๐ธ๐ช
vaia.cloud
2026-08-28 12:50:03
(36 minutes ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-08-28 12:25:09
(1 hour ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐ฟ๐ฆ
conure.sh
2026-08-28 12:14:57
(1 hour ago)
csagent: score 25.0: 404 noise floor x4, secrets grab x2, botnet path probe x1; 1 domain(s) in 0s
Web App Attack
๐ฆ๐บ
aranguren.org
2026-08-28 11:18:19
(2 hours ago)
104.196.60.174 - - [28/Aug/2026:21:18:19 +1000] "GET /crusader-404-probe HTTP/1.1" 404 999 "-" "crus ...
show more
104.196.60.174 - - [28/Aug/2026:21:18:19 +1000] "GET /crusader-404-probe HTTP/1.1" 404 999 "-" "crusader-worker/1.0"
104.196.60.174 - - [28/Aug/2026:21:18:19 +1000] "GET /.env.old HTTP/1.1" 404 999 "-" "crusader-worker/1.0"
104.196.60.174 - - [28/Aug/2026:21:18:19 +1000] "GET /wp-config.php.swp HTTP/1.1" 404 999 "-" "crusader-worker/1.0"
104.196.60.174 - - [28/Aug/2026:21:18:19 +1000] "GET /wp-config.php.bak HTTP/1.1" 404 999 "-" "crusader-worker/1.0"
104.196.60.174 - - [28/Aug/2026:21:18:19 +1000] "GET /env HTTP/1.1" 404 999 "-" "crusader-worker/1.0"
104.196.60.174 - - [28/Aug/2026:21:18:19 +1000] "GET /.env.save HTTP/1.1" 404 999 "-" "crusader-worker/1.0"
...
show less
Bad Web Bot
๐ต๐ฑ
lns.bz
2026-08-27 22:24:47
(15 hours ago)
Web app attack [PL.Lu]
Exploited Host
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-08-27 21:59:50
(15 hours ago)
Auto-ban: >3000 req/min op 2026-08-27
Web App Attack
SSH
Hacking
๐ณ๐ฑ
i-turnradio.nl
2026-08-27 20:53:13
(16 hours ago)
2026-08-27 22:53:13 (CET) ~ Blocked by abusescan risk assessment
Web App Attack
๐ฉ๐ช
Balthasar Morpheus Jรถrmundur (JKweb Service)
2026-08-27 19:29:30
(17 hours ago)
JKweb Security: Severe and dangerous web attack detected. Vulnerability Wordpress Scanning, Director ...
show more
JKweb Security: Severe and dangerous web attack detected. Vulnerability Wordpress Scanning, Directory Brute-Forcing / Content Discovery, Predictable Resource Location / Forced Browsing, Scan for administration and debugging interfaces of modern frameworks, Scan for Spring Boot Actuator Leaks, Scan for Cloud & Infrastructure Credentials, Scan for Database & Backup Dumps, Scan for IDE- und Editor-Configurations, Scan for CI/CD Pipelines & GitHub Workflows etc. The Attacker is permanently banned by Fail2Ban, configurate by JKweb Security a brand of JKweb Service.
show less
Port Scan
Bad Web Bot
Web App Attack
๐ฉ๐ช
edena
2026-08-27 19:27:26
(17 hours ago)
104.196.60.174 - - [27/Aug/2026:21:27:26 +0200] "GET /.env.production HTTP/1.1" 403 1842 "-" "crusad ...
show more
104.196.60.174 - - [27/Aug/2026:21:27:26 +0200] "GET /.env.production HTTP/1.1" 403 1842 "-" "crusader-worker/1.0"
104.196.60.174 - - [27/Aug/2026:21:27:26 +0200] "GET /.env.old HTTP/1.1" 403 1842 "-" "crusader-worker/1.0"
104.196.60.174 - - [27/Aug/2026:21:27:26 +0200] "GET /.env.bak HTTP/1.1" 403 1842 "-" "crusader-worker/1.0"
...
show less
Web App Attack
Bad Web Bot
๐ท๐บ
DZBOT
2026-08-27 19:19:42
(18 hours ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 18:50:11
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.196.60.174 (174.60.196.104.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 104.196.60.174 (174.60.196.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 14:50:04.417874 2026] [security2:error] [pid 3364196:tid 3364297] [client 104.196.60.174:51118] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "browbrew.com"] [uri "/.env.production"] [unique_id "apCG3IXx47nwz6PfTcZu4gAAAcQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 18:33:59
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.196.60.174 (174.60.196.104.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 104.196.60.174 (174.60.196.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 14:33:54.364448 2026] [security2:error] [pid 32303:tid 32303] [client 104.196.60.174:43912] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "southhigh81.com"] [uri "/wp-config.php.swp"] [unique_id "apCDElHemm0XZux9QXO5lwAAADs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
todix
2026-08-27 18:17:33
(19 hours ago)
WebAttack or semilar from 104.196.60.174
Web App Attack
๐ฉ๐ช
Hazzard
2026-08-27 18:05:44
(19 hours ago)
(mod_security) mod_security triggered on hostname [redacted]): (CF_ENABLE)
SQL Injection
๐ณ๐ด
jad-abuse
2026-08-27 17:59:54
(19 hours ago)
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: ignition_ ...
show more
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: ignition_debug, scanner_ua, env_probe, source_backup, config_backup, actuator. Observed by 1 sensor(s); 19 hits.
show less
Hacking
Web App Attack