๐บ๐ธ
wbsouza
2026-08-28 03:32:50
(23 hours ago)
CrowdSec: crowdsecurity/http-sensitive-files โ automated firewall drops on self-hosted IDS sensor
Hacking
๐ฉ๐ช
Stefan Dreher
2026-08-27 22:23:39
(1 day ago)
35.231.235.214 - - [28/Aug/2026:00:23:38 +0200] "GET /.env.local HTTP/1.1" 404 153 "-" "crusader-wor ...
show more
35.231.235.214 - - [28/Aug/2026:00:23:38 +0200] "GET /.env.local HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
35.231.235.214 - - [28/Aug/2026:00:23:38 +0200] "GET /.env HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
35.231.235.214 - - [28/Aug/2026:00:23:38 +0200] "GET /.env.production HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
35.231.235.214 - - [28/Aug/2026:00:23:38 +0200] "GET /.env.save HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
35.231.235.214 - - [28/Aug/2026:00:23:38 +0200] "GET /.env.backup HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
...
show less
Hacking
Brute-Force
๐ณ๐ฑ
homeshowdomain.nl
2026-08-27 22:02:25
(1 day ago)
Auto-ban: >3000 req/min op 2026-08-27
Web App Attack
SSH
Hacking
Anonymous
2026-08-27 21:58:47
(1 day ago)
{"reqId":"zTwbaJWfdMHXAMhrCASi","level":1,"time":"2026-08-27T23:58:46+02:00","remoteAddr":"35.231.23 ...
show more
{"reqId":"zTwbaJWfdMHXAMhrCASi","level":1,"time":"2026-08-27T23:58:46+02:00","remoteAddr":"35.231.235.214","user":"--","app":"core","method":"GET","url":"/actuator/configprops","scriptName":"/index.php","message":"Trusted domain error. \"35.231.235.214\" tried to access using \"82.67.148.87\" as host.","userAgent":"crusader-worker/1.0","version":"34.0.3.2","data":{"app":"core"}}
{"reqId":"Awjt2e8DkXCVpe9TEBkV","level":1,"time":"2026-08-27T23:58:46+02:00","remoteAddr":"35.231.235.214","user":"--","app":"core","method":"GET","url":"/actuator/env","scriptName":"/index.php","message":"Trusted domain error. \"35.231.235.214\" tried to access using \"82.67.148.87\" as host.","userAgent":"crusader-worker/1.0","version":"34.0.3.2","data":{"app":"core"}}
{"reqId":"1DRrSlNKpKTrDpbUYJmS","level":1,"time":"2026-08-27T23:58:46+02:00","remoteAddr":"35.231.235.214","user":"--","app":"core","method":"GET","url":"/env","scriptName":"/index.php","message":"Trusted domain error. \"35.231.235.214\" tried
...
show less
Web App Attack
๐ง๐ท
vfAcceloReporter
2026-08-27 21:09:55
(1 day ago)
35.231.235.214 - - [27/Aug/2026:18:09:54 -0300] "GET /.env.local HTTP/1.1" 404 153 "-" "crusader-wor ...
show more
35.231.235.214 - - [27/Aug/2026:18:09:54 -0300] "GET /.env.local HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
...
show less
Brute-Force
Web App Attack
Exploited Host
๐ฌ๐ง
thetomtaylor.co.uk
2026-08-27 21:06:00
(1 day ago)
Fail2Ban - [WEB]Custom exploit pattern detected on customexploits ... [ice01,wa01,wa02]
Hacking
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
dyln
2026-08-27 20:44:52
(1 day ago)
Dyls honeypot brute-force: proto8 (19 total hits)
Brute-Force
๐ง๐พ
lns.bz
2026-08-27 20:42:35
(1 day ago)
Too many 404 requests [BY]
Web App Attack
๐ฎ๐ช
Jim Keir
2026-08-27 19:38:03
(1 day ago)
2026-08-27 19:38:01 35.231.235.214 File scanning, blocking 35.231.235.214 for 5 minutes
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 19:21:52
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.231.235.214 (214.235.231.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.231.235.214 (214.235.231.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 15:21:46.881759 2026] [security2:error] [pid 29793:tid 29793] [client 35.231.235.214:39044] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "scottcarper.com"] [uri "/.env.dev"] [unique_id "apCOSvmWy_ZJD9PHgr20lAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 18:56:44
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.231.235.214 (214.235.231.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.231.235.214 (214.235.231.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 14:56:36.513482 2026] [security2:error] [pid 4392:tid 4392] [client 35.231.235.214:33340] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "noel-designs.com"] [uri "/.env.prod"] [unique_id "apCIZGqZ07cAmRVUnx1AeQAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-27 17:20:12
(1 day ago)
[news.tmg.gr] httpd-config-scan: sites=www.new.physio-kinisi.gr; logs=/var/log/httpd/domains/new.phy ...
show more
[news.tmg.gr] httpd-config-scan: sites=www.new.physio-kinisi.gr; logs=/var/log/httpd/domains/new.physio-kinisi.gr.log; samples=/wp-config.php~ | /actuator/env | /actuator/configprops
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 17:11:44
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.231.235.214 (214.235.231.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.231.235.214 (214.235.231.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 13:11:37.358110 2026] [security2:error] [pid 14938:tid 14938] [client 35.231.235.214:36816] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "debhill.com"] [uri "/.env.dev"] [unique_id "apBvyfOkc_xP0z0cI85CXwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-27 16:15:01
(1 day ago)
suspicious request in access.log
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-08-27 16:02:57
(1 day ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking