Anonymous
2026-09-05 07:20:09
(12 hours ago)
| Suspicious URL access.
Web App Attack
Hacking
SQL Injection
🇳🇱
homeshowdomain.nl
2026-09-04 22:03:13
(22 hours ago)
Auto-ban: >3000 req/min op 2026-09-04
Web App Attack
SSH
Hacking
🇺🇸
TPI-Abuse
2026-09-04 15:16:09
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.200.61.19 (19.61.200.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.200.61.19 (19.61.200.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 11:16:02.361274 2026] [security2:error] [pid 26458:tid 26458] [client 35.200.61.19:49760] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.farmbureaugallery.com"] [uri "/.env.bak"] [unique_id "aprgsqL5MxFYytEVFTtjlgAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-04 14:45:02
(1 day ago)
suspicious request in access.log
Web App Attack
🇦🇺
2000cn.com.au
2026-09-04 14:16:11
(1 day ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
🇺🇸
Aurealize
2026-09-04 14:11:17
(1 day ago)
Automated Sensitive File discovery attempt detected by a Cloudflare WAF custom rule. Path: /.ENV.
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-04 13:49:32
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.200.61.19 (19.61.200.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.200.61.19 (19.61.200.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 09:49:25.181718 2026] [security2:error] [pid 21393:tid 21393] [client 35.200.61.19:35878] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "affourtit-bowmaker.com"] [uri "/.env.dev"] [unique_id "aprMZasLr5liJv-60JcA7wAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
yitzhaq
2026-09-04 13:32:05
(1 day ago)
35.200.61.19 - - [04/Sep/2026:15:32:02 +0200] "GET /wp-config.php.bak HTTP/1.1" 404 4476 "-" "crusad ...
show more
35.200.61.19 - - [04/Sep/2026:15:32:02 +0200] "GET /wp-config.php.bak HTTP/1.1" 404 4476 "-" "crusader-worker/1.0"
35.200.61.19 - - [04/Sep/2026:15:32:02 +0200] "GET /wp-config.php~ HTTP/1.1" 404 4477 "-" "crusader-worker/1.0"
35.200.61.19 - - [04/Sep/2026:15:32:02 +0200] "GET /actuator/configprops HTTP/1.1" 404 4477 "-" "crusader-worker/1.0"
35.200.61.19 - - [04/Sep/2026:15:32:02 +0200] "GET /storage/logs/laravel.log HTTP/1.1" 404 4477 "-" "crusader-worker/1.0"
35.200.61.19 - - [04/Sep/2026:15:32:02 +0200] "GET /.env HTTP/1.1" 404 4477 "-" "crusader-worker/1.0"
35.200.61.19 - - [04/Sep/2026:15:32:02 +0200] "GET /.env.bak HTTP/1.1" 404 4477 "-" "crusader-worker/1.0"
35.200.61.19 - - [04/Sep/2026:15:32:02 +0200] "GET /.env.backup HTTP/1.1" 404 4477 "-" "crusader-worker/1.0"
35.200.61.19 - - [04/Sep/2026:15:32:02 +0200] "GET /.env.old HTTP/1.1" 404 4477 "-" "crusader-worker/1.0"
35.200.61.19 - - [04/Sep/2026:15:32:02 +0200] "GET /wp-config.php.swp HTTP/1.1" 404 4477 "-" "crusader-worker/
show less
Web App Attack
Brute-Force
Anonymous
2026-09-04 13:30:50
(1 day ago)
[server.tmg.gr] httpd-config-scan: sites=www.sportscardiologycongress.com; logs=/var/log/httpd/domai ...
show more
[server.tmg.gr] httpd-config-scan: sites=www.sportscardiologycongress.com; logs=/var/log/httpd/domains/sportscardiologycongress.com.log; samples=/.env | /.env.old | /actuator/env
show less
Hacking
Web App Attack
🇳🇱
WeCloudit-Anti-Abuse
2026-09-04 13:29:10
(1 day ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-04 12:52:33
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.200.61.19 (19.61.200.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.200.61.19 (19.61.200.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 08:52:28.785266 2026] [security2:error] [pid 11822:tid 11822] [client 35.200.61.19:46050] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "maunakeavista.com"] [uri "/.env"] [unique_id "apq_DA1hHWWvR3sHXExDOgAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 12:29:10
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.200.61.19 (19.61.200.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.200.61.19 (19.61.200.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 08:29:06.386135 2026] [security2:error] [pid 15679:tid 15679] [client 35.200.61.19:35150] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "zeta-me.com"] [uri "/.env"] [unique_id "apq5kjETS-k6pAOqPlZvxAAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
IndigoRidge
2026-09-04 12:19:39
(1 day ago)
[04/Sep/2026:08:19:38.975296 --0400] apq3WiR1Vir2vjiQxG4qPAAAAFY 35.200.61.19 40644 205.233.18.17 70 ...
show more
[04/Sep/2026:08:19:38.975296 --0400] apq3WiR1Vir2vjiQxG4qPAAAAFY 35.200.61.19 40644 205.233.18.17 7081
[04/Sep/2026:08:19:38.977352 --0400] apq3WjnyzNgiHYFVoXzN3wAAABA 35.200.61.19 40646 205.233.18.17 7081
[04/Sep/2026:08:19:38.977525 --0400] apq3WtBb01vGfJ0GVGURUAAAAxM 35.200.61.19 40648 205.233.18.17 7081
[04/Sep/2026:08:19:38.979917 --0400] apq3WtBb01vGfJ0GVGURUgAAAwU 35.200.61.19 40666 205.233.18.17 7081
[04/Sep/2026:08:19:38.982442 --0400] apq3WnRWCNcUXnvBc2IhOAAAAgc 35.200.61.19 40692 205.233.18.17 7081
...
show less
Hacking
🇨🇦
polycoda
2026-09-04 11:49:17
(1 day ago)
AutoBlock: 🎯 Vulnerability Scanner (Non Decay-Based) - ⚙️ Configuration File Access (Non Decay-Based ...
show more
AutoBlock: 🎯 Vulnerability Scanner (Non Decay-Based) - ⚙️ Configuration File Access (Non Decay-Based) - ❌ Excessive 40X Errors (Decay-Based)
show less
Hacking
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 11:46:10
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.200.61.19 (19.61.200.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.200.61.19 (19.61.200.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 07:46:03.436024 2026] [security2:error] [pid 23991:tid 23991] [client 35.200.61.19:37684] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.grampys.toys"] [uri "/.env.bak"] [unique_id "apqve_1gHxiTuSE0DLHYpAAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack