๐ฎ๐ณ
evicky2002
2026-08-31 00:01:03
(1 day ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
๐ญ๐บ
DumaNet
2026-08-30 09:37:00
(2 days ago)
Web app attack attempts, scanning for vulnerability.
Date: 2026 Aug 30. 03:29:35
Source IP: 35.236 ...
show more
Web app attack attempts, scanning for vulnerability.
Date: 2026 Aug 30. 03:29:35
Source IP: 35.236.194.68
Portion of the log(s):
35.236.194.68 - [30/Aug/2026:03:29:35 +0200] "GET /storage/logs/laravel.log HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
35.236.194.68 - [30/Aug/2026:03:29:35 +0200] "GET /crusader-404-probe HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
35.236.194.68 - [30/Aug/2026:03:29:35 +0200] "GET /env HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
35.236.194.68 - [30/Aug/2026:03:29:35 +0200] "GET /actuator/env HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
35.236.194.68 - [30/Aug/2026:03:29:35 +0200] "GET /.env.example HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
35.236.194.68 - [30/Aug/2026:03:29:35 +0200] "GET /.env.old HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
35.236.194.68 - [30/Aug/2026:03:29:35 +0200] "GET /.env.prod HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
35.236.194.68 - [30/Aug/2026:03:29:35 +0200] "GET /.env.save HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
show less
Web App Attack
๐ซ๐ท
bazter.pro
2026-08-30 04:11:53
(2 days ago)
Auto-Ban [2026-08-30 07:11:53]: CRITICAL: .env attack; DC: Google LLC [Paths: 19] | Details: Exploit ...
show more
Auto-Ban [2026-08-30 07:11:53]: CRITICAL: .env attack; DC: Google LLC [Paths: 19] | Details: Exploit trap paths: /.env.local, /.env, /.env.production, /.env.prod, /.env.backup | Sensitive files/paths: /.env.local, /.env, /.env.production, /.env.prod, /.env.backup | 404 errors (19): /.env.old, /actuator/configprops, /.env.backup, /storage/logs/laravel.log, /.env.save, /actuator/env, /crusader-404-probe, /.env.bak, /wp-config.php.swp, /wp-config.php~ (and 9 more)
show less
Web App Attack
Hacking
๐ซ๐ท
โจ
2026-08-30 02:07:08
(2 days ago)
Domain : pleskcontrolpanel
Rule : env
2026-08-30 02:05:31 ***hidden-privacy*** GET /.env - 8880 - 35 ...
show more
Domain : pleskcontrolpanel
Rule : env
2026-08-30 02:05:31 ***hidden-privacy*** GET /.env - 8880 - 35.236.194.68 crusader-worker/1.0 - 404 0 2 84 - -
show less
Hacking
SQL Injection
๐ฉ๐ช
kkeyser
2026-08-30 01:41:08
(2 days ago)
GET /.env.prod HTTP/1.1
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-08-29 22:00:34
(3 days ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-08-28.
show less
Web App Attack
SSH
Hacking
๐ญ๐บ
miszterx.hu
2026-08-29 06:09:13
(3 days ago)
XORP (haproxy): 3x HTTP 404/403/500 or handshake failure in 24h. Automated report from log_check_ipt ...
show more
XORP (haproxy): 3x HTTP 404/403/500 or handshake failure in 24h. Automated report from log_check_iptables_generator.sh (xorp.hu)
show less
Web App Attack
๐ฌ๐ง
openstrike.co.uk
2026-08-29 05:13:41
(3 days ago)
13 attacks on PHP URLs, env grabbing URLs:
GET /wp-config.php~ HTTP/1.1
GET /.env.bak HTTP/1.1
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-08-29 03:39:20
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 35.236.194.68 (68.194.236.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.236.194.68 (68.194.236.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 23:39:13.021271 2026] [security2:error] [pid 21170:tid 21170] [client 35.236.194.68:46864] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.swampash.lloydprins.com"] [uri "/.env"] [unique_id "apJUYcCknheOHhSC5qGY3QAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
itsolon
2026-08-29 02:38:14
(3 days ago)
[29/Aug/2026:04:38:10 +0200] 178797109043.323715 35.236.194.68 0 217.154.7.177 443
[29/Aug/2026:04:3 ...
show more
[29/Aug/2026:04:38:10 +0200] 178797109043.323715 35.236.194.68 0 217.154.7.177 443
[29/Aug/2026:04:38:10 +0200] 17879710906.135647 35.236.194.68 0 217.154.7.177 443
[29/Aug/2026:04:38:10 +0200] 178797109061.150705 35.236.194.68 0 217.154.7.177 443
[29/Aug/2026:04:38:10 +0200] 178797109095.878641 35.236.194.68 0 217.154.7.177 443
[29/Aug/2026:04:38:10 +0200] 178797109031.265375 35.236.194.68 0 217.154.7.177 443
...
show less
Port Scan
Hacking
Brute-Force
Web App Attack
๐ฌ๐ง
consul.to
2026-08-29 02:35:43
(3 days ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-29 02:19:05
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 35.236.194.68 (68.194.236.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.236.194.68 (68.194.236.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 22:18:58.733072 2026] [security2:error] [pid 27969:tid 27969] [client 35.236.194.68:52404] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "javierreinoso.com"] [uri "/.env.example"] [unique_id "apJBkoZN04KI-2iwGHvc4wAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
โจ
2026-08-29 01:24:08
(3 days ago)
Domain : MailEnable WebMail
Rule : env
2026-08-29 01:22:51 ***hidden-privacy*** GET /.env.save - 443 ...
show more
Domain : MailEnable WebMail
Rule : env
2026-08-29 01:22:51 ***hidden-privacy*** GET /.env.save - 443 - 35.236.194.68 crusader-worker/1.0 - 404 0 2 1520 107 93 - -
show less
Hacking
SQL Injection
๐ฆ๐บ
2000cn.com.au
2026-08-28 23:57:34
(3 days ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-08-28 23:14:44
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 35.236.194.68 (68.194.236.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.236.194.68 (68.194.236.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 19:14:36.753944 2026] [security2:error] [pid 11863:tid 11863] [client 35.236.194.68:39136] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bocafloorsusa.digitalmarketing-group.com"] [uri "/wp-config.php.bak"] [unique_id "apIWXJWHuQyfy6kI8dQJKAAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack