๐ฉ๐ช
FeG Deutschland
2026-08-28 18:21:25
(4 minutes ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
Anonymous
2026-08-28 17:54:04
(32 minutes ago)
Bot / scanning and/or hacking attempts: GET /wp-config.php.bak HTTP/1.1, GET /crusader-404-probe HTT ...
show more
Bot / scanning and/or hacking attempts: GET /wp-config.php.bak HTTP/1.1, GET /crusader-404-probe HTTP/1.1, GET /.env.example HTTP/1.1, GET /.env.dev HTTP/1.1, GET /.env.local HTTP/1.1, GET /_ignition/health-check HTTP/1.1, GET /wp-config.php.swp HTTP/1.1, GET /.env HTTP/1.1, GET /wp-config.php~ HTTP/1.1, GET /.env.old HTTP/1.1, GET /env HTTP/1.1, GET /.env.backup HTTP/1.1, GET /storage/logs/laravel.log HTTP/1.1, GET /actuator/configprops HTTP/1.1, GET /.env.save HTTP/1.1, GET /actuator/env HTTP/1.1, GET /.env.prod HTTP/1.1, GET /.env.production HTTP/1.1, GET /.env.bak HTTP/1.1
show less
Hacking
Web App Attack
๐ท๐บ
DZBOT
2026-08-28 17:49:03
(37 minutes ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
๐บ๐ธ
CBJ
2026-08-28 17:43:18
(42 minutes ago)
fail2ban: apache-filepath-recon
...
Web App Attack
๐ซ๐ท
Feelautom
2026-08-28 16:43:06
(1 hour ago)
[FeelAutom Auto-Ban] PathScan: /actuator/configprops (Score: 204)
Port Scan
Anonymous
2026-08-28 16:05:10
(2 hours ago)
RdpGuard detected brute-force attempt on HTTP
Brute-Force
Anonymous
2026-08-28 15:36:41
(2 hours ago)
[ssd5.kdns.gr] httpd-config-scan: sites=www.dselectrical.gr; logs=/var/log/httpd/domains/dselectrica ...
show more
[ssd5.kdns.gr] httpd-config-scan: sites=www.dselectrical.gr; logs=/var/log/httpd/domains/dselectrical.gr.log; samples=/actuator/env | /.env.save | /.env.production
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 15:17:20
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.237.4.239 (239.4.237.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.237.4.239 (239.4.237.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 11:17:14.046755 2026] [security2:error] [pid 13149:tid 13149] [client 35.237.4.239:33562] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "asiabeef.network"] [uri "/wp-config.php.bak"] [unique_id "apGmeqcDrNB7GQNsNvxuHAAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
Lee Daniel
2026-08-28 14:51:06
(3 hours ago)
35.237.4.239 - - [28/Aug/2026:10:51:06 -0400] "GET /.env HTTP/1.1" 403 6315 "-" "crusader-worker/1.0 ...
show more
35.237.4.239 - - [28/Aug/2026:10:51:06 -0400] "GET /.env HTTP/1.1" 403 6315 "-" "crusader-worker/1.0"
...
show less
DDoS Attack
Web Spam
Email Spam
Port Scan
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 14:49:39
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.237.4.239 (239.4.237.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.237.4.239 (239.4.237.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 10:49:31.626950 2026] [security2:error] [pid 9368:tid 9368] [client 35.237.4.239:50934] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.woodburymeadows.org"] [uri "/wp-config.php~"] [unique_id "apGf-3g3k9ykteC9N_0thgAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 13:36:41
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.237.4.239 (239.4.237.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.237.4.239 (239.4.237.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 09:36:37.801180 2026] [security2:error] [pid 5152:tid 5152] [client 35.237.4.239:58182] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "suffolksystems.com"] [uri "/.env"] [unique_id "apGO5RCosVvIqogiFALsDQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
poundawebsiteltd
2026-08-28 13:18:04
(5 hours ago)
Malicious activity in general-malicious. Evidence: (apache_probe) Failed Access (403/404) 35.237.4.2 ...
show more
Malicious activity in general-malicious. Evidence: (apache_probe) Failed Access (403/404) 35.237.4.239 (US/United States/[REDACTED_DOMAIN]): 20 in the last 3600 secs | UA: (apache_probe) Failed Access (403/404) 35.237.4.239 (US/United States/239.4.237.35.bc.googleusercontent.com): 20 in the last 3600 secs
show less
Brute-Force
Web App Attack
๐ซ๐ท
masterguru
2026-08-28 13:14:47
(5 hours ago)
Restricted File Access Attempt. Matched phrase ".env" at REQUEST_FILENAME. (930130-195)
Hacking
Web App Attack
๐ซ๐ท
dynamix
2026-08-28 13:11:42
(5 hours ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 12:59:03
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.237.4.239 (239.4.237.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.237.4.239 (239.4.237.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 08:58:59.480137 2026] [security2:error] [pid 6095:tid 6095] [client 35.237.4.239:43036] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "vrevgaming.net"] [uri "/wp-config.php.swp"] [unique_id "apGGE3SJc6GhqIEgAo91BAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack