🇺🇸
[email protected]
2026-09-06 06:26:08
(8 minutes ago)
Multiple requests to well known vulnerable paths:
10
Hacking
Brute-Force
🇫🇷
masterguru
2026-09-06 03:35:16
(2 hours ago)
Restricted File Access Attempt. Matched phrase ".env" at REQUEST_FILENAME. (930130-193)
Hacking
Web App Attack
Anonymous
2026-09-06 01:16:59
(5 hours ago)
35.199.30.226 - - [06/Sep/2026:03:16:58 +0200] "GET /.env.save HTTP/1.1" 403 153 "-" "crusader-worke ...
show more
35.199.30.226 - - [06/Sep/2026:03:16:58 +0200] "GET /.env.save HTTP/1.1" 403 153 "-" "crusader-worker/1.0"
35.199.30.226 - - [06/Sep/2026:03:16:58 +0200] "GET /storage/logs/laravel.log HTTP/1.1" 403 153 "-" "crusader-worker/1.0"
35.199.30.226 - - [06/Sep/2026:03:16:58 +0200] "GET /.env HTTP/1.1" 403 153 "-" "crusader-worker/1.0"
35.199.30.226 - - [06/Sep/2026:03:16:58 +0200] "GET /.env.production HTTP/1.1" 403 153 "-" "crusader-worker/1.0"
35.199.30.226 - - [06/Sep/2026:03:16:58 +0200] "GET /.env.example HTTP/1.1" 403 153 "-" "crusader-worker/1.0"
35.199.30.226 - - [06/Sep/2026:03:16:58 +0200] "GET /.env.local HTTP/1.1" 403 153 "-" "crusader-worker/1.0"
35.199.30.226 - - [06/Sep/2026:03:16:58 +0200] "GET /wp-config.php.bak HTTP/1.1" 403 153 "-" "crusader-worker/1.0"
35.199.30.226 - - [06/Sep/2026:03:16:58 +0200] "GET /wp-config.php~ HTTP/1.1" 403 153 "-" "crusader-worker/1.0"
35.199.30.226 - - [06/Sep/2026:03:16:58 +0200] "GET /.env.dev HTTP/1.1" 403 153 "-" "crusader-worker/1.0"
35.19
...
show less
Bad Web Bot
Web App Attack
🇳🇱
homeshowdomain.nl
2026-09-05 22:00:57
(8 hours ago)
Auto-ban: >3000 req/min op 2026-09-05
Web App Attack
SSH
Hacking
🇺🇸
mnsf
2026-09-05 21:05:14
(9 hours ago)
Scanning/Probing (20)
Brute-Force
Web App Attack
🇳🇱
debestelapp
2026-09-05 20:55:10
(9 hours ago)
Web App Attack
🇧🇾
lns.bz
2026-09-05 07:45:48
(22 hours ago)
Too many 404 requests [BY]
Web App Attack
🇸🇪
nekopavel
2026-09-05 07:25:34
(23 hours ago)
35.199.30.226 - - [05/Sep/2026:09:25:32 +0200]"GET /.env HTTP/1.1" 404 1456"-" 78.69.8.25 "crusader- ...
show more
35.199.30.226 - - [05/Sep/2026:09:25:32 +0200]"GET /.env HTTP/1.1" 404 1456"-" 78.69.8.25 "crusader-worker/1.0""0.000" "-""Washington" "US"
35.199.30.226 - - [05/Sep/2026:09:25:32 +0200]"GET /.env.prod HTTP/1.1" 404 1456"-" 78.69.8.25 "crusader-worker/1.0""0.000" "-""Washington" "US"
35.199.30.226 - - [05/Sep/2026:09:25:32 +0200]"GET /.env.dev HTTP/1.1" 404 1456"-" 78.69.8.25 "crusader-worker/1.0""0.000" "-""Washington" "US"
...
show less
Hacking
Bad Web Bot
Web App Attack
🇬🇧
thetomtaylor.co.uk
2026-09-04 15:08:00
(1 day ago)
Fail2Ban - [WEB]Custom exploit pattern detected on customexploits ... [ice01,ice02,wa01,wa02]
Hacking
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
MatCat
2026-09-04 15:05:10
(1 day ago)
Banned by fail2ban: apache-webprobe
Port Scan
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-04 14:11:34
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.199.30.226 (226.30.199.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.199.30.226 (226.30.199.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 10:11:27.562389 2026] [security2:error] [pid 10709:tid 10709] [client 35.199.30.226:56118] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.tidarat.com"] [uri "/.env.dev"] [unique_id "aprRj-dbgWZ8N5KLpRpVBAAAAFs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 13:45:19
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.199.30.226 (226.30.199.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.199.30.226 (226.30.199.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 09:45:14.881068 2026] [security2:error] [pid 14630:tid 14630] [client 35.199.30.226:46274] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "activethinkers.net"] [uri "/.env.example"] [unique_id "aprLaghCdnm95JNJfoSmtQAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
MyGlobalFlowers
2026-09-04 13:44:32
(1 day ago)
Multiple WAF Violations
Web App Attack
🇵🇾
armandosaucedo.me
2026-09-04 13:13:38
(1 day ago)
Threat Intelligence via ARMTI, Web Attack: GET /.env
Web App Attack
🇩🇪
webanyone
2026-09-04 13:02:45
(1 day ago)
WAF repeated trigger detected by Fail2Ban in plesk-modsecurity jail
Web App Attack