🇩🇪
srtzero
2026-09-06 06:02:42
(3 hours ago)
35.241.83.208 - - [06/Sep/2026:08:02:42 +0200] "GET /.env.prod HTTP/1.1" 404 3271 "-" "crusader-work ...
show more
35.241.83.208 - - [06/Sep/2026:08:02:42 +0200] "GET /.env.prod HTTP/1.1" 404 3271 "-" "crusader-worker/1.0"
35.241.83.208 - - [06/Sep/2026:08:02:42 +0200] "GET /.env.dev HTTP/1.1" 404 3271 "-" "crusader-worker/1.0"
35.241.83.208 - - [06/Sep/2026:08:02:42 +0200] "GET /.env.bak HTTP/1.1" 404 3271 "-" "crusader-worker/1.0"
...
show less
Port Scan
Bad Web Bot
Web App Attack
🇩🇪
tsZero
2026-09-06 03:39:37
(5 hours ago)
Scan example: path=/.env.old status=404
Hacking
🇺🇸
TPI-Abuse
2026-09-06 03:35:12
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.241.83.208 (208.83.241.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.241.83.208 (208.83.241.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 23:35:06.177506 2026] [security2:error] [pid 1307:tid 1307] [client 35.241.83.208:58530] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "prcomputersolutions.com"] [uri "/.env.save"] [unique_id "apzfaqOjHu_OWGXoeiwICwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
Bedios GmbH
2026-09-06 03:22:40
(5 hours ago)
Login credentials theft attempt
Hacking
🇺🇸
TPI-Abuse
2026-09-06 02:54:01
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.241.83.208 (208.83.241.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.241.83.208 (208.83.241.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 22:53:55.537070 2026] [security2:error] [pid 18987:tid 18987] [client 35.241.83.208:53540] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "personalizedbabynapkins.com"] [uri "/wp-config.php.bak"] [unique_id "apzVw33L_b01hrV-CrrdrQAAAG8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
FeG Deutschland
2026-09-06 02:36:06
(6 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 1247
Exploited Host
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 02:18:40
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.241.83.208 (208.83.241.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.241.83.208 (208.83.241.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 22:18:34.553512 2026] [security2:error] [pid 8319:tid 8319] [client 35.241.83.208:60664] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "testsite.kathrynmcbride.com"] [uri "/.env.save"] [unique_id "apzNehJktmWmnvownn7VHgAAACM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
ger-stg-sifi1
2026-09-06 02:08:51
(6 hours ago)
(wordpress) Failed wordpress login using wp-login.php or xmlrpc.php
Web App Attack
🇳🇱
WeCloudit-Anti-Abuse
2026-09-06 02:02:09
(7 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-06 00:53:28
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.241.83.208 (208.83.241.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.241.83.208 (208.83.241.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 20:53:23.257530 2026] [security2:error] [pid 30447:tid 30447] [client 35.241.83.208:60996] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "esendeniz.net"] [uri "/.env.save"] [unique_id "apy5g1PPs5txAw8C25K7hAAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
Victor López
2026-09-06 00:04:16
(8 hours ago)
jc-alvarez.com 35.241.83.208 - - [05/Sep/2026:19:04:15 -0500] "GET /wp-config.php.bak HTTP/1.1" 404 ...
show more
jc-alvarez.com 35.241.83.208 - - [05/Sep/2026:19:04:15 -0500] "GET /wp-config.php.bak HTTP/1.1" 404 22588 "-" "crusader-worker/1.0" MISS
jc-alvarez.com 35.241.83.208 - - [05/Sep/2026:19:04:15 -0500] "GET /wp-config.php~ HTTP/1.1" 404 22588 "-" "crusader-worker/1.0" MISS
jc-alvarez.com 35.241.83.208 - - [05/Sep/2026:19:04:15 -0500] "GET /wp-config.php.swp HTTP/1.1" 404 22588 "-" "crusader-worker/1.0" MISS
...
show less
Hacking
Web App Attack
🇮🇳
evicky2002
2026-09-06 00:02:40
(9 hours ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
🇫🇷
COMAITE
2026-09-05 23:06:20
(9 hours ago)
Suspicious URL access.
Web App Attack
🇺🇦
URAN Publishing Service
2026-09-05 23:02:44
(10 hours ago)
[06/Sep/2026:02:02:44 +0300] -- 35.241.83.208 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.env ...
show more
[06/Sep/2026:02:02:44 +0300] -- 35.241.83.208 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.env.example HTTP/1.1
show less
Bad Web Bot
Web App Attack
🇬🇧
consul.to
2026-09-05 22:39:16
(10 hours ago)
Web attack/malicious scanning detected
Web App Attack