๐ธ๐ช
teskedsgumman.se
2026-09-02 07:50:00
(57 minutes ago)
web attack Get/Post requests
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-09-01 22:00:56
(10 hours ago)
Auto-ban: >3000 req/min op 2026-09-01
Web App Attack
SSH
Hacking
Anonymous
2026-09-01 14:07:05
(18 hours ago)
Automated web scanner. Requested suspicious paths: /.env | /.env.dev | /actuator/env | /.env.backup ...
show more
Automated web scanner. Requested suspicious paths: /.env | /.env.dev | /actuator/env | /.env.backup | /.env.example | /_ignition/health-check | /.env.bak | /crusader-404-probe | /storage/logs/laravel.log | /env | /.env.production | /.env.local | /.env.prod | /.env.save | /actuator/configprops | /.env.old. UTC: 2026-09-01 13:54:27.
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 13:51:53
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.220.227.188 (188.227.220.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.220.227.188 (188.227.220.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 09:51:45.059010 2026] [security2:error] [pid 28858:tid 28858] [client 35.220.227.188:46860] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.woodsoninsuranceagency.com"] [uri "/wp-config.php~"] [unique_id "apbYceiDf4ExKUT6mW5OqwAAAEU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
thedreamer.nl
2026-09-01 12:35:12
(20 hours ago)
35.220.227.188 - - [01/Sep/2026:14:33:39 +0200] "GET /wp-config.php~ HTTP/1.1" 499 0 "-" "crusader-w ...
show more
35.220.227.188 - - [01/Sep/2026:14:33:39 +0200] "GET /wp-config.php~ HTTP/1.1" 499 0 "-" "crusader-worker/1.0" "HK" "Hong Kong" "22.28420" "114.17590"
35.220.227.188 - - [01/Sep/2026:14:33:39 +0200] "GET /.env.dev HTTP/1.1" 499 0 "-" "crusader-worker/1.0" "HK" "Hong Kong" "22.28420" "114.17590"
35.220.227.188 - - [01/Sep/2026:14:33:39 +0200] "GET /.env.save HTTP/1.1" 499 0 "-" "crusader-worker/1.0" "HK" "Hong Kong" "22.28420" "114.17590"
35.220.227.188 - - [01/Sep/2026:14:33:39 +0200] "GET /.env.backup HTTP/1.1" 499 0 "-" "crusader-worker/1.0" "HK" "Hong Kong" "22.28420" "114.17590"
...
show less
Hacking
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
NewGastroline
2026-09-01 12:33:43
(20 hours ago)
Malicious request blocked by CrowdSec on gastro-prod1.boreus.de
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-09-01 12:09:16
(20 hours ago)
Restricted File Access Attempt. Matched phrase ".env" at REQUEST_FILENAME. (930130-193)
Hacking
Web App Attack
๐น๐ผ
kk_it_man
2026-09-01 11:13:02
(21 hours ago)
ET INFO Request to Hidden Environment File - Inbound
ET WEB_SERVER Tilde in URI - potential .php~ ...
show more
ET INFO Request to Hidden Environment File - Inbound
ET WEB_SERVER Tilde in URI - potential .php~ source disclosure vulnerability
show less
Port Scan
Anonymous
2026-09-01 11:07:02
(21 hours ago)
Bot / scanning and/or hacking attempts: GET /.env HTTP/1.1, GET /.env.example HTTP/1.1
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 10:57:44
(21 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.220.227.188 (188.227.220.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.220.227.188 (188.227.220.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 06:57:36.807205 2026] [security2:error] [pid 14883:tid 14883] [client 35.220.227.188:33380] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.memelearning.net"] [uri "/.env.prod"] [unique_id "apavoLr-Bfnw_-WeBgdwvgAAAC0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
todix
2026-09-01 10:08:42
(22 hours ago)
Web App Attack Exploid from 35.220.227.188
Web App Attack
๐ฉ๐ช
pscriptos
2026-09-01 09:54:01
(22 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐ซ๐ท
masterguru
2026-09-01 09:48:19
(22 hours ago)
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 35.220.227.188 (HK/Hong Kong/188.227. ...
show more
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 35.220.227.188 (HK/Hong Kong/188.227.220.35.bc.googleusercontent.com): 1 in the last 3600 secs (0-195)
show less
Hacking
Anonymous
2026-09-01 09:33:57
(23 hours ago)
[da.kdns.gr] httpd-config-scan: logs=/var/log/httpd/access_log; samples=/.env.backup | /.env | /.env ...
show more
[da.kdns.gr] httpd-config-scan: logs=/var/log/httpd/access_log; samples=/.env.backup | /.env | /.env.production
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 08:35:37
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.220.227.188 (188.227.220.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.220.227.188 (188.227.220.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 04:35:32.565785 2026] [security2:error] [pid 236589:tid 236625] [client 35.220.227.188:52002] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mailporte.com"] [uri "/.env"] [unique_id "apaOVMfpSwUk1Zhun1l75gAAAUk"]
show less
Brute-Force
Bad Web Bot
Web App Attack