🇷🇺
DZBOT
2026-08-27 18:36:45
(2 weeks ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
🇺🇸
TPI-Abuse
2026-08-27 18:15:07
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 35.185.113.246 (246.113.185.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.185.113.246 (246.113.185.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 14:14:55.315748 2026] [security2:error] [pid 519:tid 519] [client 35.185.113.246:47796] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "elessenlabz.com.lucid-events.com"] [uri "/wp-config.php.swp"] [unique_id "apB-n7zJ20N-nWM6KfVgrwAAACA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇸🇪
vaia.cloud
2026-08-27 18:15:02
(2 weeks ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
🇩🇪
LRob
2026-08-27 17:34:38
(2 weeks ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /wp-config.php.bak (+12 more) | 2026-08-27 17:34 UTC
show less
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-08-27 17:02:39
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 35.185.113.246 (246.113.185.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.185.113.246 (246.113.185.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 13:02:32.736477 2026] [security2:error] [pid 8930:tid 8930] [client 35.185.113.246:43664] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.casagordo.goodacoustic.com"] [uri "/wp-config.php.swp"] [unique_id "apBtqEcCEb2w1S6sZq2QTAAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇦
URAN Publishing Service
2026-08-27 16:59:16
(2 weeks ago)
[27/Aug/2026:19:59:15 +0300] -- 35.185.113.246 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.en ...
show more
[27/Aug/2026:19:59:15 +0300] -- 35.185.113.246 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.env.local HTTP/1.1
show less
Bad Web Bot
Web App Attack
🇺🇸
jfz-abuse
2026-08-27 16:41:46
(2 weeks ago)
fail2ban: apache-filepath-recon
...
Web App Attack
Anonymous
2026-08-27 16:09:42
(2 weeks ago)
35.185.113.246 - - [27/Aug/2026:18:09:41 +0200] "GET /actuator/configprops HTTP/1.1" 404 444 "-" "cr ...
show more
35.185.113.246 - - [27/Aug/2026:18:09:41 +0200] "GET /actuator/configprops HTTP/1.1" 404 444 "-" "crusader-worker/1.0"
35.185.113.246 - - [27/Aug/2026:18:09:41 +0200] "GET /actuator/configprops HTTP/1.1" 404 295 "-" "crusader-worker/1.0"
35.185.113.246 - - [27/Aug/2026:18:09:41 +0200] "GET /.env.example HTTP/1.1" 404 444 "-" "crusader-worker/1.0"
35.185.113.246 - - [27/Aug/2026:18:09:41 +0200] "GET /.env.example HTTP/1.1" 404 295 "-" "crusader-worker/1.0"
35.185.113.246 - - [27/Aug/2026:18:09:41 +0200] "GET /.env.bak HTTP/1.1" 404 444 "-" "crusader-worker/1.0"
35.185.113.246 - - [27/Aug/2026:18:09:41 +0200] "GET /.env.bak HTTP/1.1" 404 295 "-" "crusader-worker/1.0"
35.185.113.246 - - [27/Aug/2026:18:09:42 +0200] "GET /wp-config.php.bak HTTP/1.1" 404 444 "-" "crusader-worker/1.0"
35.185.113.246 - - [27/Aug/2026:18:09:42 +0200] "GET /wp-config.php.bak HTTP/1.1" 404 295 "-" "crusader-worker/1.0"
35.185.113.246 - - [27/Aug/2026:18:09:42 +0200] "GET /storage/logs/laravel.log HTTP/1.1" 404 4
...
show less
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-27 15:56:02
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 35.185.113.246 (246.113.185.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.185.113.246 (246.113.185.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 11:55:55.848213 2026] [security2:error] [pid 19320:tid 19320] [client 35.185.113.246:52896] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "minetterisquez.com"] [uri "/wp-config.php~"] [unique_id "apBeCxv-E87IPRkuSu3rSwAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
s@ch@
2026-08-27 15:45:02
(2 weeks ago)
Jail: plesk-modsecurity | Web application attack (Plesk ModSecurity)
Web App Attack
🇺🇸
mnsf
2026-08-27 15:05:17
(2 weeks ago)
Abuse Detected (12)
Brute-Force
Web App Attack
🇫🇷
dynamix
2026-08-27 14:48:31
(2 weeks ago)
Multiple WAF Violations
Web App Attack
🇺🇸
TPI-Abuse
2026-08-27 14:11:41
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 35.185.113.246 (246.113.185.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.185.113.246 (246.113.185.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 10:11:34.461796 2026] [security2:error] [pid 7265:tid 7265] [client 35.185.113.246:57200] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "crewspacer.com.coalminer.com"] [uri "/wp-config.php.bak"] [unique_id "apBFltJ61-v_v8kVodvVsQAAACc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
WeCloudit-Anti-Abuse
2026-08-27 14:06:14
(2 weeks ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
🇦🇱
router.al
2026-08-27 13:43:59
(2 weeks ago)
08/27/2026-13:43:58.719878 35.185.113.246 Protocol: 6 ET WEB_SERVER Tilde in URI - potential .php~ s ...
show more
08/27/2026-13:43:58.719878 35.185.113.246 Protocol: 6 ET WEB_SERVER Tilde in URI - potential .php~ source disclosure vulnerability
show less
Hacking