🇳🇱
debestelapp
2026-08-29 03:45:08
(16 hours ago)
Web App Attack
🇫🇷
masterguru
2026-08-29 03:41:51
(17 hours ago)
Restricted File Access Attempt. Matched phrase ".env" at REQUEST_FILENAME. (930130-201)
Hacking
Web App Attack
🇩🇪
neckaralb-admin.de
2026-08-29 02:28:27
(18 hours ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
Anonymous
2026-08-29 01:41:36
(19 hours ago)
104.196.180.125 - - [29/Aug/2026:09:41:36 +0800] "GET /.env.production HTTP/1.1" 404 196 "-" "crusad ...
show more
104.196.180.125 - - [29/Aug/2026:09:41:36 +0800] "GET /.env.production HTTP/1.1" 404 196 "-" "crusader-worker/1.0"
104.196.180.125 - - [29/Aug/2026:09:41:36 +0800] "GET /.env.bak HTTP/1.1" 404 196 "-" "crusader-worker/1.0"
104.196.180.125 - - [29/Aug/2026:09:41:36 +0800] "GET /storage/logs/laravel.log HTTP/1.1" 404 196 "-" "crusader-worker/1.0"
104.196.180.125 - - [29/Aug/2026:09:41:36 +0800] "GET /actuator/configprops HTTP/1.1" 404 196 "-" "crusader-worker/1.0"
104.196.180.125 - - [29/Aug/2026:09:41:36 +0800] "GET /.env.backup HTTP/1.1" 404 196 "-" "crusader-worker/1.0"
104.196.180.125 - - [29/Aug/2026:09:41:36 +0800] "GET /.env.local HTTP/1.1" 404 196 "-" "crusader-worker/1.0"
104.196.180.125 - - [29/Aug/2026:09:41:36 +0800] "GET /crusader-404-probe HTTP/1.1" 404 196 "-" "crusader-worker/1.0"
104.196.180.125 - - [29/Aug/2026:09:41:36 +0800] "GET /.env.save HTTP/1.1" 404 196 "-" "crusader-worker/1.0"
104.196.180.125 - - [29/Aug/2026:09:41:36 +0800] "GET /wp-config.php.swp HTTP/1.1" 40
...
show less
Bad Web Bot
Web App Attack
Anonymous
2026-08-29 01:33:42
(19 hours ago)
Banned by Fail2Ban on server
Web App Attack
🇺🇸
TPI-Abuse
2026-08-29 01:24:03
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.196.180.125 (125.180.196.104.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 104.196.180.125 (125.180.196.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 21:23:57.369207 2026] [security2:error] [pid 3363342:tid 3363356] [client 104.196.180.125:42744] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "dubarch.com"] [uri "/.env.example"] [unique_id "apI0rW-f09rsyFsPsuS9jQAAAUQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
WeCloudit-Anti-Abuse
2026-08-29 01:18:22
(19 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
🇺🇸
mnsf
2026-08-29 00:08:58
(20 hours ago)
Abuse Detected (15)
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-08-28 23:58:27
(20 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.196.180.125 (125.180.196.104.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 104.196.180.125 (125.180.196.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 19:58:23.094665 2026] [security2:error] [pid 11243:tid 11243] [client 104.196.180.125:57962] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "asociacionmutualsanjose.com"] [uri "/wp-config.php.bak"] [unique_id "apIgn_mePR1mXaLNSwkZ-QAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
e.fierstra
2026-08-28 23:13:31
(21 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
🇺🇸
Gabriel Camargo
2026-08-28 22:54:13
(21 hours ago)
104.196.180.125 - - [28/Aug/2026:17:54:13 -0500] "GET /.env.production HTTP/1.1" 301 178 "-" "crusad ...
show more
104.196.180.125 - - [28/Aug/2026:17:54:13 -0500] "GET /.env.production HTTP/1.1" 301 178 "-" "crusader-worker/1.0"
104.196.180.125 - - [28/Aug/2026:17:54:13 -0500] "GET /.env.local HTTP/1.1" 301 178 "-" "crusader-worker/1.0"
104.196.180.125 - - [28/Aug/2026:17:54:13 -0500] "GET /.env HTTP/1.1" 301 178 "-" "crusader-worker/1.0"
...
show less
Brute-Force
SSH
🇳🇱
homeshowdomain.nl
2026-08-28 21:59:35
(22 hours ago)
Auto-ban: >3000 req/min op 2026-08-28
Web App Attack
SSH
Hacking
🇺🇸
TPI-Abuse
2026-08-28 21:12:23
(23 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.196.180.125 (125.180.196.104.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 104.196.180.125 (125.180.196.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 17:12:14.889039 2026] [security2:error] [pid 18100:tid 18100] [client 104.196.180.125:59076] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.dolapdere.click.handankoc.net"] [uri "/wp-config.php.swp"] [unique_id "apH5roPDNPk1NAXdo75OyQAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇮🇩
Burayot
2026-08-28 21:09:55
(23 hours ago)
LF_MODSEC: (mod_security) mod_security (id:949110) triggered by 104.196.180.125 (US/United States/12 ...
show more
LF_MODSEC: (mod_security) mod_security (id:949110) triggered by 104.196.180.125 (US/United States/125.180.196.104.bc.googleusercontent.com): 1 in the last 3600 secs
show less
Web App Attack
🇺🇸
kosada.com
2026-08-28 20:51:11
(23 hours ago)
Web vulnerability probing: /wp-config.php~
Web App Attack