๐ฆ๐บ
2000cn.com.au
2026-08-27 22:16:22
(5 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐ณ๐ฑ
homeshowdomain.nl
2026-08-27 22:01:05
(5 hours ago)
Auto-ban: >3000 req/min op 2026-08-27
Web App Attack
SSH
Hacking
๐ณ๐ฑ
i-turnradio.nl
2026-08-27 21:46:20
(6 hours ago)
2026-08-27 @ 23:46:20 (CET) ~ Blocked for trying to access: /.env.old
Web App Attack
๐ง๐ท
noconex
2026-08-27 19:44:15
(8 hours ago)
Wazuh Alert | Rule ID: 110100 | Desc: Suricata: Exploit (ET WEB_SERVER Tilde in URI - potential .php ...
show more
Wazuh Alert | Rule ID: 110100 | Desc: Suricata: Exploit (ET WEB_SERVER Tilde in URI - potential .php~ source disclosure vulnerability) 35.220.216.91
show less
Port Scan
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2026-08-27 18:14:40
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.220.216.91 (91.216.220.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.220.216.91 (91.216.220.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 14:14:37.183014 2026] [security2:error] [pid 11564:tid 11564] [client 35.220.216.91:59890] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "zmgmt.com"] [uri "/.env.backup"] [unique_id "apB-jQb6b0Igcx3LeSi2KQAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
SchorelWeb
2026-08-27 17:58:07
(9 hours ago)
Cluster member (Omitted) (FR/France/-) said, TEMPDENY 35.220.216.91, Reason:[(Suspicious02) Suspicio ...
show more
Cluster member (Omitted) (FR/France/-) said, TEMPDENY 35.220.216.91, Reason:[(Suspicious02) Suspicious activity detected 35.220.216.91 (HK/Hong Kong/91.216.220.35.bc.googleusercontent.com): 10 in the last 3600 secs]
show less
Brute-Force
SSH
๐ฉ๐ช
gadix
2026-08-27 16:22:43
(11 hours ago)
[27/Aug/2026:18:22:42.071202 +0200] apBkUt-65245T8t75U2CdwAAAAI 35.220.216.91 57268 127.0.0.1 7081
[ ...
show more
[27/Aug/2026:18:22:42.071202 +0200] apBkUt-65245T8t75U2CdwAAAAI 35.220.216.91 57268 127.0.0.1 7081
[27/Aug/2026:18:22:42.074784 +0200] apBkUiSRgXVsgAjQXNXmzwAAAAU 35.220.216.91 57278 127.0.0.1 7081
[27/Aug/2026:18:22:42.076098 +0200] apBkUvD40ssXtEV3k-9hQwAAAAA 35.220.216.91 57296 127.0.0.1 7081
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 13:47:11
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.220.216.91 (91.216.220.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.220.216.91 (91.216.220.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 09:47:06.175210 2026] [security2:error] [pid 31724:tid 31724] [client 35.220.216.91:42996] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mysticbitchsalon.com"] [uri "/.env.old"] [unique_id "apA_2kH_uxKDoRT63H2yugAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Hazzard
2026-08-27 12:55:05
(14 hours ago)
(mod_security) mod_security triggered on hostname [redacted]): (CF_ENABLE)
SQL Injection
๐ฟ๐ฆ
conure.sh
2026-08-27 12:10:06
(15 hours ago)
csagent: score 21.0: 404 noise floor x4, wp-config backup grab x1, secrets grab x1; 1 domain(s) in 0 ...
show more
csagent: score 21.0: 404 noise floor x4, wp-config backup grab x1, secrets grab x1; 1 domain(s) in 0s
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 11:57:05
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.220.216.91 (91.216.220.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.220.216.91 (91.216.220.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 07:56:56.318683 2026] [security2:error] [pid 17429:tid 17429] [client 35.220.216.91:44504] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "drbolen.com"] [uri "/.env.old"] [unique_id "apAmCDyugzaLC7vgqG_QKQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 10:35:27
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.220.216.91 (91.216.220.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.220.216.91 (91.216.220.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 06:35:22.614370 2026] [security2:error] [pid 20899:tid 20899] [client 35.220.216.91:54254] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "quincysheetmetal.com"] [uri "/.env"] [unique_id "apAS6uhoXppzHzllVrSxLwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Michel Wijnberg
2026-08-27 10:05:53
(17 hours ago)
35.220.216.91 - - [27/Aug/2026:10:05:52 +0000] "GET /storage/logs/laravel.log HTTP/1.1" 444 0 "-" "c ...
show more
35.220.216.91 - - [27/Aug/2026:10:05:52 +0000] "GET /storage/logs/laravel.log HTTP/1.1" 444 0 "-" "crusader-worker/1.0"
...
show less
Bad Web Bot
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-08-27 09:21:10
(18 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 09:01:42
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.220.216.91 (91.216.220.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.220.216.91 (91.216.220.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 05:01:34.038670 2026] [security2:error] [pid 15294:tid 15294] [client 35.220.216.91:43382] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.deltad.net"] [uri "/.env.save"] [unique_id "ao_87s_kqGJI1jKiGLp26QAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack