๐ฟ๐ฆ
conure.sh
2026-08-28 12:14:43
(1 hour ago)
csagent: score 20.8: 404 noise floor x3, wp-config backup grab x1, secrets grab x1; 1 domain(s) in 0 ...
show more
csagent: score 20.8: 404 noise floor x3, wp-config backup grab x1, secrets grab x1; 1 domain(s) in 0s
show less
Web App Attack
๐ฌ๐ง
openstrike.co.uk
2026-08-28 05:14:04
(8 hours ago)
13 attacks on env grabbing URLs, PHP URLs:
GET /.env.old HTTP/1.1
GET /wp-config.php~ HTTP/1.1
Hacking
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-08-27 22:00:38
(15 hours ago)
Auto-ban: >3000 req/min op 2026-08-27
Web App Attack
SSH
Hacking
๐ฌ๐ง
Shadymint
2026-08-27 21:24:55
(15 hours ago)
cms login attempt from IP marked as abusive
Web App Attack
๐ท๐บ
lns.bz
2026-08-27 20:53:09
(16 hours ago)
Too many 404 requests [RU.VDS]
Web App Attack
๐ง๐พ
lns.bz
2026-08-27 20:11:59
(17 hours ago)
.env scanning [BY]
Web App Attack
๐ฉ๐ช
ISPLtd
2026-08-27 19:13:16
(18 hours ago)
Aug 27 16:13:15 35.237.53.96 TCP SPT=33750 DPT=80 SYN
Aug 27 16:13:15 35.237.53.96 TCP SPT=33726 DPT ...
show more
Aug 27 16:13:15 35.237.53.96 TCP SPT=33750 DPT=80 SYN
Aug 27 16:13:15 35.237.53.96 TCP SPT=33726 DPT=80 SYN
Aug 27 16:13:15 35.237.53.96 TCP SPT=33732 DPT=80 SYN
Aug 27
...
show less
DDoS Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 18:39:05
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.237.53.96 (96.53.237.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.237.53.96 (96.53.237.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 14:38:56.768505 2026] [security2:error] [pid 31149:tid 31149] [client 35.237.53.96:59234] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "lauranixon.com"] [uri "/.env.local"] [unique_id "apCEQFwU8h8pq7mElgjQbAAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
Gabriel Camargo
2026-08-27 17:03:07
(20 hours ago)
35.237.53.96 - - [27/Aug/2026:12:03:07 -0500] "GET /.env.local HTTP/1.1" 301 178 "-" "crusader-worke ...
show more
35.237.53.96 - - [27/Aug/2026:12:03:07 -0500] "GET /.env.local HTTP/1.1" 301 178 "-" "crusader-worker/1.0"
35.237.53.96 - - [27/Aug/2026:12:03:07 -0500] "GET /.env HTTP/1.1" 301 178 "-" "crusader-worker/1.0"
35.237.53.96 - - [27/Aug/2026:12:03:07 -0500] "GET /.env.production HTTP/1.1" 301 178 "-" "crusader-worker/1.0"
...
show less
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2026-08-27 16:42:14
(20 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.237.53.96 (96.53.237.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.237.53.96 (96.53.237.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 12:42:08.768330 2026] [security2:error] [pid 30058:tid 30058] [client 35.237.53.96:49826] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "feministvoice.blog"] [uri "/.env.save"] [unique_id "apBo4FdNhQp07j0nndZIWAAAACA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
interbiznw.com
2026-08-27 15:42:44
(21 hours ago)
fail2ban-ban
Hacking
Brute-Force
Exploited Host
Web App Attack
๐ฉ๐ช
ger-stg-sifi1
2026-08-27 15:25:05
(21 hours ago)
(wordpress) Failed wordpress login using wp-login.php or xmlrpc.php
Web App Attack
๐ซ๐ท
dynamix
2026-08-27 15:15:54
(21 hours ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 15:06:42
(22 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.237.53.96 (96.53.237.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.237.53.96 (96.53.237.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 11:06:33.609215 2026] [security2:error] [pid 26669:tid 26669] [client 35.237.53.96:36912] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "tarekshohaieb.online"] [uri "/.env.prod"] [unique_id "apBSeYG_tMkw17Tf8BmUpAAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 14:50:18
(22 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.237.53.96 (96.53.237.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.237.53.96 (96.53.237.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 10:50:10.744578 2026] [security2:error] [pid 13996:tid 13996] [client 35.237.53.96:37062] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "nationalenq.com"] [uri "/.env.save"] [unique_id "apBOopIp7PLqf_yOKSWYdgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack