🇵🇱
sigurg
2026-09-04 07:20:09
(16 minutes ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-04 07:03:37
(32 minutes ago)
(mod_security) mod_security (id:210492) triggered by 35.200.9.114 (114.9.200.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.200.9.114 (114.9.200.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 03:03:32.259893 2026] [security2:error] [pid 14393:tid 14393] [client 35.200.9.114:38550] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "newlifeaccommodation.org"] [uri "/.env.bak"] [unique_id "apptRGq5r4HhL9x9s_OtyAAAAD4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-04 07:00:18
(36 minutes ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-04 06:03:20
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 35.200.9.114 (114.9.200.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.200.9.114 (114.9.200.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 02:03:12.983595 2026] [security2:error] [pid 77466:tid 77466] [client 35.200.9.114:39650] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "raumschach.org"] [uri "/.env.bak"] [unique_id "appfIJGjQqlKcz0dcicCNwAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
consul.to
2026-09-04 06:02:30
(1 hour ago)
Web attack/malicious scanning detected
Web App Attack
🇩🇪
raph
2026-09-04 05:56:58
(1 hour ago)
[DOT FILES] crawler *.env*, .git*, .config*, etc.
Bad Web Bot
Web App Attack
Anonymous
2026-09-04 05:30:03
(2 hours ago)
suspicious request in access.log
Web App Attack
🇳🇱
e.fierstra
2026-09-04 04:44:34
(2 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 04:34:19
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.200.9.114 (114.9.200.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.200.9.114 (114.9.200.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 00:34:16.579790 2026] [security2:error] [pid 2198740:tid 2198805] [client 35.200.9.114:43632] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sattraffic.com"] [uri "/.env.example"] [unique_id "appKSDsF5zHBuNPdRVELeQAAAQk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇸🇪
SkyDancer
2026-09-04 04:24:11
(3 hours ago)
Multiple unauthorized attempts to access using wrong credentials. Attack automatically blocked by Sk ...
show more
Multiple unauthorized attempts to access using wrong credentials. Attack automatically blocked by SkyDancer Ai. EXT-SYS-Vx
show less
Hacking
Brute-Force
SSH
🇺🇸
TPI-Abuse
2026-09-04 04:14:26
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.200.9.114 (114.9.200.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.200.9.114 (114.9.200.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 00:14:21.242924 2026] [security2:error] [pid 977:tid 977] [client 35.200.9.114:59888] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "atimeinhistory.andiamocomputers.com"] [uri "/.env.production"] [unique_id "appFnRmiFcHHZOUU62uEQAAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
macrob
2026-09-04 04:08:41
(3 hours ago)
2026/09/04 04:08:40 [error] 339396#339396: *554300952 access forbidden by rule, client: 35.200.9.114 ...
show more
2026/09/04 04:08:40 [error] 339396#339396: *554300952 access forbidden by rule, client: 35.200.9.114, server: fn.binixo.es, request: "GET /.env.bak HTTP/2.0", host: "host.fastcredit.net.ua"
2026/09/04 04:08:40 [error] 339396#339396: *554300953 access forbidden by rule, client: 35.200.9.114, server: fn.binixo.es, request: "GET /.env.prod HTTP/2.0", host: "host.fastcredit.net.ua"
2026/09/04 04:08:40 [error] 339399#339399: *554300954 access forbidden by rule, client: 35.200.9.114, server: fn.binixo.es, request: "GET /.env.local HTTP/2.0", host: "host.fastcredit.net.ua"
...
show less
Web App Attack
🇫🇷
dynamix
2026-09-04 04:04:51
(3 hours ago)
Multiple WAF Violations
Web App Attack
🇳🇱
WeCloudit-Anti-Abuse
2026-09-04 04:03:26
(3 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
🇮🇹
VHosting
2026-09-04 04:00:06
(3 hours ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack