🇩🇪
LRob
2026-09-04 10:44:09
(1 hour ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /wp-config.php~ (+12 more) | 2026-09-04 10:44 UTC
show less
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 10:29:00
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 35.194.159.38 (38.159.194.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.194.159.38 (38.159.194.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 06:28:53.712375 2026] [security2:error] [pid 11114:tid 11114] [client 35.194.159.38:53686] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "1st-advantage-arkansas-real-estate-school.com"] [uri "/.env.backup"] [unique_id "apqdZeRzyOnNxpHSy9ED_wAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 10:02:29
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.194.159.38 (38.159.194.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.194.159.38 (38.159.194.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 06:02:23.902783 2026] [security2:error] [pid 22561:tid 22561] [client 35.194.159.38:46668] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.adults-biz.com"] [uri "/.env.dev"] [unique_id "apqXL0FxEVZkiERND9Q1eAAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
Rocky Mountain Bioengineering Symposium
2026-09-04 10:00:18
(2 hours ago)
[Fri Sep 04 04:00:18.259681 2026] [authz_core:error] [pid 200881:tid 140669741938240] [client 35.194 ...
show more
[Fri Sep 04 04:00:18.259681 2026] [authz_core:error] [pid 200881:tid 140669741938240] [client 35.194.159.38:45194] AH01630: client denied by server configuration: /var/www/horde/wp-config.php.swp
[Fri Sep 04 04:00:18.259812 2026] [authz_core:error] [pid 200881:tid 140668064216640] [client 35.194.159.38:45048] AH01630: client denied by server configuration: /var/www/horde/wp-config.php~
[Fri Sep 04 04:00:18.268895 2026] [authz_core:error] [pid 200882:tid 140670018766400] [client 35.194.159.38:45080] AH01630: client denied by server configuration: /var/www/horde/.env.bak
...
show less
Bad Web Bot
🇸🇪
vaia.cloud
2026-09-04 09:20:05
(2 hours ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
🇳🇱
WeCloudit-Anti-Abuse
2026-09-04 07:47:23
(4 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
🇺🇸
kosada.com
2026-09-04 07:03:11
(5 hours ago)
Repeated exploit attempts, for example: /.env.dev /.env (HTTP/1.1 port 443)
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 06:39:28
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.194.159.38 (38.159.194.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.194.159.38 (38.159.194.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 02:39:21.215621 2026] [security2:error] [pid 12382:tid 12382] [client 35.194.159.38:41266] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ultratec.mx.activethinkers.net"] [uri "/.env.old"] [unique_id "appnmfgkI53iVWiskA-k3QAAACc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
raph
2026-09-04 06:19:05
(5 hours ago)
[Wordpress] crawler /wp-admin/*, /wp-content/*, etc.
Bad Web Bot
Web App Attack
🇬🇧
consul.to
2026-09-04 06:16:53
(5 hours ago)
Web attack/malicious scanning detected
Web App Attack
🇳🇱
debestelapp
2026-09-04 06:00:11
(6 hours ago)
Web App Attack
🇫🇷
masterguru
2026-09-04 05:37:56
(6 hours ago)
Restricted File Access Attempt. Matched phrase ".env" at REQUEST_FILENAME. (930130-195)
Hacking
Web App Attack
Anonymous
2026-09-04 05:31:44
(6 hours ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 04:53:27
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.194.159.38 (38.159.194.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.194.159.38 (38.159.194.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 00:53:22.421841 2026] [security2:error] [pid 7043:tid 7043] [client 35.194.159.38:54090] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "buffalogunsaz.com.compliancedepts.com"] [uri "/.env.production"] [unique_id "appOwiLiuCAT1IrvmJds2QAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 04:31:17
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.194.159.38 (38.159.194.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.194.159.38 (38.159.194.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 00:31:12.018137 2026] [security2:error] [pid 18961:tid 18961] [client 35.194.159.38:55758] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "esysapps.com"] [uri "/.env.prod"] [unique_id "appJkH5XCvn9tj_02PBzwgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack