🇳🇱
homeshowdomain.nl
2026-09-07 21:59:21
(4 hours ago)
Auto-ban: >3000 req/min op 2026-09-07
Web App Attack
SSH
Hacking
🇳🇱
e.fierstra
2026-09-07 21:01:30
(5 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 20:48:57
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 8.234.236.227 (227.236.234.8.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 8.234.236.227 (227.236.234.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 16:48:52.643501 2026] [security2:error] [pid 13402:tid 13402] [client 8.234.236.227:56136] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.krugmans.com"] [uri "/@fs/..%252f..%252f..%252f..%252f..%252froot/.env"] [unique_id "ap8jNDjZIeKVau2ULWTdjQAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 20:24:05
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 8.234.236.227 (227.236.234.8.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 8.234.236.227 (227.236.234.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 16:24:01.750493 2026] [security2:error] [pid 29500:tid 29500] [client 8.234.236.227:52754] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "hogs.whodatnation.com"] [uri "/@fs/.env.production"] [unique_id "ap8dYVB2cqA_1bw9jD7kegAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-07 20:09:13
(6 hours ago)
2026/09/07 20:09:11 [error] 199231#199231: *325861 [client 8.234.236.227] ModSecurity: Access denied ...
show more
2026/09/07 20:09:11 [error] 199231#199231: *325861 [client 8.234.236.227] ModSecurity: Access denied with code 403 (phase 2). Matched "Operator `Ge' with parameter `5' against variable `TX:BLOCKING_INBOUND_ANOMALY_SCORE' (Value: `15' ) [file "/usr/local/owasp-modsecurity-crs-4.11.0/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "222"] [id "949110"] [rev ""] [msg "Inbound Anomaly Score Exceeded (Total Score: 15)"] [data ""] [severity "0"] [ver "OWASP_CRS/4.29.0"] [maturity "0"] [accuracy "0"] [tag "anomaly-evaluation"] [tag "OWASP_CRS"] [hostname "digilms.ingeltechgh.com"] [uri "/@fs/../.env"] [unique_id "17888117512.433383"] [ref ""], client: 8.234.236.227, server: srv.ingeltechgh.com, request: "GET /@fs/../.env?raw?? HTTP/1.1", host: "digilms.ingeltechgh.com"
2026/09/07 20:09:11 [error] 199231#199231: *325863 [client 8.234.236.227] ModSecurity: Access denied with code 403 (phase 2). Matched "Operator `Ge' with parameter `5' against variable `TX:BLOCKING_INBOUND_ANOMALY_SCORE' (Value: `1
...
show less
Brute-Force
🇳🇱
Site.eu
2026-09-07 20:03:32
(6 hours ago)
Excessive 404/403 errors
Brute-Force
🇺🇸
TPI-Abuse
2026-09-07 20:00:40
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 8.234.236.227 (227.236.234.8.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 8.234.236.227 (227.236.234.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 16:00:32.517382 2026] [security2:error] [pid 23761:tid 23761] [client 8.234.236.227:35654] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.groupof12.com"] [uri "/@fs/..%252f..%252f..%252f..%252f..%252fapp/.env"] [unique_id "ap8X4GCAftsFnJv1-pY-4AAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
BlueWire Hosting
2026-09-07 19:54:23
(7 hours ago)
High-confidence malicious configuration/VCS probe
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 19:45:10
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 8.234.236.227 (227.236.234.8.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 8.234.236.227 (227.236.234.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 15:45:04.506718 2026] [security2:error] [pid 6085:tid 6085] [client 8.234.236.227:38070] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.gkwire.com"] [uri "/@fs/.env"] [unique_id "ap8UQKXnbGE6OWz0mfptPQAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
sojan
2026-09-07 19:43:55
(7 hours ago)
8.234.236.227 - - [07/Sep/2026:21:43:36 +0200] "GET /@fs/../../.env?raw?? HTTP/1.1" 400 157 "-" "-"
...
show more
8.234.236.227 - - [07/Sep/2026:21:43:36 +0200] "GET /@fs/../../.env?raw?? HTTP/1.1" 400 157 "-" "-"
8.234.236.227 - - [07/Sep/2026:21:43:54 +0200] "GET /@fs/..%2f..%2f..%2f..%2f..%2fproc/self/environ?raw?? HTTP/1.1" 400 157 "-" "-"
8.234.236.227 - - [07/Sep/2026:21:43:54 +0200] "GET /@fs/../../../../../root/.env?raw?? HTTP/1.1" 400 157 "-" "-"
...
show less
Web App Attack
🇺🇸
gamabe
2026-09-07 18:59:50
(7 hours ago)
Detected crowdsecurity/http-dos-swithcing-ua attack pattern. Reported by CrowdSec IDS.
Hacking
🇳🇱
middelkoopcc
2026-09-07 18:58:01
(7 hours ago)
2026-09-07 20:55:20 GET /@fs/.env?raw?? [301] && 2026-09-07 20:55:20 GET /@fs/.env.production?raw?? ...
show more
2026-09-07 20:55:20 GET /@fs/.env?raw?? [301] && 2026-09-07 20:55:20 GET /@fs/.env.production?raw?? [301] && 2026-09-07 20:55:20 GET /@fs/etc/passwd?raw?? [301] && 118 more within 20 minutes
show less
Web App Attack
🇫🇷
Octopuce
2026-09-07 18:50:39
(8 hours ago)
Aggressive web search of vulnerable pages: /uploads../.env /v1/.env /assets../.env /.docker/.env /.e ...
show more
Aggressive web search of vulnerable pages: /uploads../.env /v1/.env /assets../.env /.docker/.env /.env ...
show less
Web App Attack
🇳🇱
WeCloudit-Anti-Abuse
2026-09-07 18:22:00
(8 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
Anonymous
2026-09-07 18:17:21
(8 hours ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack