:15 -0300] "GET /storage/logs/laravel.log HTTP/1.1" 404 414
- 35.254.166.215 - - [27/Aug/2026:15:32:15 -0300] "GET /wp-config.php~ HTTP/1.1" 404 414
- 35.254.166.215 - - [27/Aug/2026:15:32:15 -0300] "GET /crusader-404-probe HTTP/1.1" 404 414
- 35.254.166.215 - - [27/Aug/2026:15:32:15 -0300] "GET /wp-config.php.bak HTTP/1.1" 404 414
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 17:53:43
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.254.166.215 (215.166.254.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.254.166.215 (215.166.254.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 13:53:39.220009 2026] [security2:error] [pid 24274:tid 24274] [client 35.254.166.215:35614] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "tanvie.joanofartdesign.com"] [uri "/.env.dev"] [unique_id "apB5o3NaU5wLEwSs1JAzuQAAADQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-27 17:38:35
(15 hours ago)
Scan for .env Files at 2026-08-27T17:38:35+00:00
Web App Attack
๐ซ๐ท
Baking333
2026-08-27 17:07:27
(15 hours ago)
[redacted] 35.254.166.215 - - [27/Aug/2026:18:07:25 +0100] "GET /.env HTTP/1.1" 302 6783 0/48795 "-" ...
show more
[redacted] 35.254.166.215 - - [27/Aug/2026:18:07:25 +0100] "GET /.env HTTP/1.1" 302 6783 0/48795 "-" "crusader-worker/1.0" [redacted] 35.254.166.215 - - [27/Aug/2026:18:07:25 +0100] "GET /.[redacted] HTTP/1.1" 302 6783 0/47373 "-" "crusader-worker/1.0"
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
Lee Daniel
2026-08-27 16:48:37
(15 hours ago)
35.254.166.215 - - [27/Aug/2026:12:48:37 -0400] "GET /.env HTTP/1.1" 403 6236 "-" "crusader-worker/1 ...
show more
35.254.166.215 - - [27/Aug/2026:12:48:37 -0400] "GET /.env HTTP/1.1" 403 6236 "-" "crusader-worker/1.0"
...
show less
DDoS Attack
Web Spam
Email Spam
Port Scan
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 16:33:05
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.254.166.215 (215.166.254.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.254.166.215 (215.166.254.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 12:33:01.043587 2026] [security2:error] [pid 17537:tid 17537] [client 35.254.166.215:57202] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.garantaconsulting.internetnameregistration.com"] [uri "/.env.prod"] [unique_id "apBmvUnTJbOG_QpZ8i5N4AAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-27 16:16:31
(16 hours ago)
35.254.166.215 - - [27/Aug/2026:18:16:22 +0200] "GET /wp-config.php.bak HTTP/1.1" 403 146 "-" "crusa ...
show more
35.254.166.215 - - [27/Aug/2026:18:16:22 +0200] "GET /wp-config.php.bak HTTP/1.1" 403 146 "-" "crusader-worker/1.0"
...
show less
Web App Attack
๐ฎ๐ฉ
Burayot
2026-08-27 15:47:45
(16 hours ago)
LF_MODSEC: (mod_security) mod_security (id:949110) triggered by 35.254.166.215 (US/United States/215 ...
show more
LF_MODSEC: (mod_security) mod_security (id:949110) triggered by 35.254.166.215 (US/United States/215.166.254.35.bc.googleusercontent.com): 1 in the last 3600 secs
show less
Web App Attack
๐ธ๐ช
vaia.cloud
2026-08-27 15:45:04
(16 hours ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 15:34:52
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.254.166.215 (215.166.254.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.254.166.215 (215.166.254.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 11:34:45.878177 2026] [security2:error] [pid 15486:tid 15486] [client 35.254.166.215:34160] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.liferestorationproject.rejuvenationsystems.com"] [uri "/.env.save"] [unique_id "apBZFf3M0VWSyvurboDpHAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 15:04:40
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.254.166.215 (215.166.254.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.254.166.215 (215.166.254.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 11:04:31.512485 2026] [security2:error] [pid 21762:tid 21762] [client 35.254.166.215:43674] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "julieknightbooks.com"] [uri "/.env.save"] [unique_id "apBR_9oiBms37su-KUX_zQAAADA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ท๐บ
DZBOT
2026-08-27 14:59:24
(17 hours ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack