๐ฉ๐ช
LRob
2026-09-01 07:38:55
(13 hours ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /.git/config (+1 more) | 2026-09-01 07:38 UTC
show less
Hacking
Web App Attack
๐ณ๐ฑ
Site.eu
2026-09-01 05:18:11
(15 hours ago)
Excessive multi-domain requests
Brute-Force
๐ฉ๐ช
TheDjRider
2026-09-01 04:43:52
(16 hours ago)
CrowdSec detected Web application reconnaissance. Scenario: local/framework-recon. Automatic ban tri ...
show more
CrowdSec detected Web application reconnaissance. Scenario: local/framework-recon. Automatic ban triggered. Detection time (UTC): 2026-09-01T04:43:48.688549758Z. Context: http_status=301
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 03:48:02
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.203.25.19 (19.25.203.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.203.25.19 (19.25.203.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 23:47:58.214671 2026] [security2:error] [pid 27839:tid 27839] [client 35.203.25.19:58958] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.kaleidoscopeglassworks.kaleidoscope-glass.com"] [uri "/.git/config"] [unique_id "apZK7nMrLP9VLz0p3K82kQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 03:32:09
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.203.25.19 (19.25.203.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.203.25.19 (19.25.203.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 23:32:00.591598 2026] [security2:error] [pid 23149:tid 23149] [client 35.203.25.19:44600] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.kaldaragroup.com.greenlight.us"] [uri "/.git/config"] [unique_id "apZHMA4OxjomoRuJg3C7qgAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Octopuce
2026-09-01 03:11:28
(17 hours ago)
Aggressive web search of vulnerable pages: /.env /.env.local /app/.env /apps/.env /api/.env ...
Web App Attack
๐ธ๐ช
vaia.cloud
2026-09-01 02:20:04
(18 hours ago)
crowdsecurity/http-admin-interface-probing
Brute-Force
Web App Attack
๐ฉ๐ช
ghostwarriors
2026-09-01 01:50:16
(19 hours ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack
๐ฉ๐ช
yitzhaq
2026-09-01 01:49:12
(19 hours ago)
35.203.25.19 - - [01/Sep/2026:03:49:08 +0200] "GET /.env.example HTTP/1.1" 404 512 "-" "Mozilla/5.0 ...
show more
35.203.25.19 - - [01/Sep/2026:03:49:08 +0200] "GET /.env.example HTTP/1.1" 404 512 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
35.203.25.19 - - [01/Sep/2026:03:49:08 +0200] "GET /.env.dev HTTP/1.1" 404 512 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
35.203.25.19 - - [01/Sep/2026:03:49:08 +0200] "GET /.env.prod HTTP/1.1" 404 512 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
35.203.25.19 - - [01/Sep/2026:03:49:08 +0200] "GET /.env.stage HTTP/1.1" 404 512 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
35.203.25.19 - - [01/Sep/2026:03:49:08 +0200] "GET /.env.ci HTTP/1.1" 404 512 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
35.203.25
show less
Web App Attack
Hacking
๐ณ๐ฑ
homeshowdomain.nl
2026-08-31 22:01:04
(22 hours ago)
Auto-ban: >3000 req/min op 2026-08-31
Web App Attack
SSH
Hacking
Anonymous
2026-08-31 16:57:41
(1 day ago)
[ns41.kdns.gr] httpd-config-scan: sites=www.koukas-machines.com; logs=/var/log/httpd/domains/koukas- ...
show more
[ns41.kdns.gr] httpd-config-scan: sites=www.koukas-machines.com; logs=/var/log/httpd/domains/koukas-machines.com.log; samples=/.git/config | /.env | /.env.local
show less
Hacking
Web App Attack
๐ฉ๐ช
todix
2026-08-31 15:52:43
(1 day ago)
WebAttack or semilar from 35.203.25.19
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-31 15:40:55
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.203.25.19 (19.25.203.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.203.25.19 (19.25.203.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 11:40:48.794492 2026] [security2:error] [pid 21925:tid 21925] [client 35.203.25.19:53570] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.koshland.koshland.us"] [uri "/.git/config"] [unique_id "apWggPu-aIacn7_ftyA0tAAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-31 15:10:02
(1 day ago)
suspicious request in access.log
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-31 14:20:53
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.203.25.19 (19.25.203.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.203.25.19 (19.25.203.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 10:20:48.754808 2026] [security2:error] [pid 12813:tid 12813] [client 35.203.25.19:42848] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.koreagreenrecycling.com"] [uri "/.git/config"] [unique_id "apWNwE2wqyUt0Fb25kofuQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack