🇺🇸
kosada.com
2026-09-05 13:14:05
(5 hours ago)
Repeated requests for suspicious nonexistent URLs, for example: /var/www/.git/config (HTTP/1.1 port ...
show more
Repeated requests for suspicious nonexistent URLs, for example: /var/www/.git/config (HTTP/1.1 port 443, user agent: "crusader-worker/1.0")
show less
Web App Attack
🇩🇪
Nightreaver
2026-09-05 07:42:39
(11 hours ago)
35.190.214.230 - - [05/Sep/2026:09:42:39 0200] "GET /.env.backup HTTP/1.1" 404 5722 "-" "crusader-w ...
show more
35.190.214.230 - - [05/Sep/2026:09:42:39 0200] "GET /.env.backup HTTP/1.1" 404 5722 "-" "crusader-worker/1.0"
35.190.214.230 - - [05/Sep/2026:09:42:39 0200] "GET /.env.old HTTP/1.1" 404 5722 "-" "crusader-worker/1.0"
35.190.214.230 - - [05/Sep/2026:09:42:39 0200] "GET /wp-config.php.bak HTTP/1.1" 404 5722 "-" "crusader-worker/1.0"
35.190.214.230 - - [05/Sep/2026:09:42:39 0200] "GET /.env.dev HTTP/1.1" 404 5722 "-" "crusader-worker/1.0"
35.190.214.230 - - [05/Sep/2026:09:42:39 0200] "GET /_ignition/health-check HTTP/1.1" 404 5722 "-" "crusader-worker/1.0"[...]
show less
Bad Web Bot
Web App Attack
Anonymous
2026-09-05 06:58:59
(11 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
🇪🇸
Gem
2026-09-04 22:11:47
(20 hours ago)
Unauthorized web scan.
Web App Attack
🇳🇱
homeshowdomain.nl
2026-09-04 22:03:00
(20 hours ago)
Auto-ban: >3000 req/min op 2026-09-04
Web App Attack
SSH
Hacking
🇺🇸
TPI-Abuse
2026-09-04 15:19:39
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.190.214.230 (230.214.190.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.190.214.230 (230.214.190.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 11:19:32.017601 2026] [security2:error] [pid 23311:tid 23311] [client 35.190.214.230:48516] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.nataliedenizescott.com"] [uri "/.env.local"] [unique_id "aprhhDYh99xMCckiFtiscgAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 14:53:48
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.190.214.230 (230.214.190.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.190.214.230 (230.214.190.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 10:53:43.235648 2026] [security2:error] [pid 21370:tid 21370] [client 35.190.214.230:54140] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ppichardocigars.com"] [uri "/.env.old"] [unique_id "aprbd9-wTcSbvBGRCtlR2wAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
ISPLtd
2026-09-04 14:51:23
(1 day ago)
Sep 4 11:51:22 35.190.214.230 TCP SPT=36570 DPT=80 SYN
Sep 4 11:51:22 35.190.214.230 TCP SPT=36584 ...
show more
Sep 4 11:51:22 35.190.214.230 TCP SPT=36570 DPT=80 SYN
Sep 4 11:51:22 35.190.214.230 TCP SPT=36584 DPT=80 SYN
Sep 4 11:51:22 35.190.214.230 TCP SPT=36572 DPT=80 SYN
...
show less
DDoS Attack
🇺🇸
TPI-Abuse
2026-09-04 14:07:50
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.190.214.230 (230.214.190.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.190.214.230 (230.214.190.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 10:07:46.316398 2026] [security2:error] [pid 32652:tid 32652] [client 35.190.214.230:33486] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.nematoads.com"] [uri "/.env.backup"] [unique_id "aprQsvanFluus6y6kGCMtwAAAGU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-04 14:05:02
(1 day ago)
suspicious request in access.log
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 13:36:16
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.190.214.230 (230.214.190.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.190.214.230 (230.214.190.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 09:36:08.820157 2026] [security2:error] [pid 31066:tid 31066] [client 35.190.214.230:38350] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "feministvoice.blog"] [uri "/.env.old"] [unique_id "aprJSJMEo-c0CHWWIo4ycQAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 12:53:32
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.190.214.230 (230.214.190.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.190.214.230 (230.214.190.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 08:53:29.046757 2026] [security2:error] [pid 7901:tid 7901] [client 35.190.214.230:52132] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "memphislimousines.com"] [uri "/.env.old"] [unique_id "apq_SWTfipUw3F-Uw03X4AAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 12:04:17
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.190.214.230 (230.214.190.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.190.214.230 (230.214.190.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 08:04:12.419544 2026] [security2:error] [pid 25612:tid 25612] [client 35.190.214.230:54136] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "therhclan.com"] [uri "/wp-config.php.bak"] [unique_id "apqzvCpFPXADiJy7cqudDQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-04 10:43:05
(1 day ago)
Web application attack detected.
Web App Attack
🇫🇷
masterguru
2026-09-04 10:13:35
(1 day ago)
Restricted File Access Attempt. Matched phrase ".env" at REQUEST_FILENAME. (930130-201)
Hacking
Web App Attack