๐ฌ๐ง
relianoid.com
2026-08-28 19:13:13
(4 minutes ago)
404 Errors Abuse detected by Relianoid OSS Load Balancer - relianoid.com
Web App Attack
๐จ๐ญ
4server
2026-08-28 18:47:18
(30 minutes ago)
[FriAug2820:47:14.0499382026][security2:error][pid2573014:tid2573550][client35.190.136.253:0]ModSecu ...
show more
[FriAug2820:47:14.0499382026][security2:error][pid2573014:tid2573550][client35.190.136.253:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\".env\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"610\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"cpcontacts.mondo-it.ch\"][uri\"/.env.prod\"][unique_id\"apHXspQHkYY6BNuW0Prg5QAAAJE\"]
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 18:18:47
(59 minutes ago)
(mod_security) mod_security (id:210492) triggered by 35.190.136.253 (253.136.190.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.190.136.253 (253.136.190.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 14:18:41.485430 2026] [security2:error] [pid 7001:tid 7001] [client 35.190.136.253:59040] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "georgegourmet.visionremota.info"] [uri "/wp-config.php.swp"] [unique_id "apHRAU3V36_xjFDwg3hK7AAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
MaxMeier
2026-08-28 18:16:59
(1 hour ago)
35.190.136.253 - - [28/Aug/2026:20:15:58 +0200] "GET /.env.local HTTP/1.1" 444 0 "-" "crusader-worke ...
show more
35.190.136.253 - - [28/Aug/2026:20:15:58 +0200] "GET /.env.local HTTP/1.1" 444 0 "-" "crusader-worker/1.0"
35.190.136.253 - - [28/Aug/2026:20:15:58 +0200] "GET /crusader-404-probe HTTP/1.1" 444 0 "-" "crusader-worker/1.0"
35.190.136.253 - - [28/Aug/2026:20:15:58 +0200] "GET /.env.prod HTTP/1.1" 444 0 "-" "crusader-worker/1.0"
35.190.136.253 - - [28/Aug/2026:20:15:58 +0200] "GET /.env.backup HTTP/1.1" 444 0 "-" "crusader-worker/1.0"
35.190.136.253 - - [28/Aug/2026:20:15:58 +0200] "GET /.env HTTP/1.1" 444 0 "-" "crusader-worker/1.0"
35.190.136.253 - - [28/Aug/2026:20:15:58 +0200] "GET /.env.production HTTP/1.1" 444 0 "-" "crusader-worker/1.0"
35.190.136.253 - - [28/Aug/2026:20:15:58 +0200] "GET /wp-config.php~ HTTP/1.1" 444 0 "-" "crusader-worker/1.0"
35.190.136.253 - - [28/Aug/2026:20:15:58 +0200] "GET /env HTTP/1.1" 444 0 "-" "crusader-worker/1.0"
...
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob
2026-08-28 17:58:47
(1 hour ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /.env.local (+12 more) | 2026-08-28 17:58 UTC
show less
Hacking
Web App Attack
๐ณ๐ด
jad-abuse
2026-08-28 17:46:05
(1 hour ago)
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: env_probe ...
show more
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: env_probe, scanner_ua, source_backup, config_backup, actuator, ignition_debug. Observed by 1 sensor(s); 52 hits.
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 17:25:26
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 35.190.136.253 (253.136.190.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.190.136.253 (253.136.190.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 13:25:20.466310 2026] [security2:error] [pid 25278:tid 25278] [client 35.190.136.253:33354] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "smarthome.varnadorefamily.com"] [uri "/.env.local"] [unique_id "apHEgBf513DfNIPhytKvvQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-08-28 17:05:05
(2 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
Anonymous
2026-08-28 16:33:04
(2 hours ago)
Bot / scanning and/or hacking attempts: GET /.env.dev HTTP/1.1, GET /.env.bak HTTP/1.1, GET /.env.ba ...
show more
Bot / scanning and/or hacking attempts: GET /.env.dev HTTP/1.1, GET /.env.bak HTTP/1.1, GET /.env.backup HTTP/1.1
show less
Hacking
Web App Attack
๐ฉ๐ช
yitzhaq
2026-08-28 15:18:25
(3 hours ago)
35.190.136.253 - - [28/Aug/2026:17:18:22 +0200] "GET /wp-config.php.bak HTTP/1.1" 404 62660 "-" "cru ...
show more
35.190.136.253 - - [28/Aug/2026:17:18:22 +0200] "GET /wp-config.php.bak HTTP/1.1" 404 62660 "-" "crusader-worker/1.0"
35.190.136.253 - - [28/Aug/2026:17:18:22 +0200] "GET /wp-config.php~ HTTP/1.1" 404 62660 "-" "crusader-worker/1.0"
35.190.136.253 - - [28/Aug/2026:17:18:22 +0200] "GET /_ignition/health-check HTTP/1.1" 404 67668 "-" "crusader-worker/1.0"
35.190.136.253 - - [28/Aug/2026:17:18:22 +0200] "GET /.env.save HTTP/1.1" 404 66443 "-" "crusader-worker/1.0"
35.190.136.253 - - [28/Aug/2026:17:18:22 +0200] "GET /actuator/env HTTP/1.1" 404 66444 "-" "crusader-worker/1.0"
35.190.136.253 - - [28/Aug/2026:17:18:22 +0200] "GET /actuator/configprops HTTP/1.1" 404 62660 "-" "crusader-worker/1.0"
35.190.136.253 - - [28/Aug/2026:17:18:22 +0200] "GET /.env.old HTTP/1.1" 404 66443 "-" "crusader-worker/1.0"
35.190.136.253 - - [28/Aug/2026:17:18:22 +0200] "GET /.env.dev HTTP/1.1" 404 66443 "-" "crusader-worker/1.0"
35.190.136.253 - - [28/Aug/2026:17:18:22 +0200] "GET /.env.production HTTP/1.1" 40
show less
Web App Attack
Brute-Force
๐ฉ๐ช
4server
2026-08-28 15:14:22
(4 hours ago)
[FriAug2817:14:20.4392902026][security2:error][pid2820068:tid2820114][client35.190.136.253:0]ModSecu ...
show more
[FriAug2817:14:20.4392902026][security2:error][pid2820068:tid2820114][client35.190.136.253:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Patternmatch\"\(\?i\)\(\?:/\(\?:\^\|/\)\\\\\\\\.\(env\|git\|svn\|hg\|DS_Store\)\|/\(\?:wp-config\|\\\\\\\\.htaccess\|\\\\\\\\.htpasswd\)\|\\\\\\\\.\(\?:sql\|bak\|old\|log\)\$\)\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"156\"][id\"960720\"][msg\"Forbiddenfileaccessattempt\"][severity\"CRITICAL\"][hostname\"tourkomanis.ch\"][uri\"/wp-config.php.swp\"][unique_id\"apGlzGvTJpNzIOX8jC87dgAAAEo\"]
show less
Port Scan
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 15:00:09
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.190.136.253 (253.136.190.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.190.136.253 (253.136.190.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 10:59:58.530674 2026] [security2:error] [pid 26853:tid 26853] [client 35.190.136.253:56162] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "herstonfarm.com"] [uri "/.env.dev"] [unique_id "apGibiwp3R0vxWtYvejyfAAAACI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 14:27:24
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.190.136.253 (253.136.190.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.190.136.253 (253.136.190.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 10:27:16.490389 2026] [security2:error] [pid 4952:tid 4952] [client 35.190.136.253:47470] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "camerongunsmith.com"] [uri "/.env.example"] [unique_id "apGaxEYzdEtSczIkTVLpCwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 14:07:01
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.190.136.253 (253.136.190.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.190.136.253 (253.136.190.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 10:06:54.707124 2026] [security2:error] [pid 24295:tid 24295] [client 35.190.136.253:34806] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "freemanfoundationcle.org"] [uri "/.env.prod"] [unique_id "apGV_lQnxn_cadP8CmEVvgAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
consul.to
2026-08-28 13:43:18
(5 hours ago)
Web attack/malicious scanning detected
Web App Attack