🇫🇷
Octopuce
2026-09-07 19:21:52
(27 minutes ago)
Aggressive web search of vulnerable pages: /_nuxt/../.env /v2/.env /.env.local /assets../.env /image ...
show more
Aggressive web search of vulnerable pages: /_nuxt/../.env /v2/.env /.env.local /assets../.env /images../.env ...
show less
Web App Attack
Anonymous
2026-09-07 19:08:34
(40 minutes ago)
Blocked by FortiWeb WAF ML threat detection. ML probability: 99%, Country: US, Attack patterns: Word ...
show more
Blocked by FortiWeb WAF ML threat detection. ML probability: 99%, Country: US, Attack patterns: WordPress scanning, Backup file probing, Cloud secrets probing
show less
Bad Web Bot
Web App Attack
🇩🇪
initsol
2026-09-07 19:03:24
(45 minutes ago)
[Mon Sep 07 21:03:18.318525 2026] [authz_core:error] [pid 2461641:tid 2461641] [client 35.192.103.80 ...
show more
[Mon Sep 07 21:03:18.318525 2026] [authz_core:error] [pid 2461641:tid 2461641] [client 35.192.103.80:2102] AH01630: client denied by server configuration: /var/www/
[Mon Sep 07 21:03:23.871576 2026] [authz_core:error] [pid 2461602:tid 2461602] [client 35.192.103.80:35608] AH01630: client denied by server configuration: /var/www/@fs
[Mon Sep 07 21:03:23.881296 2026] [authz_core:error] [pid 2461603:tid 2461603] [client 35.192.103.80:35694] AH01630: client denied by server configuration: /var/www/@fs
...
show less
Brute-Force
🇳🇱
Savvii
2026-09-07 18:59:32
(49 minutes ago)
20 attempts against mh-misbehave-ban on redirect
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 18:23:41
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 35.192.103.80 (80.103.192.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.192.103.80 (80.103.192.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 14:23:36.116804 2026] [security2:error] [pid 17672:tid 17672] [client 35.192.103.80:18090] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "register-yacht-bvi.com"] [uri "/@fs/root/.env"] [unique_id "ap8BKMv-evXXvwx5AnICGwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
Savvii
2026-09-07 18:12:15
(1 hour ago)
20 attempts against mh-misbehave-ban on yeti
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-07 17:45:00
(2 hours ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
🇩🇪
NewGastroline
2026-09-07 17:35:07
(2 hours ago)
Malicious request blocked by CrowdSec on gastro-prod1.boreus.de
Bad Web Bot
Web App Attack
🇬🇧
consul.to
2026-09-07 17:27:32
(2 hours ago)
Web attack/malicious scanning detected
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 17:12:41
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.192.103.80 (80.103.192.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.192.103.80 (80.103.192.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 13:12:36.314927 2026] [security2:error] [pid 10099:tid 10099] [client 35.192.103.80:37470] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.kfraser.com"] [uri "/@fs/..%252f..%252f..%252f..%252f..%252fapp/.env"] [unique_id "ap7whMcG_7HORbMJZTyPRgAAAC4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
oja
2026-09-07 17:12:03
(2 hours ago)
Aggressive web scanner
Web App Attack
🇺🇸
IndigoRidge
2026-09-07 16:58:55
(2 hours ago)
35.192.103.80 - - [07/Sep/2026:12:58:52 -0400] "GET /@fs/..%252f..%252f..%252f..%252f..%252fapp/.env ...
show more
35.192.103.80 - - [07/Sep/2026:12:58:52 -0400] "GET /@fs/..%252f..%252f..%252f..%252f..%252fapp/.env?raw?? HTTP/1.1" 404 73942 "https://carolinacreativegroup.com/@fs/..%252f..%252f..%252f..%252f..%252fapp/.env?raw??" "Mozilla/5.0 (Windows NT 11.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko; compatible; GPTBot/1.4; +https://openai.com/gptbot) Chrome/128.0.7865.164 Safari/537.36"
35.192.103.80 - - [07/Sep/2026:12:58:53 -0400] "GET /@fs/..%252f..%252f..%252f..%252f..%252froot/.env?raw?? HTTP/1.1" 404 73948 "https://carolinacreativegroup.com/@fs/..%252f..%252f..%252f..%252f..%252froot/.env?raw??" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; Claude-SearchBot/1.0; +https://www.anthropic.com/claude-searchbot"
35.192.103.80 - - [07/Sep/2026:12:58:53 -0400] "GET /.env?raw?? HTTP/1.1" 404 72952 "https://carolinacreativegroup.com/@fs/../.env?raw??" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Amazonbot/0.1; +https://developer.amazon.com/support/amazon
...
show less
Web App Attack
🇧🇪
cmbplf
2026-09-07 16:58:03
(2 hours ago)
152 requests with url.path *.config/*
105 requests with url.path *.ssh/*
Brute-Force
Bad Web Bot
🇩🇪
Marc
2026-09-07 16:50:21
(2 hours ago)
35.192.103.80 - - [07/Sep/2026:18:50:20 +0200] "GET /@fs/../.env?raw?? HTTP/1.1" 404 2042 "-" "Mozil ...
show more
35.192.103.80 - - [07/Sep/2026:18:50:20 +0200] "GET /@fs/../.env?raw?? HTTP/1.1" 404 2042 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; GrokBot/1.0; +https://x.ai/grokbot)" 35.192.103.80 - - [07/Sep/2026:18:50:20 +0200] "GET /@fs/..%252f..%252f..%252f..%252f..%252fapp/.env?raw?? HTTP/1.1" 404 2042 "-" "Mozilla/5.0 (Windows NT 10.0; rv:121.10) Gecko/20100101 Firefox/121.10; compatible; ClaudeBot/1.0; [email protected] " 35.192.103.80 - - [07/Sep/2026:18:50:20 +0200] "GET /@fs/src/.env?raw?? HTTP/1.1" 404 2042 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 14_5) AppleWebKit/537.36 (KHTML, like Gecko; compatible; meta-externalagent/1.1; +https://developers.facebook.com/docs/sharing/webmasters/crawler) Chrome/120.0.4763.235 Safari/537.36"
show less
Brute-Force
Anonymous
2026-09-07 16:45:15
(3 hours ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack