🇧🇪
cmbplf
2026-09-06 12:51:30
(8 hours ago)
173 requests with url.path *.sql.gz
Brute-Force
Bad Web Bot
Anonymous
2026-09-06 06:33:24
(15 hours ago)
35.231.248.193 - - [06/Sep/2026:03:33:23 -0300] "GET /wp-config.php.bak HTTP/1.1" 302 138 "-" "crusa ...
show more
35.231.248.193 - - [06/Sep/2026:03:33:23 -0300] "GET /wp-config.php.bak HTTP/1.1" 302 138 "-" "crusader-worker/1.0"
...
show less
Port Scan
Hacking
SQL Injection
Brute-Force
Bad Web Bot
Exploited Host
Anonymous
2026-09-06 03:37:04
(18 hours ago)
Bot / scanning and/or hacking attempts: GET /.env.save HTTP/1.1, GET /wp-config.php~ HTTP/1.1, GET / ...
show more
Bot / scanning and/or hacking attempts: GET /.env.save HTTP/1.1, GET /wp-config.php~ HTTP/1.1, GET /crusader-404-probe HTTP/1.1, GET /storage/logs/laravel.log HTTP/1.1, GET /.env.bak HTTP/1.1
show less
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 03:32:34
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.231.248.193 (193.248.231.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.231.248.193 (193.248.231.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 23:32:30.917910 2026] [security2:error] [pid 15987:tid 15987] [client 35.231.248.193:49884] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "primelb.com"] [uri "/.env.dev"] [unique_id "apzezgj6BzqAufm-rqX84gAAAII"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇷🇴
clauss
2026-09-06 03:26:04
(18 hours ago)
35.231.248.193 - - [06/Sep/2026:06:26:04 +0300] "GET /actuator/configprops HTTP/2.0" 404 201 "-" "cr ...
show more
35.231.248.193 - - [06/Sep/2026:06:26:04 +0300] "GET /actuator/configprops HTTP/2.0" 404 201 "-" "crusader-worker/1.0"
35.231.248.193 - - [06/Sep/2026:06:26:04 +0300] "GET /storage/logs/laravel.log HTTP/2.0" 403 146 "-" "crusader-worker/1.0"
...
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 02:03:10
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.231.248.193 (193.248.231.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.231.248.193 (193.248.231.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 22:03:03.899331 2026] [security2:error] [pid 4806:tid 4806] [client 35.231.248.193:40406] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "markgiffin.com"] [uri "/wp-config.php~"] [unique_id "apzJ1wLZ-KcRjHIygRfwxQAAAEE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 01:10:57
(20 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.231.248.193 (193.248.231.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.231.248.193 (193.248.231.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 21:10:51.298027 2026] [security2:error] [pid 22177:tid 22215] [client 35.231.248.193:42932] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.boraozbek.com"] [uri "/.env.example"] [unique_id "apy9m7FrBBBv6RD6KBcBTQAAAME"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇵🇾
armandosaucedo.me
2026-09-06 00:51:38
(20 hours ago)
Threat Intelligence via ARMTI, Web Attack: GET /dump.sql
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 00:02:34
(21 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.231.248.193 (193.248.231.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.231.248.193 (193.248.231.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 20:02:28.058779 2026] [security2:error] [pid 3505653:tid 3505680] [client 35.231.248.193:46446] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "josephablumphotography.com"] [uri "/.env.prod"] [unique_id "apytlJt-xs6dfcnCXm50lQAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
dbmwebdesign
2026-09-06 00:00:21
(21 hours ago)
WAF repeated trigger detected by Fail2Ban in plesk-modsecurity jail
Web App Attack
🇩🇪
DyhnenTv
2026-09-05 23:54:08
(21 hours ago)
CrowdSec webserver: crowdsecurity/http-sensitive-files
Web App Attack
Bad Web Bot
🇳🇱
cybertailor
2026-09-05 23:48:28
(21 hours ago)
35.231.248.193 - - [06/Sep/2026:04:48:25 +0500] "GET /actuator/configprops HTTP/1.1" 404 146 "-" "cr ...
show more
35.231.248.193 - - [06/Sep/2026:04:48:25 +0500] "GET /actuator/configprops HTTP/1.1" 404 146 "-" "crusader-worker/1.0"
35.231.248.193 - - [06/Sep/2026:04:48:25 +0500] "GET /.env.example HTTP/1.1" 404 146 "-" "crusader-worker/1.0"
35.231.248.193 - - [06/Sep/2026:04:48:25 +0500] "GET /_ignition/health-check HTTP/1.1" 404 146 "-" "crusader-worker/1.0"
35.231.248.193 - - [06/Sep/2026:04:48:25 +0500] "GET /storage/logs/laravel.log HTTP/1.1" 404 146 "-" "crusader-worker/1.0"
35.231.248.193 - - [06/Sep/2026:04:48:25 +0500] "GET /crusader-404-probe HTTP/1.1" 404 146 "-" "crusader-worker/1.0"
...
show less
Port Scan
🇫🇷
dynamix
2026-09-05 23:24:00
(22 hours ago)
Multiple WAF Violations
Web App Attack
🇩🇪
Vegascosmetics
2026-09-05 22:58:30
(22 hours ago)
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after sensitive config/credentials exposure ...
show more
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after sensitive config/credentials exposure probe. Evidence: AttackPattern: /\.env (Match: /.env)
show less
Hacking
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 22:22:37
(23 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.231.248.193 (193.248.231.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.231.248.193 (193.248.231.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 18:22:33.062262 2026] [security2:error] [pid 28651:tid 28651] [client 35.231.248.193:58666] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htaccess" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.eaglesnestfuelfarm.com"] [uri "/.htaccess"] [unique_id "apyWKfzasonKjEVD0eHbTgAAAGA"]
show less
Brute-Force
Bad Web Bot
Web App Attack