๐ซ๐ท
service Informatique
2026-08-28 04:00:37
(12 minutes ago)
GET /wp-config
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-08-27 22:01:30
(6 hours ago)
Auto-ban: >3000 req/min op 2026-08-27
Web App Attack
SSH
Hacking
๐บ๐ธ
factor1
2026-08-27 19:23:36
(8 hours ago)
CrowdSec at apollo Reports Abuse
Web App Attack
Anonymous
2026-08-27 19:01:09
(9 hours ago)
Banned by Fail2Ban on server
Web App Attack
๐ต๐ซ
www.gregorymariani.com
2026-08-27 18:12:49
(10 hours ago)
35.227.84.202 - - [27/Aug/2026:18:12:48 +0000] "GET /actuator/configprops HTTP/1.1" 404 179 "-" "cru ...
show more
35.227.84.202 - - [27/Aug/2026:18:12:48 +0000] "GET /actuator/configprops HTTP/1.1" 404 179 "-" "crusader-worker/1.0" 415 0.013 [default-shop-oscar-amartyne-8080] [] 10.244.41.147:8080 179 0.013 404 11d9ac1fd8ebe4f4f7ed8cb79d1b82e2
35.227.84.202 - - [27/Aug/2026:18:12:48 +0000] "GET /.env.old HTTP/1.1" 404 179 "-" "crusader-worker/1.0" 403 0.017 [default-shop-oscar-amartyne-8080] [] 10.244.41.147:8080 179 0.016 404 ee2c99d3f5442f75384c49e500d507b3
35.227.84.202 - - [27/Aug/2026:18:12:48 +0000] "GET /.env HTTP/1.1" 404 179 "-" "crusader-worker/1.0" 399 0.025 [default-shop-oscar-amartyne-8080] [] 10.244.41.147:8080 179 0.024 404 d70612fc240f17ed16a862d44e004235
35.227.84.202 - - [27/Aug/2026:18:12:48 +0000] "GET /.env.production HTTP/1.1" 404 179 "-" "crusader-worker/1.0" 410 0.035 [default-shop-oscar-amartyne-8080] [] 10.244.41.147:8080 179 0.035 404 1a6d7f9ea3e55f6de53bb5358a770dbc
35.227.84.202 - - [27/Aug/2026:18:12:48 +0000] "GET /.env.dev HTTP/1.1" 404 179 "-" "crusader-worker/1.0"
...
show less
Web App Attack
๐ฎ๐น
mediarama.com
2026-08-27 17:53:18
(10 hours ago)
Banned by Fail2Ban
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 17:46:51
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.227.84.202 (202.84.227.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.227.84.202 (202.84.227.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 13:46:44.882955 2026] [security2:error] [pid 4955:tid 4955] [client 35.227.84.202:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.caspina.com"] [uri "/.env.production"] [unique_id "apB4BJbh4VZn2n2yRIaGFgAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-27 17:35:16
(10 hours ago)
Failed login attempt detected by Fail2Ban in plesk-modsecurity jail
Exploited Host
๐ง๐ช
voormedia
2026-08-27 17:27:04
(10 hours ago)
Accessed trap at '/actuator/env'
Web App Attack
๐บ๐ธ
Rocky Mountain Bioengineering Symposium
2026-08-27 17:01:49
(11 hours ago)
[Thu Aug 27 11:01:49.432903 2026] [authz_core:error] [pid 1015351:tid 139831116035648] [client 35.22 ...
show more
[Thu Aug 27 11:01:49.432903 2026] [authz_core:error] [pid 1015351:tid 139831116035648] [client 35.227.84.202:46034] AH01630: client denied by server configuration: /var/www/horde/.env.bak
[Thu Aug 27 11:01:49.445102 2026] [authz_core:error] [pid 1015351:tid 139831082464832] [client 35.227.84.202:46168] AH01630: client denied by server configuration: /var/www/horde/wp-config.php.bak
[Thu Aug 27 11:01:49.457244 2026] [authz_core:error] [pid 1015351:tid 139830713316928] [client 35.227.84.202:46070] AH01630: client denied by server configuration: /var/www/horde/wp-config.php~
...
show less
Bad Web Bot
๐ฉ๐ช
bazter.pro
2026-08-27 16:30:58
(11 hours ago)
Fail2Ban: plesk-bot-aggressive - 15 failures
Port Scan
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 16:28:54
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.227.84.202 (202.84.227.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.227.84.202 (202.84.227.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 12:28:46.771168 2026] [security2:error] [pid 23918:tid 23952] [client 35.227.84.202:53190] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.seanmeriwether.com"] [uri "/.env.local"] [unique_id "apBlvoQLw7JqZXPJjViCfAAAAFM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Octopuce
2026-08-27 16:10:42
(12 hours ago)
Aggressive web search of vulnerable pages: /.env.dev /.env.old /.env.bak /.env.local /.env.backup /. ...
show more
Aggressive web search of vulnerable pages: /.env.dev /.env.old /.env.bak /.env.local /.env.backup /.env /.env.save /.env.prod /.env.production ...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 15:44:15
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.227.84.202 (202.84.227.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.227.84.202 (202.84.227.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 11:44:10.701842 2026] [security2:error] [pid 2724393:tid 2724405] [client 35.227.84.202:33858] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.tonysftpfiles.com.pwrcoupling.com"] [uri "/.env.local"] [unique_id "apBbSumHkda15Q5D3BzHTwAAAIo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
Some Body
2026-08-27 15:35:58
(12 hours ago)
Aggressive web scan
Brute-Force
Web App Attack