🇺🇸
Starburst SysOp Team
2026-08-30 01:50:52
(6 hours ago)
Restricted File Access Attempt. Matched phrase ".env" at REQUEST_FILENAME. (930130-stl2-14)
Hacking
Web App Attack
🇱🇻
garmtech.com
2026-08-30 00:25:52
(8 hours ago)
Attempted access to sensitive endpoint (/.env.old) detected. Automated scan or unauthorized probing.
Web App Attack
🇺🇸
TPI-Abuse
2026-08-29 03:11:23
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.234.181.160 (160.181.234.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.234.181.160 (160.181.234.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 23:11:14.639637 2026] [security2:error] [pid 5202:tid 5202] [client 35.234.181.160:55054] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "xtrl.com"] [uri "/.env.backup"] [unique_id "apJN0kyhcjmVrmVBv4EkLQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
LRob
2026-08-29 02:54:13
(1 day ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /wp-config.php.swp (+12 more) | 2026-08-29 02:54 UTC
show less
Hacking
Web App Attack
Anonymous
2026-08-29 02:50:04
(1 day ago)
suspicious request in access.log
Web App Attack
🇩🇪
raspi4
2026-08-29 02:14:01
(1 day ago)
Fail2Ban Ban Triggered
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-08-29 01:56:38
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.234.181.160 (160.181.234.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.234.181.160 (160.181.234.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 21:56:31.162671 2026] [security2:error] [pid 28015:tid 28015] [client 35.234.181.160:43326] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "michleen-collins.com"] [uri "/.env.local"] [unique_id "apI8T0FQCyX48SB0v_9HWAAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
WeCloudit-Anti-Abuse
2026-08-29 01:09:41
(1 day ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-08-29 00:38:53
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.234.181.160 (160.181.234.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.234.181.160 (160.181.234.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 20:38:49.338342 2026] [security2:error] [pid 2121:tid 2305] [client 35.234.181.160:44708] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kaukabsiddique.net"] [uri "/.env.bak"] [unique_id "apIqGZQWMZof_yvrvQ0CPgAAAkI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
mnsf
2026-08-29 00:09:00
(1 day ago)
Abuse Detected (18)
Brute-Force
Web App Attack
🇸🇪
vaia.cloud
2026-08-28 23:55:01
(1 day ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
🇫🇷
Baking333
2026-08-28 23:13:25
(1 day ago)
[redacted] 35.234.181.160 - - [29/Aug/2026:00:13:24 +0100] "GET /.[redacted] HTTP/1.1" 302 1538 0/44 ...
show more
[redacted] 35.234.181.160 - - [29/Aug/2026:00:13:24 +0100] "GET /.[redacted] HTTP/1.1" 302 1538 0/44912 "-" "crusader-worker/1.0" [redacted] 35.234.181.160 - - [29/Aug/2026:00:13:24 +0100] "GET /.[redacted] HTTP/1.1" 302 1538 0/73589 "-" "crusader-worker/1.0" [redacted] 35.234.181.160 - - [29/Aug/2026:00:13:24 +0100] "GET /.[redacted] HTTP/1.1" 302 1538 0/95384 "-" "crusader-worker/1.0" [redacted] 35.234.181.160 - - [29/Aug/2026:00:13:24 +0100] "GET /.[redacted] HTTP/1.1" 302 1538 0/102668 "-" "crusader-worker/1.0" [redacted] 35.234.181.160 - - [29/Aug/2026:00:13:24 +0100] "GET /.[redacted] HTTP/1.1" 302 1538 0/99363 "-" "crusader-worker/1.0"
show less
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-28 22:34:48
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.234.181.160 (160.181.234.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.234.181.160 (160.181.234.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 18:34:44.318468 2026] [security2:error] [pid 22718:tid 22718] [client 35.234.181.160:58976] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mcefa.org.general.graphics"] [uri "/.env.production"] [unique_id "apINBCnYJHebkoDsSrjouQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
homeshowdomain.nl
2026-08-28 22:01:23
(1 day ago)
Auto-ban: >3000 req/min op 2026-08-28
Web App Attack
SSH
Hacking
🇺🇸
TPI-Abuse
2026-08-28 21:16:48
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.234.181.160 (160.181.234.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.234.181.160 (160.181.234.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 17:16:42.212404 2026] [security2:error] [pid 9511:tid 9511] [client 35.234.181.160:40922] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.andiamorun.com.bknj2.org"] [uri "/.env.save"] [unique_id "apH6urd5EVm_HQZ-fZA0swAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack