🇩🇪
pscriptos
2026-09-06 14:34:53
(4 minutes ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-06 04:47:20
(9 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.241.142.45 (45.142.241.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.241.142.45 (45.142.241.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 00:47:16.431228 2026] [security2:error] [pid 7108:tid 7108] [client 35.241.142.45:47998] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||uptimefleet.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "uptimefleet.com"] [uri "/backup.sql"] [unique_id "apzwVIRmOgI1WwW-mfi32AAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 03:54:17
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.241.142.45 (45.142.241.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.241.142.45 (45.142.241.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 23:54:12.575150 2026] [security2:error] [pid 17094:tid 17094] [client 35.241.142.45:56342] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.mikeneame.com"] [uri "/.env.production"] [unique_id "apzj5BRmsWck5BmzR2G-wgAAADY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
Felisse
2026-09-06 03:38:44
(11 hours ago)
CrowdSec ban: crowdsecurity/http-sensitive-files (duration: 3h57m7s)
Web App Attack
🇵🇱
TaKeN
2026-09-06 03:05:22
(11 hours ago)
Automated Wazuh local observation. Wazuh rule 31151 lvl=10 detected repeated HTTP web application pr ...
show more
Automated Wazuh local observation. Wazuh rule 31151 lvl=10 detected repeated HTTP web application probing from this source IP. Observed 1 matching blocked event(s) between 2026-09-06T05:05:22+02:00 and 2026-09-06T05:05:22+02:00. Sample requested paths: /.env.dev.
show less
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-06 02:58:12
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.241.142.45 (45.142.241.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.241.142.45 (45.142.241.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 22:58:05.775872 2026] [security2:error] [pid 27532:tid 27532] [client 35.241.142.45:37718] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.lahamradio.com"] [uri "/.env.production"] [unique_id "apzWvcIF1BtTVeZfsChBWQAAAEM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
LRob
2026-09-06 02:22:57
(12 hours ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /wp-config.php~ (+12 more) | 2026-09-06 02:22 UTC
show less
Hacking
Web App Attack
🇺🇸
factor1
2026-09-06 02:22:32
(12 hours ago)
CrowdSec at apollo Reports Abuse
Web App Attack
Anonymous
2026-09-06 02:07:08
(12 hours ago)
Automated web scanner. Requested suspicious paths: /.env.save | /.env.local | /.env.bak | /.env.prod ...
show more
Automated web scanner. Requested suspicious paths: /.env.save | /.env.local | /.env.bak | /.env.production | /crusader-404-probe | /.env.example | /.env.old | /actuator/env | /env | /.env | /_ignition/health-check | /.env.dev | /actuator/configprops | /.env.backup | /.env.prod. UTC: 2026-09-06 01:57:31.
show less
Web App Attack
🇺🇸
mcarthey
2026-09-06 02:04:33
(12 hours ago)
Automated honeypot report from mcarthey.com. 4 hits across 2 bait families (actuator-env, dotenv) in ...
show more
Automated honeypot report from mcarthey.com. 4 hits across 2 bait families (actuator-env, dotenv) in the last 24h. Full log: https://mcarthey.com/Shame
show less
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 01:46:43
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.241.142.45 (45.142.241.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.241.142.45 (45.142.241.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 21:46:37.119891 2026] [security2:error] [pid 19944:tid 19944] [client 35.241.142.45:38754] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ftp.alpha-hk.com"] [uri "/.env.save"] [unique_id "apzF_cJUVjHZzfxa1GEchgAAACE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
Savvii
2026-09-06 01:18:32
(13 hours ago)
15 attempts against mh-modsecurity-ban on star
Brute-Force
Web App Attack
🇫🇷
masterguru
2026-09-06 01:11:29
(13 hours ago)
Restricted File Access Attempt. Matched phrase ".env" at REQUEST_FILENAME. (930130-193)
Hacking
Web App Attack
🇫🇮
YF
2026-09-06 01:00:32
(13 hours ago)
WordPress config file probe
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 00:33:31
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.241.142.45 (45.142.241.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.241.142.45 (45.142.241.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 20:33:24.146180 2026] [security2:error] [pid 10445:tid 10445] [client 35.241.142.45:49264] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bastardesign.va-designers.com"] [uri "/.env.local"] [unique_id "apy01HBiTlwkOwSpgfJXQgAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack