🇳🇱
homeshowdomain.nl
2026-09-01 21:59:52
(5 days ago)
Auto-ban: >3000 req/min op 2026-09-01
Web App Attack
SSH
Hacking
🇺🇸
TPI-Abuse
2026-09-01 05:38:08
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 8.234.81.10 (10.81.234.8.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 8.234.81.10 (10.81.234.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 01:38:03.693956 2026] [security2:error] [pid 25745:tid 25753] [client 8.234.81.10:37550] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "i-masmx.com"] [uri "/wp-config.php~"] [unique_id "apZku4BdI55s7-WYQ1o0jwAAAQY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
consul.to
2026-09-01 04:37:49
(6 days ago)
Web attack/malicious scanning detected
Web App Attack
🇳🇱
WeCloudit-Anti-Abuse
2026-09-01 03:08:21
(6 days ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-01 02:34:31
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 8.234.81.10 (10.81.234.8.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 8.234.81.10 (10.81.234.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 22:34:24.225210 2026] [security2:error] [pid 16238:tid 16238] [client 8.234.81.10:42868] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.gabosoftware.com"] [uri "/.env.dev"] [unique_id "apY5sEY_IZEbsUQMA8ZA2wAAAC8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇷🇴
iulianh
2026-09-01 02:27:37
(6 days ago)
80,443
Brute-Force
SSH
🇺🇸
TPI-Abuse
2026-09-01 02:18:29
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 8.234.81.10 (10.81.234.8.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 8.234.81.10 (10.81.234.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 22:18:20.952416 2026] [security2:error] [pid 20506:tid 20519] [client 8.234.81.10:53310] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "hawk-av.com"] [uri "/.env.backup"] [unique_id "apY17Ds9ucFxdqsrUIMtkQAAAEo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
e.fierstra
2026-09-01 02:18:17
(6 days ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
🇩🇪
FeG Deutschland
2026-09-01 00:53:07
(6 days ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 1247
Exploited Host
Web App Attack
🇺🇸
TPI-Abuse
2026-09-01 00:28:39
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 8.234.81.10 (10.81.234.8.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 8.234.81.10 (10.81.234.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 20:28:32.326694 2026] [security2:error] [pid 18749:tid 18749] [client 8.234.81.10:35936] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.noscentpro.com"] [uri "/.env.bak"] [unique_id "apYcMMTwfKzjDh24vP1byAAAAFA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-01 00:12:49
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 8.234.81.10 (10.81.234.8.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 8.234.81.10 (10.81.234.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 20:12:45.415180 2026] [security2:error] [pid 2403:tid 2403] [client 8.234.81.10:33070] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.acsellsre.com"] [uri "/.env.save"] [unique_id "apYYfeZDqvZyCOyQdpCA9gAAACk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-31 23:07:05
(6 days ago)
Automated web scanner. Requested suspicious paths: /.env.dev | /.env | /storage/logs/laravel.log | / ...
show more
Automated web scanner. Requested suspicious paths: /.env.dev | /.env | /storage/logs/laravel.log | /.env.production | /actuator/configprops | /actuator/env | /_ignition/health-check | /env | /.env.bak | /.env.local | /.env.backup | /crusader-404-probe | /.env.prod | /.env.example | /.env.old, /.env.save | /.env | /storage/logs/laravel.log | /.env.production | /actuator/configprops | /actuator/env | /_ignition/health-check | /env | /.env.bak | /.env.local | /.env.backup | /crusader-404-probe | /.env.prod | /.env.example | /.env.old. UTC: 2026-08-31 22:48:47.
show less
Web App Attack
🇫🇷
dynamix
2026-08-31 22:52:48
(6 days ago)
Multiple WAF Violations
Web App Attack
🇺🇸
TPI-Abuse
2026-08-31 22:20:26
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 8.234.81.10 (10.81.234.8.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 8.234.81.10 (10.81.234.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 18:20:20.623245 2026] [security2:error] [pid 11987:tid 11987] [client 8.234.81.10:44908] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.lucasadams.com"] [uri "/.env.dev"] [unique_id "apX-JD_U7WvhJxUNn0R89AAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇨🇭
ca
2026-08-31 22:17:36
(6 days ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking