๐ฟ๐ฆ
conure.sh
2026-09-23 12:13:51
(3 days ago)
csagent: score 20.8: 404 noise floor x3, secrets grab x2; 1 domain(s) in 0s
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-09-22 21:59:45
(4 days ago)
Auto-ban: >3000 req/min op 2026-09-22
Web App Attack
SSH
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-22 17:00:16
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 35.231.11.222 (222.11.231.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.231.11.222 (222.11.231.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 13:00:10.627226 2026] [security2:error] [pid 30167:tid 30167] [client 35.231.11.222:46434] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sekizinci.com"] [uri "/.env.save"] [unique_id "arK0GslRvj7KB-dH4K1DdQAAADc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-09-22 16:15:50
(4 days ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
Anonymous
2026-09-22 15:54:08
(4 days ago)
[osotir.org] httpd-config-scan: sites=www.osotir.org,www.osotir.gr; logs=/var/log/httpd/domains/osot ...
show more
[osotir.org] httpd-config-scan: sites=www.osotir.org,www.osotir.gr; logs=/var/log/httpd/domains/osotir.org.log,/var/log/httpd/domains/osotir.gr.log; samples=/wp-config.php~ | /.env.production | /.env.old
show less
Hacking
Web App Attack
๐ฉ๐ช
ghostwarriors
2026-09-22 15:50:13
(4 days ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack
๐ฉ๐ช
yitzhaq
2026-09-22 15:22:23
(4 days ago)
35.231.11.222 - - [22/Sep/2026:17:22:21 +0200] "GET /wp-config.php~ HTTP/1.1" 404 4437 "-" "crusader ...
show more
35.231.11.222 - - [22/Sep/2026:17:22:21 +0200] "GET /wp-config.php~ HTTP/1.1" 404 4437 "-" "crusader-worker/1.0"
35.231.11.222 - - [22/Sep/2026:17:22:21 +0200] "GET /wp-config.php.bak HTTP/1.1" 404 4436 "-" "crusader-worker/1.0"
35.231.11.222 - - [22/Sep/2026:17:22:21 +0200] "GET /.env.prod HTTP/1.1" 404 4436 "-" "crusader-worker/1.0"
35.231.11.222 - - [22/Sep/2026:17:22:21 +0200] "GET /.env HTTP/1.1" 404 4436 "-" "crusader-worker/1.0"
35.231.11.222 - - [22/Sep/2026:17:22:21 +0200] "GET /wp-config.php.swp HTTP/1.1" 404 4436 "-" "crusader-worker/1.0"
35.231.11.222 - - [22/Sep/2026:17:22:21 +0200] "GET /_ignition/health-check HTTP/1.1" 404 4436 "-" "crusader-worker/1.0"
35.231.11.222 - - [22/Sep/2026:17:22:21 +0200] "GET /.env.bak HTTP/1.1" 404 4436 "-" "crusader-worker/1.0"
35.231.11.222 - - [22/Sep/2026:17:22:21 +0200] "GET /actuator/configprops HTTP/1.1" 404 4437 "-" "crusader-worker/1.0"
35.231.11.222 - - [22/Sep/2026:17:22:21 +0200] "GET /actuator/env HTTP/1.1" 404 4435 "-" "crusade
show less
Web App Attack
Brute-Force
๐บ๐ธ
gumbysoft
2026-09-22 15:22:11
(4 days ago)
Unauthorized web vulnerability scan (/.env, wordpress, etc.)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 15:21:18
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 35.231.11.222 (222.11.231.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.231.11.222 (222.11.231.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 11:21:10.815796 2026] [security2:error] [pid 23228:tid 23228] [client 35.231.11.222:59874] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mrconway.com"] [uri "/.env.local"] [unique_id "arKc5hyhPUAybPOwV5-ERQAAACE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
Saec
2026-09-22 15:17:35
(4 days ago)
Jarvis auto-ban: Honeypot /.env.old via mobil.saec.me [US] ASN:Google LLC
Port Scan
Web App Attack
๐ฒ๐พ
Rizzy
2026-09-22 14:15:27
(4 days ago)
Multiple WAF Violations
Brute-Force
Web App Attack
๐จ๐ญ
Origon
2026-09-22 13:56:24
(4 days ago)
http-sensitive-files - IP: 35.231.11.222 - time="2026-09-22T15:56:24+02:00" level=info msg="(555f66 ...
show more
http-sensitive-files - IP: 35.231.11.222 - time="2026-09-22T15:56:24+02:00" level=info msg="(555f66b4f6a74558bc11e3f93469658es8App0Mcc0TKEeje/crowdsec) crowdsecurity/http-sensitive-files by ip 35.231.11.222 (US/396982) : 4h ban on Ip 35.231.11.222" module=db
show less
Web App Attack
๐ฌ๐ง
consul.to
2026-09-22 13:29:28
(4 days ago)
Web attack/malicious scanning detected
Web App Attack
Anonymous
2026-09-22 13:20:53
(4 days ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-22 12:58:17
(4 days ago)
[ti-22al] Web exploit scanning: 11 suspicious requests detected by fail2ban jail apache-scanner. Exa ...
show more
[ti-22al] Web exploit scanning: 11 suspicious requests detected by fail2ban jail apache-scanner. Example: 35.231.11.222 - - [22/Sep/2026:14:58:10 +0200] "GET /wp-config.php.bak HTTP/1.1" 403 6321 "-" "crusader-worker/1.0"
...
show less
Bad Web Bot
Web App Attack