Anonymous
2026-08-30 03:01:08
(2 hours ago)
Bloqueado automaticamente por CrowdSec escenario crowdsecurity/http-sensitive-files
Brute-Force
🇺🇸
natdem.org
2026-08-30 02:46:24
(2 hours ago)
Web: .env file probe, WordPress config probe, Spring actuator probe
Web App Attack
Hacking
🇩🇪
FD-IX
2026-08-30 01:02:37
(4 hours ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
🇫🇷
Catalin Negru
2026-08-30 00:58:28
(4 hours ago)
2026-08-30 03:58:27,372 fail2ban.actions [1796604]: NOTICE [laravel-auth] Ban 35.227.45.89
2 ...
show more
2026-08-30 03:58:27,372 fail2ban.actions [1796604]: NOTICE [laravel-auth] Ban 35.227.45.89
2026-08-30 03:58:27,391 fail2ban.actions [1796604]: NOTICE [apache-scan] Ban 35.227.45.89
2026-08-30 03:58:27,395 fail2ban.actions [1796604]: NOTICE [apache-404] Ban 35.227.45.89
2026-08-30 03:58:27,395 fail2ban.actions [1796604]: NOTICE [web-scanner] Ban 35.227.45.89
2026-08-30 03:58:27,458 fail2ban.actions [1796604]: NOTICE [apache-security] Ban 35.227.45.89
...
show less
Brute-Force
Web App Attack
Anonymous
2026-08-30 00:28:07
(4 hours ago)
(config_exploit_scan) Configuratie Scanner / Nep GPTBot 35.227.45.89 (US/United States/89.45.227.35. ...
show more
(config_exploit_scan) Configuratie Scanner / Nep GPTBot 35.227.45.89 (US/United States/89.45.227.35.bc.googleusercontent.com): 3 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 35.227.45.89 - - [30/Aug/2026:02:28:04 +0200] "GET /.env.example HTTP/1.1" 406 4831 "-" "crusader-worker/1.0"
35.227.45.89 - - [30/Aug/2026:02:28:04 +0200] "GET /.env.backup HTTP/1.1" 406 4832 "-" "crusader-worker/1.0"
35.227.45.89 - - [30/Aug/2026:02:28:04 +0200] "GET /.env.production HTTP/1.1" 406 4831 "-" "crusader-worker/1.0"
show less
Port Scan
🇿🇦
conure.sh
2026-08-29 12:01:38
(17 hours ago)
csagent: score 20.5: secrets grab x2, 404 noise floor x2; 1 domain(s) in 0s
Web App Attack
🇩🇪
tentwentyfour
2026-08-29 02:51:04
(1 day ago)
Blocked for probing for sensitive web application components
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-08-29 01:10:58
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.227.45.89 (89.45.227.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.227.45.89 (89.45.227.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 21:10:53.445514 2026] [security2:error] [pid 30520:tid 30520] [client 35.227.45.89:45532] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "imagesbyaubrey.com"] [uri "/.env"] [unique_id "apIxnWhs3WnRE7AOEuCyzgAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇧🇪
sid3windr
2026-08-29 00:57:14
(1 day ago)
GET /.env (Tarpitted for 4m22s, wasted 15.47kB)
Web App Attack
🇸🇪
vaia.cloud
2026-08-29 00:50:02
(1 day ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
🇩🇪
Marc
2026-08-29 00:49:59
(1 day ago)
35.227.45.89 - - [29/Aug/2026:02:49:59 +0200] "GET /.env.example HTTP/1.1" 404 4617 "-" "crusader-wo ...
show more
35.227.45.89 - - [29/Aug/2026:02:49:59 +0200] "GET /.env.example HTTP/1.1" 404 4617 "-" "crusader-worker/1.0" 35.227.45.89 - - [29/Aug/2026:02:49:59 +0200] "GET /.env.local HTTP/1.1" 404 4616 "-" "crusader-worker/1.0" 35.227.45.89 - - [29/Aug/2026:02:49:59 +0200] "GET /actuator/configprops HTTP/1.1" 404 4617 "-" "crusader-worker/1.0"
show less
Brute-Force
Anonymous
2026-08-29 00:43:13
(1 day ago)
Bot / seems abusive / Apache connections: 24
DDoS Attack
Web Spam
Bad Web Bot
Web App Attack
🇺🇸
mnsf
2026-08-29 00:05:06
(1 day ago)
Abuse Detected (16)
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-08-28 23:37:21
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.227.45.89 (89.45.227.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.227.45.89 (89.45.227.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 19:37:16.930866 2026] [security2:error] [pid 6851:tid 6851] [client 35.227.45.89:35538] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.boulevardflowergardens.com"] [uri "/.env.old"] [unique_id "apIbrOuxeQVRcTQN_UER3AAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-28 23:25:45
(1 day ago)
RdpGuard detected brute-force attempt on HTTP
Brute-Force