🇩🇪
LRob
2026-09-08 06:42:55
(25 minutes ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /@fs/.env (+10 more) | 2026-09-08 06:42 UTC
show less
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 06:24:24
(43 minutes ago)
(mod_security) mod_security (id:210492) triggered by 35.187.237.71 (71.237.187.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.187.237.71 (71.237.187.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 02:24:19.392026 2026] [security2:error] [pid 2138:tid 2138] [client 35.187.237.71:14802] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.robinsnestingplace.net"] [uri "/@fs/.env"] [unique_id "ap-qE3pOc3My9EUdFacr0QAAACg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇧🇪
cmbplf
2026-09-08 05:49:21
(1 hour ago)
114 requests with url.path *.local/share/*
Brute-Force
Bad Web Bot
🇳🇱
Site.eu
2026-09-08 05:40:14
(1 hour ago)
Excessive multi-domain requests
Brute-Force
🇫🇮
oh.mg
2026-09-08 05:11:41
(1 hour ago)
35.187.237.71 - - [08/Sep/2026:07:10:54 +0200] "GET /env.js HTTP/1.1" 403 2466 "-" "Mozilla/5.0 (Lin ...
show more
35.187.237.71 - - [08/Sep/2026:07:10:54 +0200] "GET /env.js HTTP/1.1" 403 2466 "-" "Mozilla/5.0 (Linux; Android 12; Pixel 6) AppleWebKit/537.36 (KHTML, like Gecko; compatible; Bytespider; +https://zhanzhang.toutiao.com/) Chrome/91.0.7879.242 Mobile Safari/537.36"
35.187.237.71 - - [08/Sep/2026:07:11:11 +0200] "GET /runtime-config.js HTTP/1.1" 403 2466 "-" "Mozilla/5.0 (Linux; Android 14; Pixel 8) AppleWebKit/537.36 (KHTML, like Gecko; compatible; facebookexternalhit/1.1; +http://www.facebook.com/externalhit_uatext.php) Chrome/130.0.1221.3 Mobile Safari/537.36"
35.187.237.71 - - [08/Sep/2026:07:11:40 +0200] "GET /assets/env.js HTTP/1.1" 403 2466 "-" "Mozilla/5.0 (X11; Linux x86_64; rv:150.12) Gecko/20100101 Firefox/150.12; compatible; Bytespider; +https://zhanzhang.toutiao.com/"
35.187.237.71 - - [08/Sep/2026:07:11:40 +0200] "GET /awsConfig.js HTTP/1.1" 403 2466 "-" "Mozilla/5.0 (compatible; GPTBot/1.2; +https://openai.com/gptbot)"
35.187.237.71 - - [08/Sep/2026:07:11:41 +0200] "GET /.e
...
show less
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 05:11:29
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 35.187.237.71 (71.237.187.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.187.237.71 (71.237.187.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 01:11:25.928344 2026] [security2:error] [pid 19865:tid 19872] [client 35.187.237.71:13474] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.trinketjar.com"] [uri "/@fs/.env"] [unique_id "ap-Y_eiA7oCXpgeGAueUxgAAAMU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇨🇭
🇨🇭 Hosting
2026-09-08 05:10:43
(1 hour ago)
Automated WAF report: 150-175 blocked requests from this IP detected by our WAF.
Bad Web Bot
Web App Attack
🇪🇸
pipeline.es
2026-09-08 05:07:55
(2 hours ago)
Web scanning / probing for vulnerable paths | URL: /.htpasswd | Evidence: www.sereli.es 35.187.237.7 ...
show more
Web scanning / probing for vulnerable paths | URL: /.htpasswd | Evidence: www.sereli.es 35.187.237.71 - - [08/Sep/2026:07:07:25 +0200] \"GET /.htpasswd HTTP/1.1\" 403 211 \"http://sereli.es/.htpasswd\" \"Mozilla/5.0 (compatible; Perplexity-User/1.0; +https://perplexity.ai/perplexity-user)\" GEOIP_COUNTRY_CODE=SG | ASN: GOOGLE-CLOUD-PLATFORM | Country: SG
show less
Port Scan
Web App Attack
🇩🇪
big-cloud.nl
2026-09-08 04:57:25
(2 hours ago)
Try to access /@fs/root/.env?raw??
Web App Attack
🇺🇸
mnsf
2026-09-08 03:05:44
(4 hours ago)
Scanning/Probing (25)
Brute-Force
Web App Attack
🇸🇪
vaia.cloud
2026-09-08 03:00:03
(4 hours ago)
crowdsecurity/http-probing
Brute-Force
Web App Attack
Anonymous
2026-09-08 02:59:37
(4 hours ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-08 02:59:19
(4 hours ago)
(mod_security) mod_security (id:949110) triggered by 35.187.237.71 (71.237.187.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:949110) triggered by 35.187.237.71 (71.237.187.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 22:59:13.539428 2026] [security2:error] [pid 17106:tid 17106] [client 35.187.237.71:12526] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "crazycontrols.com"] [uri "/@fs/app/.env"] [unique_id "ap96AW3p0nW6VfTOpmXaUgAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 02:38:50
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.187.237.71 (71.237.187.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.187.237.71 (71.237.187.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 22:38:45.131986 2026] [security2:error] [pid 9593:tid 9593] [client 35.187.237.71:6612] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.mldlnn.com"] [uri "/@fs/..%252f..%252f..%252f..%252f..%252froot/.env"] [unique_id "ap91NXPthz0Sz3Hi3H5uuwAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
consul.to
2026-09-08 02:13:14
(4 hours ago)
Web attack/malicious scanning detected
Web App Attack