๐ฎ๐ณ
evicky2002
2026-08-31 00:01:03
(1 day ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
๐ซ๐ท
geot
2026-08-29 22:12:08
(2 days ago)
GET /.env.prod HTTP/1.1
GET /wp-config.php~ HTTP/1.1
GET /env HTTP/1.1
GET /actuator/env HTTP/1.1
GE ...
show more
GET /.env.prod HTTP/1.1
GET /wp-config.php~ HTTP/1.1
GET /env HTTP/1.1
GET /actuator/env HTTP/1.1
GET /.env.old HTTP/1.1
GET /storage/logs/laravel.log HTTP/1.1
GET /crusader-404-probe HTTP/1.1
GET /.env.production HTTP/1.1
GET /wp-config.php.bak HTTP/1.1
GET /_ignition/health-check HTTP/1.1
GET /.env.bak HTTP/1.1
GET /.env.dev HTTP/1.1
GET /wp-config.php.swp HTTP/1.1
GET /.env HTTP/1.1
GET /.env.example HTTP/1.1
GET /.env.backup HTTP/1.1
GET /.env.local HTTP/1.1
GET /.env.save HTTP/1.1
GET /actuator/configprops HTTP/1.1
show less
Hacking
Bad Web Bot
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-08-29 22:01:16
(2 days ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-08-28.
show less
Web App Attack
SSH
Hacking
Anonymous
2026-08-29 03:26:48
(3 days ago)
35.227.86.252 - - [29/Aug/2026:03:26:46 +0000] "GET /.env.production HTTP/1.1" 302 4921 "-" "crusade ...
show more
35.227.86.252 - - [29/Aug/2026:03:26:46 +0000] "GET /.env.production HTTP/1.1" 302 4921 "-" "crusader-worker/1.0"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
Starburst SysOp Team
2026-08-29 03:07:57
(3 days ago)
Restricted File Access Attempt. Matched phrase ".env" at REQUEST_FILENAME. (930130-stl2-13)
Hacking
Web App Attack
๐ธ๐ช
vaia.cloud
2026-08-29 02:10:02
(3 days ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
๐ซ๐ฎ
as211431.net
2026-08-29 02:06:47
(3 days ago)
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET metho ...
show more
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET method)
Endpoint: /.env.
UA: crusader-worker/1.0
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐บ๐ธ
RLDD
2026-08-29 00:39:02
(3 days ago)
WP probing for vulnerabilities -nov
Web App Attack
๐ฌ๐ง
consul.to
2026-08-29 00:26:12
(3 days ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 22:57:49
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 35.227.86.252 (252.86.227.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.227.86.252 (252.86.227.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 18:57:42.860183 2026] [security2:error] [pid 32531:tid 32531] [client 35.227.86.252:38180] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.ibook.micahgartman.com"] [uri "/.env.save"] [unique_id "apISZmdrxWBUabhIdcUNAwAAADc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
CoreTech srl
2026-08-28 22:53:56
(3 days ago)
cloudlinux2 fail2ban: 2026-08-29 00:49:45,241 fail2ban.filter [1478]: INFO [plesk-modsecu ...
show more
cloudlinux2 fail2ban: 2026-08-29 00:49:45,241 fail2ban.filter [1478]: INFO [plesk-modsecurity] Found 35.227.86.252 - 2026-08-29 00:49:45cloudlinux2 fail2ban: 2026-08-29 00:49:45,278 fail2ban.filter [1478]: INFO [plesk-modsecurity] Found 35.227.86.252 - 2026-08-29 00:49:45cloudlinux2 fail2ban: 2026-08-29 00:49:45,299 fail2ban.filter [1478]: INFO [plesk-modsecurity] Found 35.227.86.252 - 2026-08-29 00:49:45cloudlinux2 fail2ban: 2026-08-29 00:49:45,321 fail2ban.filter [1478]: INFO [plesk-modsecurity] Found 35.227.86.252 - 2026-08-29 00:49:45cloudlinux2 fail2ban: 2026-08-29 00:49:45,329 fail2ban.filter [1478]: INFO [plesk-modsecurity] Found 35.227.86.252 - 2026-08-29 00:49:45cloudlinux2 fail2ban: 2026-08-29 00:49:45,262 fail2ban.filter [1478]: INFO [plesk-modsecurity] Found 35.227.86.252 - 2026-08-29 00:49:45cloudlinux2 fail2ban: 2026-08-29 00:49:45,357 fail2ban.filter [1478]: INFO [plesk-modsecurity] Found 35.227.86.252 - 2026-08-29 00:
show less
Brute-Force
๐ณ๐ฑ
homeshowdomain.nl
2026-08-28 21:59:56
(3 days ago)
Auto-ban: >3000 req/min op 2026-08-28
Web App Attack
SSH
Hacking
๐บ๐ธ
TPI-Abuse
2026-08-28 21:25:17
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 35.227.86.252 (252.86.227.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.227.86.252 (252.86.227.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 17:25:14.959954 2026] [security2:error] [pid 3356584:tid 3356753] [client 35.227.86.252:35894] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.citydentalclinic.oplconnect.com"] [uri "/.env.dev"] [unique_id "apH8ulaK7I3gFT1ABKRiOgAAAQU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 18:54:23
(3 days ago)
(mod_security) mod_security (id:949110) triggered by 35.227.86.252 (252.86.227.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:949110) triggered by 35.227.86.252 (252.86.227.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 14:54:18.244444 2026] [security2:error] [pid 6513:tid 6513] [client 35.227.86.252:52258] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "novintzkiariste.net"] [uri "/.env.prod"] [unique_id "apHZWshcYwz63HkSeJUhuQAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob
2026-08-28 18:33:30
(3 days ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /wp-config.php~ (+12 more) | 2026-08-28 18:33 UTC
show less
Hacking
Web App Attack