🇩🇪
big-cloud.nl
2026-09-04 14:41:55
(6 hours ago)
Try to access /.env
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 14:38:27
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.230.165.213 (213.165.230.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.230.165.213 (213.165.230.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 10:38:23.755483 2026] [security2:error] [pid 17541:tid 17541] [client 35.230.165.213:50070] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "deborbon.alessiaalessandra.com"] [uri "/.env.local"] [unique_id "aprX35wcI6kWAPy49UWleAAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 14:05:40
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.230.165.213 (213.165.230.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.230.165.213 (213.165.230.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 10:05:33.216233 2026] [security2:error] [pid 18984:tid 18984] [client 35.230.165.213:60830] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.mskimberleesspace.com"] [uri "/.env"] [unique_id "aprQLZoQHXofSD6-lcfh-wAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
LRob
2026-09-04 14:05:33
(6 hours ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /wp-config.php.bak (+12 more) | 2026-09-04 14:05 UTC
show less
Hacking
Web App Attack
Anonymous
2026-09-04 13:33:28
(7 hours ago)
Web App Attack
Brute-Force
Exploited Host
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 11:17:00
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.230.165.213 (213.165.230.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.230.165.213 (213.165.230.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 07:16:54.102586 2026] [security2:error] [pid 6447:tid 6447] [client 35.230.165.213:51520] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.countylockup.org"] [uri "/wp-config.php.bak"] [unique_id "apqopvVrWl_FHnMpJKfsbwAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇪🇸
loadsoporte
2026-09-04 10:31:29
(10 hours ago)
RdpGuard detected brute-force attempt on HTTP
Brute-Force
🇺🇸
TPI-Abuse
2026-09-04 10:31:04
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.230.165.213 (213.165.230.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.230.165.213 (213.165.230.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 06:30:55.880118 2026] [security2:error] [pid 519866:tid 519866] [client 35.230.165.213:60482] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ic1.ic1.biz"] [uri "/.env.save"] [unique_id "apqd35NSQyFXHMWJQJVBTgAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 10:00:55
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.230.165.213 (213.165.230.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.230.165.213 (213.165.230.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 06:00:48.534389 2026] [security2:error] [pid 13475:tid 13475] [client 35.230.165.213:42128] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.lapapevip.com"] [uri "/.env"] [unique_id "apqW0FW7xwhK7B-dTwOFXQAAAB8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇦🇺
neilwal
2026-09-04 08:55:53
(11 hours ago)
Web Probe (443): teamhummingbird.neilwallace.au:443 35.230.165.213 - - [04/Sep/2026:18:55:53 +1000] ...
show more
Web Probe (443): teamhummingbird.neilwallace.au:443 35.230.165.213 - - [04/Sep/2026:18:55:53 +1000] "GET /.env.backup HTTP/1.1" 401 4770 "-" "crusader-worker/1.0"
teamhummingbird.neilwallace.au:443 35.230.165.213 - - [04/Sep/2026:18:55:53 +1000] "GET /.env.production HTTP/1.1" 401 4771 "-" "crusader-worker/1.0"
teamhummingbird.neilwallace.au:443 35.230.165.213 - - [04/Sep/2026:18:55:53 +1000] "GET /wp-config.php~ HTTP/1.1" 401 4770 "-" "crusader-worker/1.0"
show less
Web App Attack
🇩🇪
wpadm3
2026-09-04 08:39:06
(12 hours ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
🇳🇱
e.fierstra
2026-09-04 08:36:15
(12 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 07:56:42
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.230.165.213 (213.165.230.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.230.165.213 (213.165.230.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 03:56:35.244611 2026] [security2:error] [pid 23560:tid 23560] [client 35.230.165.213:57508] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "inmaine.us"] [uri "/.env.backup"] [unique_id "app5s-3wYBAUjD2gTF85XwAAADo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
WeCloudit-Anti-Abuse
2026-09-04 07:50:17
(12 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
🇺🇸
cybertailor
2026-09-04 07:50:02
(12 hours ago)
35.230.165.213 - - [04/Sep/2026:12:49:59 +0500] "GET /.env HTTP/1.1" 404 146 "-" "crusader-worker/1. ...
show more
35.230.165.213 - - [04/Sep/2026:12:49:59 +0500] "GET /.env HTTP/1.1" 404 146 "-" "crusader-worker/1.0"
35.230.165.213 - - [04/Sep/2026:12:49:59 +0500] "GET /.env.prod HTTP/1.1" 404 146 "-" "crusader-worker/1.0"
35.230.165.213 - - [04/Sep/2026:12:49:59 +0500] "GET /storage/logs/laravel.log HTTP/1.1" 404 146 "-" "crusader-worker/1.0"
35.230.165.213 - - [04/Sep/2026:12:49:59 +0500] "GET /.env.bak HTTP/1.1" 404 146 "-" "crusader-worker/1.0"
35.230.165.213 - - [04/Sep/2026:12:49:59 +0500] "GET /.env.old HTTP/1.1" 404 146 "-" "crusader-worker/1.0"
...
show less
Web App Attack