๐บ๐ธ
VanKoh
2026-08-27 20:45:01
(36 minutes ago)
35.202.173.141 - - [27/Aug/2026:14:45:00 -0600] "GET /.env HTTP/1.1" 404 58296 "-" "crusader-worker/ ...
show more
35.202.173.141 - - [27/Aug/2026:14:45:00 -0600] "GET /.env HTTP/1.1" 404 58296 "-" "crusader-worker/1.0"
35.202.173.141 - - [27/Aug/2026:14:45:00 -0600] "GET /.env.save HTTP/1.1" 404 58296 "-" "crusader-worker/1.0"
35.202.173.141 - - [27/Aug/2026:14:45:00 -0600] "GET /.env.backup HTTP/1.1" 404 58296 "-" "crusader-worker/1.0"
...
show less
Port Scan
Web App Attack
๐ฉ๐ช
XICTRON
2026-08-27 19:55:05
(1 hour ago)
ModSecurity rule violation detected by Fail2Ban
Web App Attack
๐ฉ๐ช
todix
2026-08-27 18:57:38
(2 hours ago)
Web App Attack Exploid from 35.202.173.141
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-08-27 18:46:46
(2 hours ago)
[27/Aug/2026:21:46:45 +0300] -- 35.202.173.141 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET ...
show more
[27/Aug/2026:21:46:45 +0300] -- 35.202.173.141 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET /storage/logs/laravel.log HTTP/1.1
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
4server
2026-08-27 18:11:40
(3 hours ago)
[ThuAug2720:11:37.9908242026][security2:error][pid1529867:tid1529968][client35.202.173.141:0]ModSecu ...
show more
[ThuAug2720:11:37.9908242026][security2:error][pid1529867:tid1529968][client35.202.173.141:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:5\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.10\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"mail.buletti-panettoni.ch\"][uri\"/.env.local\"][unique_id\"apB92S9pfNuE33lageBGygAAAg0\"]
show less
Port Scan
Brute-Force
Web App Attack
๐ฆ๐บ
A.i.D.A.N.N
2026-08-27 17:48:46
(3 hours ago)
A.i.D.A.N.N ML: Anomaly Detected - Signature match Web Service - Web application attack detected
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 17:46:50
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.202.173.141 (141.173.202.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.202.173.141 (141.173.202.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 13:46:42.498711 2026] [security2:error] [pid 6140:tid 6140] [client 35.202.173.141:50876] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "spicymilk.com"] [uri "/wp-config.php.swp"] [unique_id "apB4AnWLkRMgU3kH00H9pgAAACM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 16:55:38
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.202.173.141 (141.173.202.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.202.173.141 (141.173.202.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 12:55:32.629507 2026] [security2:error] [pid 1378:tid 1378] [client 35.202.173.141:55524] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.raritymountainadventures.com.savingshvac.com"] [uri "/.env.example"] [unique_id "apBsBPpHeXPCvtX_iX53hwAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 16:29:52
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.202.173.141 (141.173.202.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.202.173.141 (141.173.202.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 12:29:47.514349 2026] [security2:error] [pid 7043:tid 7043] [client 35.202.173.141:52654] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "brooklynmeeting.org"] [uri "/wp-config.php.bak"] [unique_id "apBl-6tmjFsngNm-HIQSUgAAACI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Webhoster
2026-08-27 16:09:59
(5 hours ago)
CrowdSec scenario: crowdsecurity/http-sensitive-files
Hacking
๐ซ๐ท
dynamix
2026-08-27 15:54:03
(5 hours ago)
Multiple WAF Violations
Web App Attack
๐ฉ๐ช
Dominik Lysiak
2026-08-27 15:46:07
(5 hours ago)
35.202.173.141 - - [27/Aug/2026:17:46:06 +0200] "GET /.env.bak HTTP/1.1" 444 0 "-" "crusader-worker/ ...
show more
35.202.173.141 - - [27/Aug/2026:17:46:06 +0200] "GET /.env.bak HTTP/1.1" 444 0 "-" "crusader-worker/1.0"
35.202.173.141 - - [27/Aug/2026:17:46:06 +0200] "GET /.env.production HTTP/1.1" 444 0 "-" "crusader-worker/1.0"
35.202.173.141 - - [27/Aug/2026:17:46:06 +0200] "GET /wp-config.php.swp HTTP/1.1" 444 0 "-" "crusader-worker/1.0"
...
show less
Web App Attack
๐ณ๐ฑ
MyGlobalFlowers
2026-08-27 15:39:07
(5 hours ago)
Multiple WAF Violations
Web App Attack
๐ฉ๐ช
BlueWire Hosting
2026-08-27 15:25:09
(5 hours ago)
High-confidence malicious configuration/VCS probe
Web App Attack
๐ฉ๐ช
DyhnenTv
2026-08-27 14:43:07
(6 hours ago)
CrowdSec webserver: crowdsecurity/http-probing
Web App Attack
Bad Web Bot