🇺🇸
TPI-Abuse
2026-09-04 14:17:52
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 35.185.90.48 (48.90.185.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.185.90.48 (48.90.185.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 10:17:46.372671 2026] [security2:error] [pid 26952:tid 26952] [client 35.185.90.48:39076] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "windsorpalms.iainrealtor.com"] [uri "/.env.dev"] [unique_id "aprTCqsiluAULcBMEG1ecgAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
LavrinenkoRM
2026-09-04 14:16:54
(1 hour ago)
Sentinel WAF: web/pass.lavrinenko.info; Honeypot URL; confidence=90; blocked_at=2026-09-04T14:02:14. ...
show more
Sentinel WAF: web/pass.lavrinenko.info; Honeypot URL; confidence=90; blocked_at=2026-09-04T14:02:14.909188+00:00
show less
Web App Attack
Anonymous
2026-09-04 14:12:24
(2 hours ago)
Scenarios: http-probing, http-sensitive-files
Total requests: 19
Web App Attack
🇫🇮
000rosiu
2026-09-04 13:47:21
(2 hours ago)
Triggered Cloudflare WAF (firewallCustom) from US.
Action: BLOCK | Protocol: HTTP/1.1 (GET) | Endpoi ...
show more
Triggered Cloudflare WAF (firewallCustom) from US.
Action: BLOCK | Protocol: HTTP/1.1 (GET) | Endpoint: /.env/ | UA: crusader-worker/1.0 • Generated by: github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
🇸🇪
vaia.cloud
2026-09-04 13:40:05
(2 hours ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
🇫🇷
Felisse
2026-09-04 13:02:50
(3 hours ago)
CrowdSec ban: crowdsecurity/http-probing (duration: 3h59m1s)
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 12:53:18
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.185.90.48 (48.90.185.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.185.90.48 (48.90.185.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 08:53:15.254827 2026] [security2:error] [pid 14708:tid 14722] [client 35.185.90.48:41828] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mentz.me.aafm.us"] [uri "/.env.old"] [unique_id "apq_OwJpOaN6CP-sjtfyIQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
Rocky Mountain Bioengineering Symposium
2026-09-04 12:36:05
(3 hours ago)
[Fri Sep 04 06:36:05.429204 2026] [authz_core:error] [pid 200880:tid 140668802414144] [client 35.185 ...
show more
[Fri Sep 04 06:36:05.429204 2026] [authz_core:error] [pid 200880:tid 140668802414144] [client 35.185.90.48:58660] AH01630: client denied by server configuration: /var/www/horde/.env.bak
[Fri Sep 04 06:36:05.430749 2026] [authz_core:error] [pid 200880:tid 140669171529280] [client 35.185.90.48:58538] AH01630: client denied by server configuration: /var/www/horde/wp-config.php~
[Fri Sep 04 06:36:05.465581 2026] [authz_core:error] [pid 200880:tid 140667544131136] [client 35.185.90.48:58660] AH01630: client denied by server configuration: /var/www/horde/wp-config.php.bak
...
show less
Bad Web Bot
🇺🇦
URAN Publishing Service
2026-09-04 12:32:49
(3 hours ago)
[04/Sep/2026:15:32:48 +0300] -- 35.185.90.48 Ban reason: Scanner [CMS_GENERIC] | Request: GET /wp-co ...
show more
[04/Sep/2026:15:32:48 +0300] -- 35.185.90.48 Ban reason: Scanner [CMS_GENERIC] | Request: GET /wp-config.php.swp HTTP/1.1
show less
Bad Web Bot
Web App Attack
Anonymous
2026-09-04 12:22:56
(3 hours ago)
(config_exploit_scan) Configuratie Scanner / Nep GPTBot 35.185.90.48 (US/United States/48.90.185.35. ...
show more
(config_exploit_scan) Configuratie Scanner / Nep GPTBot 35.185.90.48 (US/United States/48.90.185.35.bc.googleusercontent.com): 3 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 35.185.90.48 - - [04/Sep/2026:14:22:53 +0200] "GET /.env.save HTTP/1.1" 406 4831 "-" "crusader-worker/1.0"
35.185.90.48 - - [04/Sep/2026:14:22:53 +0200] "GET /.env.bak HTTP/1.1" 406 4832 "-" "crusader-worker/1.0"
35.185.90.48 - - [04/Sep/2026:14:22:53 +0200] "GET /.env HTTP/1.1" 406 4831 "-" "crusader-worker/1.0"
show less
Port Scan
🇺🇸
mnsf
2026-09-04 12:05:29
(4 hours ago)
Scanning/Probing (20)
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 11:53:46
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.185.90.48 (48.90.185.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.185.90.48 (48.90.185.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 07:53:39.469784 2026] [security2:error] [pid 27778:tid 27778] [client 35.185.90.48:47454] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "streamlinenz.com"] [uri "/wp-config.php.bak"] [unique_id "apqxQ5q3sGvpDSJUBRj0pQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-04 11:25:49
(4 hours ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack
🇮🇹
VHosting
2026-09-04 11:20:05
(4 hours ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
🇳🇴
jad-abuse
2026-09-04 11:18:14
(4 hours ago)
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: env_probe ...
show more
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: env_probe, source_backup, scanner_ua, actuator, ignition_debug, config_backup. Observed by 1 sensor(s); 26 hits.
show less
Hacking
Web App Attack