🇳🇱
homeshowdomain.nl
2026-09-06 22:01:04
(1 day ago)
Auto-ban: >3000 req/min op 2026-09-06
Web App Attack
SSH
Hacking
🇺🇸
TPI-Abuse
2026-09-06 02:58:19
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.231.106.244 (244.106.231.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.231.106.244 (244.106.231.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 22:58:14.505686 2026] [security2:error] [pid 3660185:tid 3660185] [client 35.231.106.244:39454] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.loudenlow.com"] [uri "/wp-config.php.bak"] [unique_id "apzWxqm2jrseXbpPg2r8AAAAADk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
Octopuce
2026-09-06 02:56:34
(1 day ago)
Aggressive web search of vulnerable pages: /.env /.env.local /backup.tar.gz /backup.rar /backup.sql ...
show more
Aggressive web search of vulnerable pages: /.env /.env.local /backup.tar.gz /backup.rar /backup.sql /www.zip /admin/phpinfo.php ...
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 02:23:45
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.231.106.244 (244.106.231.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.231.106.244 (244.106.231.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 22:23:39.934101 2026] [security2:error] [pid 18830:tid 18830] [client 35.231.106.244:59598] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "contrarianadvisors.com"] [uri "/.env.local"] [unique_id "apzOq-ntEW2DHCj71ys8fQAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
ghostwarriors
2026-09-06 01:50:03
(1 day ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack
🇩🇪
yitzhaq
2026-09-06 01:32:11
(1 day ago)
35.231.106.244 - - [06/Sep/2026:03:32:08 +0200] "GET /wp-config.php.bak HTTP/1.1" 303 4559 "-" "crus ...
show more
35.231.106.244 - - [06/Sep/2026:03:32:08 +0200] "GET /wp-config.php.bak HTTP/1.1" 303 4559 "-" "crusader-worker/1.0"
35.231.106.244 - - [06/Sep/2026:03:32:08 +0200] "GET /wp-config.php~ HTTP/1.1" 303 4554 "-" "crusader-worker/1.0"
35.231.106.244 - - [06/Sep/2026:03:32:08 +0200] "GET /_ignition/health-check HTTP/1.1" 303 4569 "-" "crusader-worker/1.0"
35.231.106.244 - - [06/Sep/2026:03:32:08 +0200] "GET /.env.example HTTP/1.1" 303 4551 "-" "crusader-worker/1.0"
35.231.106.244 - - [06/Sep/2026:03:32:08 +0200] "GET /.env HTTP/1.1" 303 4534 "-" "crusader-worker/1.0"
35.231.106.244 - - [06/Sep/2026:03:32:08 +0200] "GET /actuator/env HTTP/1.1" 303 4549 "-" "crusader-worker/1.0"
35.231.106.244 - - [06/Sep/2026:03:32:08 +0200] "GET /env HTTP/1.1" 303 4531 "-" "crusader-worker/1.0"
35.231.106.244 - - [06/Sep/2026:03:32:08 +0200] "GET /crusader-404-probe HTTP/1.1" 303 4561 "-" "crusader-worker/1.0"
35.231.106.244 - - [06/Sep/2026:03:32:08 +0200] "GET /.env.bak HTTP/1.1" 303 4543 "-" "crusader-wo
show less
Web App Attack
Brute-Force
🇺🇸
TPI-Abuse
2026-09-06 00:36:16
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.231.106.244 (244.106.231.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.231.106.244 (244.106.231.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 20:36:11.135757 2026] [security2:error] [pid 22070:tid 22070] [client 35.231.106.244:33592] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "hollistercomputer.com"] [uri "/.env.production"] [unique_id "apy1e2vxjIfT5R4hzHlxKAAAAJI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-06 00:09:34
(1 day ago)
Web application attack detected.
Web App Attack
🇮🇳
evicky2002
2026-09-06 00:02:40
(1 day ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
🇨🇭
ca
2026-09-05 23:57:17
(1 day ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
🇳🇱
javierin
2026-09-05 23:09:03
(2 days ago)
35.231.106.244 - regalo-personalizado.javierin.com - - [05/Sep/2026:23:09:02 +0000] "GET /.env.dev H ...
show more
35.231.106.244 - regalo-personalizado.javierin.com - - [05/Sep/2026:23:09:02 +0000] "GET /.env.dev HTTP/1.1" 404 7362 "-" "crusader-worker/1.0"
35.231.106.244 - regalo-personalizado.javierin.com - - [05/Sep/2026:23:09:02 +0000] "GET /.env.production HTTP/1.1" 404 7362 "-" "crusader-worker/1.0"
...
show less
Web App Attack
Hacking
🇬🇧
blik2108
2026-09-05 22:46:52
(2 days ago)
vm20.blacknell.co.uk:443 35.231.106.244 - - [05/Sep/2026:23:46:50 +0100] "GET /_ignition/health-chec ...
show more
vm20.blacknell.co.uk:443 35.231.106.244 - - [05/Sep/2026:23:46:50 +0100] "GET /_ignition/health-check HTTP/1.1" 404 5310 "-" "crusader-worker/1.0"
vm20.blacknell.co.uk:443 35.231.106.244 - - [05/Sep/2026:23:46:50 +0100] "GET /wp-config.php.bak HTTP/1.1" 404 5310 "-" "crusader-worker/1.0"
vm20.blacknell.co.uk:443 35.231.106.244 - - [05/Sep/2026:23:46:50 +0100] "GET /.env.old HTTP/1.1" 404 5310 "-" "crusader-worker/1.0"
vm20.blacknell.co.uk:443 35.231.106.244 - - [05/Sep/2026:23:46:50 +0100] "GET /.env HTTP/1.1" 404 5310 "-" "crusader-worker/1.0"
vm20.blacknell.co.uk:443 35.231.106.244 - - [05/Sep/2026:23:46:50 +0100] "GET /crusader-404-probe HTTP/1.1" 404 5310 "-" "crusader-worker/1.0"
vm20.blacknell.co.uk:443 35.231.106.244 - - [05/Sep/2026:23:46:50 +0100] "GET /actuator/env HTTP/1.1" 404 5310 "-" "crusader-worker/1.0"
vm20.blacknell.co.uk:443 35.231.106.244 - - [05/Sep/2026:23:46:50 +0100] "GET /.env.save HTTP/1.1" 404 5310 "-" "crusader-worker/1.0"
vm20.blacknell.co.uk:443 35.231.106
...
show less
Web App Attack
🇬🇧
consul.to
2026-09-05 22:44:45
(2 days ago)
Web attack/malicious scanning detected
Web App Attack
Anonymous
2026-09-05 21:39:07
(2 days ago)
35.231.106.244 - - [05/Sep/2026:23:39:00 +0200] "GET /actuator/env HTTP/1.1" 404 164 "-" "crusader-w ...
show more
35.231.106.244 - - [05/Sep/2026:23:39:00 +0200] "GET /actuator/env HTTP/1.1" 404 164 "-" "crusader-worker/1.0"
35.231.106.244 - - [05/Sep/2026:23:39:00 +0200] "GET /wp-config.php~ HTTP/1.1" 403 164 "-" "crusader-worker/1.0"
35.231.106.244 - - [05/Sep/2026:23:39:00 +0200] "GET /actuator/configprops HTTP/1.1" 404 164 "-" "crusader-worker/1.0"
35.231.106.244 - - [05/Sep/2026:23:39:00 +0200] "GET /.env.old HTTP/1.1" 403 164 "-" "crusader-worker/1.0"
35.231.106.244 - - [05/Sep/2026:23:39:00 +0200] "GET /.env.dev HTTP/1.1" 403 164 "-" "crusader-worker/1.0"
35.231.106.244 - - [05/Sep/2026:23:39:00 +0200] "GET /.env.example HTTP/1.1" 403 164 "-" "crusader-worker/1.0"
35.231.106.244 - - [05/Sep/2026:23:39:00 +0200] "GET /wp-config.php.swp HTTP/1.1" 403 164 "-" "crusader-worker/1.0"
35.231.106.244 - - [05/Sep/2026:23:39:00 +0200] "GET /wp-config.php.bak HTTP/1.1" 403 164 "-" "crusader-worker/1.0"
35.231.106.244 - - [05/Sep/2026:23:39:00 +0200] "GET /env HTTP/1.1" 404 164 "-" "crusader-worker/1.0
...
show less
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 21:20:14
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 35.231.106.244 (244.106.231.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.231.106.244 (244.106.231.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 17:20:03.718054 2026] [security2:error] [pid 576:tid 576] [client 35.231.106.244:42452] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cageliners.net"] [uri "/.env.backup"] [unique_id "apyHgzqdr4Sc0JvOoH-lNwAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack