🇩🇪
dbmwebdesign
2026-09-15 17:05:14
(1 hour ago)
WAF repeated trigger detected by Fail2Ban in plesk-modsecurity jail
Web App Attack
🇩🇪
big-cloud.nl
2026-09-15 17:00:45
(1 hour ago)
Try to access /.aws/config
Web App Attack
🇩🇪
snhosting
2026-09-15 16:58:12
(1 hour ago)
35.232.197.27 - - [15/Sep/2026:18:58:01 +0200] "GET /.env.js HTTP/2.0" 200 1601 "-" "DuckAssistBot/1 ...
show more
35.232.197.27 - - [15/Sep/2026:18:58:01 +0200] "GET /.env.js HTTP/2.0" 200 1601 "-" "DuckAssistBot/1.1 (https://duckduckgo.com/duckassistbot)"
35.232.197.27 - - [15/Sep/2026:18:58:02 +0200] "GET /.aws/credentials HTTP/2.0" 200 1606 "-" "Mozilla/5.0 (compatible; Qwenbot/1.0; +https://qwen.alibaba.com/)"
35.232.197.27 - - [15/Sep/2026:18:58:02 +0200] "GET /.aws/config HTTP/2.0" 200 1606 "-" "Mozilla/5.0 (compatible; cohere-ai; +https://cohere.com/crawler)"
35.232.197.27 - - [15/Sep/2026:18:58:02 +0200] "GET /.git/config HTTP/2.0" 200 1601 "-" "Mozilla/5.0 (compatible; MistralAI-User/1.0; +https://mistral.ai/)"
35.232.197.27 - - [15/Sep/2026:18:58:02 +0200] "GET /.git/HEAD HTTP/2.0" 200 1601 "-" "Mozilla/5.0 (compatible; KimiBot/1.0; +https://kimi.ai/)"
...
show less
DNS Compromise
DNS Poisoning
Phishing
Email Spam
Brute-Force
Web App Attack
SSH
🇩🇪
neckaralb-admin.de
2026-09-15 16:52:32
(1 hour ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
Anonymous
2026-09-15 16:10:41
(2 hours ago)
35.232.197.27 - - [15/Sep/2026:11:10:34 -0500] "GET /.env.example HTTP/1.1" 301 262 "-" "Mozilla/5.0 ...
show more
35.232.197.27 - - [15/Sep/2026:11:10:34 -0500] "GET /.env.example HTTP/1.1" 301 262 "-" "Mozilla/5.0 (compatible; Google-Extended; +http://www.google.com/bot.html)" 162.158.49.151
35.232.197.27 - - [15/Sep/2026:11:10:34 -0500] "GET /.env.local HTTP/1.1" 301 260 "-" "Mozilla/5.0 (compatible; GrokBot/1.0; +https://x.ai/)" 162.158.49.130
35.232.197.27 - - [15/Sep/2026:11:10:34 -0500] "GET /.env.bak HTTP/1.1" 301 258 "-" "Mozilla/5.0 (compatible; Qwenbot/1.0; +https://qwen.alibaba.com/)" 162.158.49.131
35.232.197.27 - - [15/Sep/2026:11:10:36 -0500] "GET /.env.dev HTTP/1.1" 301 258 "-" "Mozilla/5.0 (compatible; YiBot/1.0; +https://01.ai/)" 162.158.49.150
35.232.197.27 - - [15/Sep/2026:11:10:37 -0500] "GET /.env.docker HTTP/1.1" 301 261 "-" "Mozilla/5.0 (compatible; YiBot/1.0; +https://01.ai/)" 162.158.49.151
35.232.197.27 - - [15/Sep/2026:11:10:37 -0500] "GET /.env.production.bak HTTP/1.1" 301 269 "-" "Mozilla/5.0 (compatible; DeepSeekBot/1.0; +https://www.deepseek.com/)" 162.158.49.150
35.
...
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-15 15:55:20
(2 hours ago)
Web scanner: GET /.git/config
Web App Attack
Hacking
🇨🇭
sternwart
2026-09-15 14:48:38
(3 hours ago)
Automatisch erkannt: Zugriff auf /%2E%2E/%2E%2E/%2E%2E/%2E%2E/.env (absofort.ch)
Web App Attack
Bad Web Bot
🇳🇱
Roderic
2026-09-15 14:48:35
(3 hours ago)
(mod_security) mod_security triggered on hostname [redacted])
SQL Injection
🇩🇪
maxpower
2026-09-15 14:44:34
(3 hours ago)
(junkbot) REGOLA 8 - Junk Bot Blocked 35.232.197.27 (US/United States/27.197.232.35.bc.googleusercon ...
show more
(junkbot) REGOLA 8 - Junk Bot Blocked 35.232.197.27 (US/United States/27.197.232.35.bc.googleusercontent.com): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 35.232.197.27 - - [15/Sep/2026:16:44:32 +0200] "GET /_astro/pages/index.astro.mjs.map HTTP/2.0" 200 4829 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; GPTBot/1.3; +https://openai.com/gptbot)" "35.232.197.27" host=abruzzotour.it
show less
Port Scan
🇺🇸
agenciahypelab.com.br
2026-09-15 14:40:04
(3 hours ago)
WordPress login brute-force detectado e bloqueado pelo CSF/LFD. Trigger: LF_TRIGGER
Brute-Force
SSH
🇳🇴
jad-abuse
2026-09-15 14:19:13
(4 hours ago)
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: aws_creds ...
show more
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: aws_creds, env_probe, path_traversal, git_exposure, source_backup, ssh_keys, credential_file, dotfile_probe. Observed by 1 sensor(s); 453 hits.
show less
Hacking
Web App Attack
🇺🇸
mnsf
2026-09-15 14:05:28
(4 hours ago)
Too many Status 40X (12)
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-15 14:04:34
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.232.197.27 (27.197.232.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.232.197.27 (27.197.232.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 10:04:30.147768 2026] [security2:error] [pid 8655:tid 8655] [client 35.232.197.27:37882] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ablogisticsgroup.com"] [uri "/.env.example"] [unique_id "aqlQbiXTcK1oGDNRMNYUbgAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
kosada.com
2026-09-15 14:01:32
(4 hours ago)
Repeated requests for suspicious nonexistent URLs, for example: /secrets.yml (HTTP/2.0 port 443, use ...
show more
Repeated requests for suspicious nonexistent URLs, for example: /secrets.yml (HTTP/2.0 port 443, user agent: "Mozilla/5.0 (compatible; Kimi-SearchBot/1.0; +https://kimi.ai/)")
show less
Web App Attack
🇬🇧
abivia
2026-09-15 13:58:06
(4 hours ago)
Abivia WAF trigger: Rule scriptKiddies: Credential probing uri: /static/manifest.json
Hacking