🇮🇪
AutosOnShow
2026-09-06 06:04:06
(12 hours ago)
blocked for webapp attack | path requested: / | seen at 2026-09-06 06:03:39.538 |
Web App Attack
🇭🇺
DumaNet
2026-09-06 04:55:00
(13 hours ago)
Web app attack attempts, scanning for vulnerability.
Date: 2026 Sep 05. 23:18:05
Source IP: 35.233 ...
show more
Web app attack attempts, scanning for vulnerability.
Date: 2026 Sep 05. 23:18:05
Source IP: 35.233.45.153
Portion of the log(s):
35.233.45.153 - [05/Sep/2026:23:18:05 +0200] "GET /.env.backup HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
35.233.45.153 - [05/Sep/2026:23:18:05 +0200] "GET /storage/logs/laravel.log HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
35.233.45.153 - [05/Sep/2026:23:18:05 +0200] "GET /.env.example HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
35.233.45.153 - [05/Sep/2026:23:18:05 +0200] "GET /.env.production HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
35.233.45.153 - [05/Sep/2026:23:18:05 +0200] "GET /wp-config.php~ HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
35.233.45.153 - [05/Sep/2026:23:18:05 +0200] "GET /.env.dev HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
35.233.45.153 - [05/Sep/2026:23:18:05 +0200] "GET /.env.old HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
35.233.45.153 - [05/Sep/2026:23:18:05 +0200] "GET /.env.save HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 03:50:30
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.233.45.153 (153.45.233.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.233.45.153 (153.45.233.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 23:50:23.182882 2026] [security2:error] [pid 10351:tid 10351] [client 35.233.45.153:44710] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.crep-psych.org"] [uri "/.env.prod"] [unique_id "apzi_6ccRB7Ocam3UYsEBQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
LRob
2026-09-06 02:46:21
(15 hours ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /.env.save (+12 more) | 2026-09-06 02:46 UTC
show less
Hacking
Web App Attack
🇩🇪
FeG Deutschland
2026-09-06 02:41:03
(16 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 01:57:28
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.233.45.153 (153.45.233.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.233.45.153 (153.45.233.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 21:57:23.111095 2026] [security2:error] [pid 4569:tid 4569] [client 35.233.45.153:36956] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "math1on1.net"] [uri "/wp-config.php.swp"] [unique_id "apzIg99Xckp5zuhf45s5tQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇵🇱
Budyn
2026-09-06 01:45:06
(16 hours ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scan ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scanner. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: goblinpot.tech | URI: /actuator/env | UA: crusader-worker/1.0 | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
🇫🇮
YF
2026-09-06 00:31:24
(18 hours ago)
WordPress config file probe
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 00:19:18
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.233.45.153 (153.45.233.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.233.45.153 (153.45.233.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 20:19:12.177551 2026] [security2:error] [pid 32321:tid 32321] [client 35.233.45.153:54272] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "answeringamerica.net.hellomdinc.com"] [uri "/.env.backup"] [unique_id "apyxgI8Wp9KzLXTTVoFqRgAAADA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
e.fierstra
2026-09-06 00:13:59
(18 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
🇦🇺
paulshipley.com.au
2026-09-06 00:04:57
(18 hours ago)
[Sun Sep 06 10:04:56.709572 2026] [security2:error] [pid 855154] [client 35.233.45.153:59816] [clien ...
show more
[Sun Sep 06 10:04:56.709572 2026] [security2:error] [pid 855154] [client 35.233.45.153:59816] [client 35.233.45.153] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/modsecurity/crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "paulshipley.com.au"] [uri "/wp-config.php.swp"] [unique_id "apyuKK0oWfvdDEFGn5WrPQAAAAE"]
...
show less
Web App Attack
🇩🇪
raph
2026-09-06 00:04:40
(18 hours ago)
[DOT FILES] crawler *.env*, .git*, .config*, etc.
Bad Web Bot
Web App Attack
🇺🇸
antlac1
2026-09-05 23:58:11
(18 hours ago)
crowdsecurity/http-probing
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 23:58:03
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.233.45.153 (153.45.233.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.233.45.153 (153.45.233.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 19:57:58.396558 2026] [security2:error] [pid 8911:tid 8911] [client 35.233.45.153:41858] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.clustershow.com"] [uri "/.env"] [unique_id "apyshtpYuSMGmKEVq48yogAAACA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
SysAdmin Dylan
2026-09-05 23:00:30
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.233.45.153 (BE/Belgium/153.45.233.35.bc.goog ...
show more
(mod_security) mod_security (id:210492) triggered by 35.233.45.153 (BE/Belgium/153.45.233.35.bc.googleusercontent.com): 10 in the last 3600 secs
show less
Brute-Force