🇳🇱
r4fo.com
2026-09-08 20:04:27
(17 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
🇳🇱
Site.eu
2026-09-08 20:00:36
(17 hours ago)
Excessive multi-domain requests
Brute-Force
🇸🇪
vaia.cloud
2026-09-08 19:35:01
(17 hours ago)
crowdsecurity/http-admin-interface-probing
Brute-Force
Web App Attack
Anonymous
2026-09-08 19:34:12
(17 hours ago)
Bot / seems abusive / Apache connections: 34
DDoS Attack
Web Spam
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 18:13:24
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 207.175.112.99 (99.112.175.207.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 207.175.112.99 (99.112.175.207.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 14:13:16.717076 2026] [security2:error] [pid 1987:tid 1987] [client 207.175.112.99:31584] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "eagles-landing.wexfordcap.com"] [uri "/@fs/root/.env"] [unique_id "aqBQPEIFlm41LSj_gVs_7AAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
middelkoopcc
2026-09-08 17:53:01
(19 hours ago)
2026-09-08 19:51:10 GET /@fs/root/.env?raw?? [301] && 2026-09-08 19:51:10 GET /@fs/.env?raw?? [301] ...
show more
2026-09-08 19:51:10 GET /@fs/root/.env?raw?? [301] && 2026-09-08 19:51:10 GET /@fs/.env?raw?? [301] && 2026-09-08 19:51:10 GET /@fs/app/.env?raw?? [301] && 174 more within 20 minutes
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 17:46:48
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 207.175.112.99 (99.112.175.207.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 207.175.112.99 (99.112.175.207.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 13:46:42.605615 2026] [security2:error] [pid 9217:tid 9217] [client 207.175.112.99:29538] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.creertest.com"] [uri "/@fs/.env"] [unique_id "aqBKAlaBwVrJIq4V1N2btAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
dynamix
2026-09-08 17:39:09
(19 hours ago)
Multiple WAF Violations
Web App Attack
Anonymous
2026-09-08 17:15:14
(19 hours ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack
🇧🇪
cmbplf
2026-09-08 17:03:01
(20 hours ago)
6.401 4xx requests in 1 hour (3d3h5m)
Brute-Force
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-08 17:02:54
(20 hours ago)
(mod_security) mod_security (id:210492) triggered by 207.175.112.99 (99.112.175.207.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 207.175.112.99 (99.112.175.207.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 13:02:49.930137 2026] [security2:error] [pid 20969:tid 20969] [client 207.175.112.99:43088] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.brupharm.org"] [uri "/@fs/src/.env"] [unique_id "aqA_uVO8LPw4PEWjXGc1_AAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-08 16:44:27
(20 hours ago)
Multiple web server 400 error codes from same source ip
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 16:34:28
(20 hours ago)
(mod_security) mod_security (id:210492) triggered by 207.175.112.99 (99.112.175.207.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 207.175.112.99 (99.112.175.207.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 12:34:24.698726 2026] [security2:error] [pid 12553:tid 12553] [client 207.175.112.99:51356] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.rmjaero.com"] [uri "/@fs/app/.env"] [unique_id "aqA5EFqC1p3kZo-OnsbfZAAAAI8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
Savvii
2026-09-08 16:02:24
(21 hours ago)
20 attempts against mh_ha-misbehave-ban on grass
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-08 15:29:29
(21 hours ago)
Aggressive web scan
Web App Attack