🇺🇸
Lee Daniel
2026-08-28 18:59:09
(3 weeks ago)
35.239.2.178 - - [28/Aug/2026:14:59:08 -0400] "GET /.env HTTP/1.1" 403 6250 "-" "crusader-worker/1.0 ...
show more
35.239.2.178 - - [28/Aug/2026:14:59:08 -0400] "GET /.env HTTP/1.1" 403 6250 "-" "crusader-worker/1.0"
...
show less
DDoS Attack
Web Spam
Email Spam
Port Scan
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-28 13:59:45
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 35.239.2.178 (178.2.239.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.239.2.178 (178.2.239.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 09:59:39.167206 2026] [security2:error] [pid 15973:tid 15973] [client 35.239.2.178:45068] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.angelaboyle.flyingdodopublications.com"] [uri "/wp-config.php.bak"] [unique_id "apGUS-WhN7dc5d1w5VRymgAAAFE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇮
Daniel Baer
2026-08-28 13:35:01
(3 weeks ago)
CrowdSec local HTTP alert
scenario: crowdsecurity/http-sensitive-files
alert_id: 5454
events: 5
crea ...
show more
CrowdSec local HTTP alert
scenario: crowdsecurity/http-sensitive-files
alert_id: 5454
events: 5
created_at: 2026-08-28T13:31:14Z
message: Ip 35.239.2.178 performed 'crowdsecurity/http-sensitive-files' (5 events over 135.707034ms) at 2026-08-28 13:31:13.796551132 +0000 UTC
target_uri: ["/.env.local","/.env.backup","/.env","/.env.dev","/.env.prod"]
method: ["GET"]
status: ["404"]
user_agent: ["crusader-worker/1.0"]
show less
Bad Web Bot
Web App Attack
🇷🇴
clauss
2026-08-28 13:01:45
(3 weeks ago)
35.239.2.178 - - [28/Aug/2026:16:01:44 +0300] "GET /_ignition/health-check HTTP/2.0" 404 33960 "-" " ...
show more
35.239.2.178 - - [28/Aug/2026:16:01:44 +0300] "GET /_ignition/health-check HTTP/2.0" 404 33960 "-" "crusader-worker/1.0"
35.239.2.178 - - [28/Aug/2026:16:01:44 +0300] "GET /actuator/configprops HTTP/2.0" 404 33956 "-" "crusader-worker/1.0"
...
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-08-28 12:04:22
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 35.239.2.178 (178.2.239.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.239.2.178 (178.2.239.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 08:04:14.034400 2026] [security2:error] [pid 1976:tid 1976] [client 35.239.2.178:43172] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.oogeothermal.com.greenlight.us"] [uri "/.env.prod"] [unique_id "apF5PgxghDfKn4BAyUYIjgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
consul.to
2026-08-28 11:59:40
(3 weeks ago)
Web attack/malicious scanning detected
Web App Attack
🇫🇷
Stara
2026-08-28 11:33:43
(3 weeks ago)
ModSecurity detected web attack - .env/config probing or SQLi/Code injection (Rule 949110)
Brute-Force
SSH
Web App Attack
🇩🇪
ger-stg-sifi1
2026-08-28 11:10:02
(3 weeks ago)
(wordpress) Failed wordpress login using wp-login.php or xmlrpc.php
Web App Attack
🇺🇸
TPI-Abuse
2026-08-28 10:21:03
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 35.239.2.178 (178.2.239.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.239.2.178 (178.2.239.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 06:20:56.537057 2026] [security2:error] [pid 32684:tid 32684] [client 35.239.2.178:47574] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "w-c-p-m.com"] [uri "/.env.dev"] [unique_id "apFhCEJE_JNvI1SXz9vjhwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
homeshowdomain.nl
2026-08-27 22:03:44
(3 weeks ago)
Auto-ban: >3000 req/min op 2026-08-27
Web App Attack
SSH
Hacking
🇳🇱
aks4226
2026-08-27 21:44:32
(3 weeks ago)
Bot search, attacking common web applications.
Web App Attack
Anonymous
2026-08-27 21:30:15
(3 weeks ago)
| Suspicious URL access.
Web App Attack
Hacking
SQL Injection
🇺🇸
TPI-Abuse
2026-08-27 18:00:23
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 35.239.2.178 (178.2.239.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.239.2.178 (178.2.239.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 14:00:19.194437 2026] [security2:error] [pid 14083:tid 14083] [client 35.239.2.178:53142] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "seacor.us"] [uri "/.env.bak"] [unique_id "apB7M6ern7RtH8lNQfeHxQAAAC0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
Selckie
2026-08-27 17:56:57
(3 weeks ago)
fail2ban: NGINX unusual impact
Web App Attack
🇺🇸
TPI-Abuse
2026-08-27 17:18:55
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 35.239.2.178 (178.2.239.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.239.2.178 (178.2.239.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 13:18:47.560680 2026] [security2:error] [pid 7630:tid 7630] [client 35.239.2.178:46582] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.jeremyscraig.com"] [uri "/.env.save"] [unique_id "apBxd-zBBBSNihLRf69A-wAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack