π©πͺ
Phenix Info
2026-08-30 01:56:29
(1 day ago)
SmallGuard.fr/Prestashop Forbidden Ext.
Web App Attack
πΊπΈ
etu brutus
2026-08-30 00:38:20
(1 day ago)
35.243.181.61 Blocked by [Attack Vector List]
...
Hacking
Brute-Force
Exploited Host
πΏπ¦
conure.sh
2026-08-29 12:01:38
(1 day ago)
csagent: score 20.0: secrets grab x2; 1 domain(s) in 0s
Web App Attack
π©πͺ
BlueWire Hosting
2026-08-29 03:08:08
(2 days ago)
High-confidence malicious configuration/VCS probe
Web App Attack
π©πͺ
LRob
2026-08-29 01:50:37
(2 days ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /.env (+12 more) | 2026-08-29 01:50 UTC
show less
Hacking
Web App Attack
Anonymous
2026-08-29 01:14:17
(2 days ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
π©πͺ
SCHAPPY
2026-08-29 01:11:11
(2 days ago)
Malicious activity from IP detected: crowdsecurity/http-sensitive-files.
Web App Attack
Hacking
π·π΄
iulianh
2026-08-29 01:04:54
(2 days ago)
80,443
Brute-Force
SSH
π«π·
masterguru
2026-08-29 00:41:15
(2 days ago)
Attempt to access a backup or working file. Pattern match "\\\\. (920500-193)
Hacking
πΊπΈ
TPI-Abuse
2026-08-29 00:29:12
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 35.243.181.61 (61.181.243.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.243.181.61 (61.181.243.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 20:29:04.810708 2026] [security2:error] [pid 2826:tid 2826] [client 35.243.181.61:36734] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "angelaknightmusic.com"] [uri "/.env.save"] [unique_id "apIn0FYQ_5fP4gKYNkyiFwAAAD4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π«π·
masterguru
2026-08-29 00:00:18
(2 days ago)
URL file extension is restricted by policy. String match within ".ani/ .asa/ .asax/ .ascx/ .back/ .b ...
show more
URL file extension is restricted by policy. String match within ".ani/ .asa/ .asax/ .ascx/ .back/ .backup/ .bak/ .bck/ .bk/ .bkp/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .cnf/ .com/ .compositefont/ .config/ .conf/ .copy/ .crt/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dist/ .dll/ .dos/ .dpkg-dist/ .drv/ .gadget/ .hta/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .inf/ .ini/ .jks/ .jse/ .key/ .licx/ .lnk/ .log/ .mdb/ .msc/ .ocx/ .old/ .pass/ .pdb/ .pfx/ .pif/ .pem/ .pol/ .prf/ .printer/ .pwd/ .rdb/ .rdp/ .reg/ .resources/ .resx/ .sav/ .save/ .scr/ .sct/ .sh/ .shs/ .sql/ .sqlite/ .sqlite3/ .swap/ .swo/ .swp/ .sys/ .temp/ .tfstate/ .tlb/ .tmp/ .vb/ .vbe/ .vbs/ .vbproj/ .vsdisco/ .vxd/ .webinfo/ .ws/ .wsc/ .wsf/ .wsh/ .xsd/ .xsx/" at TX:extension. (920440-197)
show less
Hacking
πΊπΈ
TPI-Abuse
2026-08-28 22:10:11
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 35.243.181.61 (61.181.243.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.243.181.61 (61.181.243.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 18:10:06.582912 2026] [security2:error] [pid 27918:tid 27925] [client 35.243.181.61:60492] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.projekmanagement.aafm.us"] [uri "/.env"] [unique_id "apIHPmp3kbhirv200-xncwAAAMU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
homeshowdomain.nl
2026-08-28 21:59:45
(2 days ago)
Auto-ban: >3000 req/min op 2026-08-28
Web App Attack
SSH
Hacking
πΊπΈ
TPI-Abuse
2026-08-28 21:33:16
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 35.243.181.61 (61.181.243.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.243.181.61 (61.181.243.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 17:33:08.343030 2026] [security2:error] [pid 15345:tid 15345] [client 35.243.181.61:42768] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.towns.bookingsouthafrica.com"] [uri "/.env.prod"] [unique_id "apH-lCR1bZbrahOfiRnrLAAAACc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-28 20:52:36
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 35.243.181.61 (61.181.243.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.243.181.61 (61.181.243.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 16:52:32.591623 2026] [security2:error] [pid 27077:tid 27077] [client 35.243.181.61:42762] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "johnmueller.org"] [uri "/.env"] [unique_id "apH1EFEBWZCxGmicOoSEPAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack