๐ซ๐ท
polarolouis
2026-08-28 17:46:03
(1 hour ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-08-28 17:26:36
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 35.229.114.155 (155.114.229.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.229.114.155 (155.114.229.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 13:26:30.105668 2026] [security2:error] [pid 3356583:tid 3356742] [client 35.229.114.155:34674] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.agrigrailtech.com.pwrcoupling.com"] [uri "/.env.bak"] [unique_id "apHExqlJEgWrCNqOjYVcIgAAANE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 16:25:08
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.229.114.155 (155.114.229.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.229.114.155 (155.114.229.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 12:25:00.861259 2026] [security2:error] [pid 6267:tid 6275] [client 35.229.114.155:35774] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.californiacosmeticsurgery.aafm.us"] [uri "/.env.old"] [unique_id "apG2XGneo3UW81ajQd6xogAAAQU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ท๐บ
DZBOT
2026-08-28 16:19:29
(2 hours ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
๐บ๐ธ
WizardsToolkit
2026-08-28 16:15:02
(2 hours ago)
attempted to access /storage/logs/laravel.log
Web App Attack
๐ฉ๐ช
raph
2026-08-28 15:53:12
(3 hours ago)
[Wordpress] crawler /wp-admin/*, /wp-content/*, etc.
Bad Web Bot
Web App Attack
๐ฉ๐ช
neckaralb-admin.de
2026-08-28 15:23:50
(3 hours ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 15:04:45
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.229.114.155 (155.114.229.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.229.114.155 (155.114.229.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 11:04:39.618754 2026] [security2:error] [pid 14243:tid 14243] [client 35.229.114.155:55702] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "36quant.com"] [uri "/.env.old"] [unique_id "apGjh82Sg_OeiWjL_NkAvwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
CoreTech srl
2026-08-28 14:33:57
(4 hours ago)
cloudlinux2 fail2ban: 2026-08-28 16:29:12,579 fail2ban.filter [1478]: INFO [plesk-wordpre ...
show more
cloudlinux2 fail2ban: 2026-08-28 16:29:12,579 fail2ban.filter [1478]: INFO [plesk-wordpress] Found 45.132.227.175 - 2026-08-28 16:29:12cloudlinux2 fail2ban: 2026-08-28 16:29:16,931 fail2ban.filter [1478]: INFO [plesk-wordpress] Found 45.132.227.175 - 2026-08-28 16:29:16cloudlinux2 fail2ban: 2026-08-28 16:29:29,132 fail2ban.actions [1478]: NOTICE [plesk-panel] Unban 9.205.104.228cloudlinux2 fail2ban: 2026-08-28 16:30:30,889 fail2ban.filter [1478]: INFO [plesk-modsecurity] Found 35.229.114.155 - 2026-08-28 16:30:30cloudlinux2 fail2ban: 2026-08-28 16:30:30,847 fail2ban.filter [1478]: INFO [plesk-modsecurity] Found 35.229.114.155 - 2026-08-28 16:30:30cloudlinux2 fail2ban: 2026-08-28 16:30:30,907 fail2ban.filter [1478]: INFO [plesk-modsecurity] Found 35.229.114.155 - 2026-08-28 16:30:30cloudlinux2 fail2ban: 2026-08-28 16:30:30,871 fail2ban.filter [1478]: INFO [plesk-modsecurity] Found 35.229.114.155 - 2026-08-28 16:30:30cloudlinux2 fail2ban:
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 14:15:22
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.229.114.155 (155.114.229.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.229.114.155 (155.114.229.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 10:15:14.782848 2026] [security2:error] [pid 3139:tid 3139] [client 35.229.114.155:34602] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.jimrussell2010.russellforcongress.com"] [uri "/.env.bak"] [unique_id "apGX8snyd_7krFVi1_m2gwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-28 14:13:03
(4 hours ago)
Bot / scanning and/or hacking attempts: GET /.env.production HTTP/1.1, GET /wp-config.php.swp HTTP/1 ...
show more
Bot / scanning and/or hacking attempts: GET /.env.production HTTP/1.1, GET /wp-config.php.swp HTTP/1.1, GET /wp-config.php~ HTTP/1.1, GET /.env HTTP/1.1, GET /.env.example HTTP/1.1, GET /.env.prod HTTP/1.1, GET /env HTTP/1.1, GET /.env.local HTTP/1.1, GET /crusader-404-probe HTTP/1.1, GET /_ignition/health-check HTTP/1.1, GET /actuator/env HTTP/1.1, GET /actuator/configprops HTTP/1.1, GET /.env.old HTTP/1.1, GET /storage/logs/laravel.log HTTP/1.1, GET /wp-config.php.bak HTTP/1.1, GET /.env.bak HTTP/1.1, GET /.env.dev HTTP/1.1, GET /.env.save HTTP/1.1
show less
Hacking
Web App Attack
๐ฆ๐บ
aranguren.org
2026-08-28 14:12:09
(4 hours ago)
35.229.114.155 - - [29/Aug/2026:00:12:08 +1000] "GET /actuator/env HTTP/1.1" 404 996 "-" "crusader-w ...
show more
35.229.114.155 - - [29/Aug/2026:00:12:08 +1000] "GET /actuator/env HTTP/1.1" 404 996 "-" "crusader-worker/1.0"
35.229.114.155 - - [29/Aug/2026:00:12:08 +1000] "GET /.env.backup HTTP/1.1" 404 996 "-" "crusader-worker/1.0"
35.229.114.155 - - [29/Aug/2026:00:12:08 +1000] "GET /actuator/configprops HTTP/1.1" 404 996 "-" "crusader-worker/1.0"
35.229.114.155 - - [29/Aug/2026:00:12:08 +1000] "GET /.env.save HTTP/1.1" 404 996 "-" "crusader-worker/1.0"
35.229.114.155 - - [29/Aug/2026:00:12:08 +1000] "GET /wp-config.php.swp HTTP/1.1" 404 996 "-" "crusader-worker/1.0"
35.229.114.155 - - [29/Aug/2026:00:12:08 +1000] "GET /env HTTP/1.1" 404 996 "-" "crusader-worker/1.0"
...
show less
Bad Web Bot
Anonymous
2026-08-28 13:48:58
(5 hours ago)
Detected by CrowdSec: crowdsecurity/http-probing
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-08-28 13:21:15
(5 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-08-28 13:17:44
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.229.114.155 (155.114.229.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.229.114.155 (155.114.229.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 09:17:37.196043 2026] [security2:error] [pid 8270:tid 8270] [client 35.229.114.155:33056] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.929.hongkonger.org"] [uri "/.env.example"] [unique_id "apGKcZZJLIXjCXFdPo1RhgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack