🇳🇱
homeshowdomain.nl
2026-09-04 22:02:20
(27 minutes ago)
Auto-ban: >3000 req/min op 2026-09-04
Web App Attack
SSH
Hacking
Anonymous
2026-09-04 15:20:25
(7 hours ago)
35.204.112.134 - - [04/Sep/2026:15:20:24 +0000] "GET /.env.backup HTTP/1.1" 404 8773 "-" "crusader-w ...
show more
35.204.112.134 - - [04/Sep/2026:15:20:24 +0000] "GET /.env.backup HTTP/1.1" 404 8773 "-" "crusader-worker/1.0"
...
show less
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 15:00:57
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.204.112.134 (134.112.204.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.204.112.134 (134.112.204.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 11:00:53.348500 2026] [security2:error] [pid 28157:tid 28157] [client 35.204.112.134:60832] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "leeknight.com"] [uri "/.env"] [unique_id "aprdJW6rqqOi7rACIZmnCAAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇨🇭
zynex
2026-09-04 14:55:27
(7 hours ago)
URL Probing: /wp-config.php~
Web App Attack
🇩🇪
pscriptos
2026-09-04 14:46:06
(7 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
🇺🇸
Epimetheus
2026-09-04 14:10:05
(8 hours ago)
Unauthorized access attempts:
[GET] /.ENV
[GET] //.env
[GET] /%2eenv
[GET] /.env/
[GET] /.env.
[GET ...
show more
Unauthorized access attempts:
[GET] /.ENV
[GET] //.env
[GET] /%2eenv
[GET] /.env/
[GET] /.env.
[GET] /.env;.png
[GET] /.env.bak
[GET] /wp-config.php.bak
[GET] /.env.dev
[GET] /.env.production
[GET] /storage/logs/laravel.log
[GET] /.env.local
[GET] /wp-config.php~
[GET] /.env.save
[GET] /wp-config.php.swp
[GET] /.env.backup
[GET] /_ignition/health-check
[GET] /.env
[GET] /.env.example
[GET] /env
[GET] /.env.old
[GET] /crusader-404-probe
[GET] /.env.prod
[GET] /actuator/configprops
[GET] /actuator/env
UA: crusader-worker/1.0
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 14:07:07
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.204.112.134 (134.112.204.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.204.112.134 (134.112.204.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 10:07:03.796529 2026] [security2:error] [pid 9692:tid 9692] [client 35.204.112.134:38562] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.garantagroup.com"] [uri "/.env.save"] [unique_id "aprQh4gtb15gCLh5FqnFPQAAAEA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
e.fierstra
2026-09-04 13:50:33
(8 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
🇧🇾
lns.bz
2026-09-04 13:44:55
(8 hours ago)
Too many 404 requests [BY]
Web App Attack
🇳🇱
sernate
2026-09-04 13:29:38
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.204.112.134 (134.112.204.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.204.112.134 (134.112.204.35.bc.googleusercontent.com): 10 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_MODSEC
show less
Brute-Force
🇺🇸
TPI-Abuse
2026-09-04 12:54:58
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.204.112.134 (134.112.204.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.204.112.134 (134.112.204.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 08:54:54.987349 2026] [security2:error] [pid 13656:tid 13656] [client 35.204.112.134:56366] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "marriedtv.com"] [uri "/.env.old"] [unique_id "apq_nnrCsc6OE0dsp7KEGAAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
raph
2026-09-04 12:49:15
(9 hours ago)
[DOT FILES] crawler *.env*, .git*, .config*, etc.
Bad Web Bot
Web App Attack
🇬🇧
consul.to
2026-09-04 12:34:07
(9 hours ago)
Web attack/malicious scanning detected
Web App Attack
🇩🇪
bogdanv
2026-09-04 12:18:18
(10 hours ago)
$f2bV_matches
DDoS Attack
Web Spam
SQL Injection
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
kosada.com
2026-09-04 12:17:25
(10 hours ago)
Repeated exploit attempts, for example: /.env.local /.env (HTTP/1.1 port 443)
Web App Attack