๐บ๐ธ
TPI-Abuse
2026-09-06 01:33:35
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 35.236.0.36 (36.0.236.35.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 35.236.0.36 (36.0.236.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 21:33:27.385273 2026] [security2:error] [pid 12025:tid 12025] [client 35.236.0.36:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ipv6.kidswithcamerasmovie.com"] [uri "/api/.git/config"] [unique_id "apzC51cMrVi4U4eGBgW3AAAAACw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-06 00:29:14
(1 month ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐ง๐ช
sid3windr
2026-09-05 13:59:19
(1 month ago)
GET /.env (Tarpitted for , wasted 120B)
Web App Attack
๐บ๐ธ
aks4226
2026-09-05 07:07:27
(1 month ago)
Bot search, attacking common web applications.
Web App Attack
๐บ๐ธ
natdem.org
2026-09-05 06:47:21
(1 month ago)
Web: .env file probe, WordPress config probe, Spring actuator probe
Web App Attack
Hacking
๐ณ๐ฑ
homeshowdomain.nl
2026-09-04 21:59:15
(1 month ago)
Auto-ban: >3000 req/min op 2026-09-04
Web App Attack
SSH
Hacking
๐บ๐ธ
mhemart
2026-09-04 14:45:45
(1 month ago)
Automated web application attack detected. Last URL: /.ENV. Attempts: 6.
Web App Attack
๐ง๐ท
dominioz
2026-09-04 14:09:50
(1 month ago)
2026-09-04 14:09:31 GET /.env.bak - - 35.236.0.36 HTTP/1.1 crusader-worker/1.0 - 404 245
2026-09-04 ...
show more
2026-09-04 14:09:31 GET /.env.bak - - 35.236.0.36 HTTP/1.1 crusader-worker/1.0 - 404 245
2026-09-04 14:09:31 GET /.env.old - - 35.236.0.36 HTTP/1.1 crusader-worker/1.0 - 404 245
2026-09-04 14:09:31 GET /wp-config.php.bak - - 35.236.0.36 HTTP/1.1 crusader-worker/1.0 - 404 245
2026-09-04 14:09:31 GET /.env - - 35.236.0.36 HTTP/1.1 crusader-worker/1.0 - 301 494
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-04 14:09:11
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 35.236.0.36 (36.0.236.35.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 35.236.0.36 (36.0.236.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 10:09:04.936147 2026] [security2:error] [pid 21321:tid 21321] [client 35.236.0.36:39798] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.firebelly.org"] [uri "/.env"] [unique_id "aprRAERUWRLQA2UTrGwBfAAAADc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-04 13:19:33
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 35.236.0.36 (36.0.236.35.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 35.236.0.36 (36.0.236.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 09:19:28.278480 2026] [security2:error] [pid 26603:tid 26603] [client 35.236.0.36:51142] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "steamboatrowena.virginiabeachlovebird.com"] [uri "/wp-config.php.swp"] [unique_id "aprFYLjvNiV6_f20ordo8AAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
debestelapp
2026-09-04 12:40:11
(1 month ago)
Web App Attack
Anonymous
2026-09-04 12:38:26
(1 month ago)
2026/09/04 14:38:26 [error] 358977#358977: *62284 access forbidden by rule, client: 35.236.0.36, ser ...
show more
2026/09/04 14:38:26 [error] 358977#358977: *62284 access forbidden by rule, client: 35.236.0.36, server: sahpa.co.za, request: "GET /.env.production HTTP/1.1", host: "sahpa.co.za"
2026/09/04 14:38:26 [error] 358976#358976: *62287 access forbidden by rule, client: 35.236.0.36, server: sahpa.co.za, request: "GET /.env.old HTTP/1.1", host: "sahpa.co.za"
2026/09/04 14:38:26 [error] 358976#358976: *62288 access forbidden by rule, client: 35.236.0.36, server: sahpa.co.za, request: "GET /.env.bak HTTP/1.1", host: "sahpa.co.za"
...
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-04 12:32:40
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 35.236.0.36 (36.0.236.35.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 35.236.0.36 (36.0.236.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 08:32:35.847601 2026] [security2:error] [pid 1327:tid 1327] [client 35.236.0.36:56384] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ftp.portcitybluessociety.com"] [uri "/wp-config.php~"] [unique_id "apq6Y-DTPUIAUaSffg-gCAAAACU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Jager
2026-09-04 12:09:55
(1 month ago)
Blocked by CrowdSec on my OVH VPS for scenario: crowdsecurity/http-sensitive-files
Brute-Force
Port Scan
Web App Attack
Anonymous
2026-09-04 11:24:38
(1 month ago)
[ssd5.kdns.gr] httpd-config-scan: sites=www.energy.inoxal.gr; logs=/var/log/httpd/domains/inoxal.gr. ...
show more
[ssd5.kdns.gr] httpd-config-scan: sites=www.energy.inoxal.gr; logs=/var/log/httpd/domains/inoxal.gr.energy.log; samples=/.env.production | /.env.example | /wp-config.php~
show less
Hacking
Web App Attack