Anonymous
2026-08-28 18:27:43
(12 minutes ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
๐ฉ๐ช
neckaralb-admin.de
2026-08-28 18:25:14
(15 minutes ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
๐ฎ๐ฉ
Burayot
2026-08-28 18:13:56
(26 minutes ago)
LF_MODSEC: (mod_security) mod_security (id:949110) triggered by 35.236.213.216 (US/United States/216 ...
show more
LF_MODSEC: (mod_security) mod_security (id:949110) triggered by 35.236.213.216 (US/United States/216.213.236.35.bc.googleusercontent.com): 1 in the last 3600 secs
show less
Web App Attack
๐บ๐ธ
Rocky Mountain Bioengineering Symposium
2026-08-28 17:45:27
(55 minutes ago)
[Fri Aug 28 11:45:26.504585 2026] [authz_core:error] [pid 1050110:tid 139832500045376] [client 35.23 ...
show more
[Fri Aug 28 11:45:26.504585 2026] [authz_core:error] [pid 1050110:tid 139832500045376] [client 35.236.213.216:39566] AH01630: client denied by server configuration: /var/www/horde/.env.bak
[Fri Aug 28 11:45:26.507645 2026] [authz_core:error] [pid 1050110:tid 139833229948480] [client 35.236.213.216:39558] AH01630: client denied by server configuration: /var/www/horde/wp-config.php~
[Fri Aug 28 11:45:26.520481 2026] [authz_core:error] [pid 1050110:tid 139832600757824] [client 35.236.213.216:39638] AH01630: client denied by server configuration: /var/www/horde/wp-config.php.bak
...
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-08-28 17:40:24
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 35.236.213.216 (216.213.236.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.236.213.216 (216.213.236.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 13:40:21.031557 2026] [security2:error] [pid 17889:tid 17889] [client 35.236.213.216:43628] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.4md.whatifandwhynot.xyz"] [uri "/.env.old"] [unique_id "apHIBQJWGDhK4SJ81N2snwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
paissangroup
2026-08-28 17:04:50
(1 hour ago)
Multiple WAF Violations
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-08-28 16:47:35
(1 hour ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐ฌ๐ง
Apache
2026-08-28 16:43:03
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 35.236.213.216 (US/United States/216.213.236.35 ...
show more
(mod_security) mod_security (id:210492) triggered by 35.236.213.216 (US/United States/216.213.236.35.bc.googleusercontent.com): 5 in the last 300 secs (CF_ENABLE)
show less
Brute-Force
Web App Attack
๐ซ๐ท
GoodOldTOS
2026-08-28 16:39:30
(2 hours ago)
Bad keywords detected in request: /.env
Web App Attack
๐ท๐บ
DZBOT
2026-08-28 16:24:23
(2 hours ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 16:24:12
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.236.213.216 (216.213.236.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.236.213.216 (216.213.236.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 12:24:08.596618 2026] [security2:error] [pid 16244:tid 16244] [client 35.236.213.216:57558] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.herston.org.herston.net"] [uri "/.env.production"] [unique_id "apG2KGFWbRsQLeFOh7xDhwAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-08-28 14:40:35
(3 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-08-28 14:26:16
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.236.213.216 (216.213.236.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.236.213.216 (216.213.236.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 10:26:12.139565 2026] [security2:error] [pid 25856:tid 25856] [client 35.236.213.216:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "demondomain.com"] [uri "/.env.bak"] [unique_id "apGahIC7H6WFrTdqdTubZgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 14:06:26
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.236.213.216 (216.213.236.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.236.213.216 (216.213.236.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 10:06:19.140615 2026] [security2:error] [pid 20744:tid 20744] [client 35.236.213.216:41972] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.hazelzito.com.blazezito.com"] [uri "/wp-config.php.bak"] [unique_id "apGV2zTYbJucdFWobgWS1QAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob
2026-08-28 14:00:58
(4 hours ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /.env.old (+12 more) | 2026-08-28 14:00 UTC
show less
Hacking
Web App Attack