🇭🇺
miszterx.hu
2026-08-29 06:09:21
(1 week ago)
XORP (haproxy): 19x HTTP 404/403/500 or handshake failure in 24h. Automated report from log_check_ip ...
show more
XORP (haproxy): 19x HTTP 404/403/500 or handshake failure in 24h. Automated report from log_check_iptables_generator.sh (xorp.hu)
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-08-29 03:18:11
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 35.243.46.100 (100.46.243.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.243.46.100 (100.46.243.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 23:18:03.385235 2026] [security2:error] [pid 2619:tid 2619] [client 35.243.46.100:52534] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "pointandshootfilm.com"] [uri "/.env.bak"] [unique_id "apJPay4NQMzrPUoQyyi2vwAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇵🇱
sefinek.net
2026-08-29 02:05:41
(1 week ago)
Triggered Cloudflare WAF (firewallCustom) from US.
Action: BLOCK | Protocol: HTTP/1.1 (GET) | Endpoi ...
show more
Triggered Cloudflare WAF (firewallCustom) from US.
Action: BLOCK | Protocol: HTTP/1.1 (GET) | Endpoint: / | UA: crusader-worker/1.0 • Generated by: github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
🇺🇸
TPI-Abuse
2026-08-29 01:49:16
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 35.243.46.100 (100.46.243.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.243.46.100 (100.46.243.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 21:49:09.626629 2026] [security2:error] [pid 19950:tid 19950] [client 35.243.46.100:40982] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "contiautos.com.grupoporvenir.com"] [uri "/.env.dev"] [unique_id "apI6lTLBlhW8iYgZjNqqfAAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
andypiper
2026-08-29 01:01:49
(1 week ago)
CrowdSec ban for AbuseIPDB Top List
Brute-Force
Web App Attack
🇳🇱
debestelapp
2026-08-29 00:45:08
(1 week ago)
Web App Attack
🇫🇷
Baking333
2026-08-29 00:13:16
(1 week ago)
[redacted] 35.243.46.100 - - [29/Aug/2026:01:13:15 +0100] "GET /.[redacted] HTTP/1.1" 302 6798 0/495 ...
show more
[redacted] 35.243.46.100 - - [29/Aug/2026:01:13:15 +0100] "GET /.[redacted] HTTP/1.1" 302 6798 0/49565 "-" "crusader-worker/1.0" [redacted] 35.243.46.100 - - [29/Aug/2026:01:13:15 +0100] "GET /.[redacted] HTTP/1.1" 302 6798 0/67443 "-" "crusader-worker/1.0" [redacted] 35.243.46.100 - - [29/Aug/2026:01:13:15 +0100] "GET /.[redacted] HTTP/1.1" 302 6798 0/66634 "-" "crusader-worker/1.0" [redacted] 35.243.46.100 - - [29/Aug/2026:01:13:15 +0100] "GET /.[redacted] HTTP/1.1" 302 6798 0/75561 "-" "crusader-worker/1.0"
show less
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-29 00:05:43
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 35.243.46.100 (100.46.243.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.243.46.100 (100.46.243.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 20:05:38.431975 2026] [security2:error] [pid 1782:tid 1782] [client 35.243.46.100:35424] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "pa-ksa.com"] [uri "/.env.production"] [unique_id "apIiUhPTh3sk_dHvKQYrXgAAADE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
Dominik Lysiak
2026-08-28 23:44:50
(1 week ago)
35.243.46.100 - - [29/Aug/2026:01:44:49 +0200] "GET /.env.prod HTTP/1.1" 401 172 "-" "crusader-worke ...
show more
35.243.46.100 - - [29/Aug/2026:01:44:49 +0200] "GET /.env.prod HTTP/1.1" 401 172 "-" "crusader-worker/1.0"
35.243.46.100 - - [29/Aug/2026:01:44:49 +0200] "GET /.env.save HTTP/1.1" 401 172 "-" "crusader-worker/1.0"
35.243.46.100 - - [29/Aug/2026:01:44:49 +0200] "GET /.env.old HTTP/1.1" 401 172 "-" "crusader-worker/1.0"
...
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-08-28 22:06:40
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 35.243.46.100 (100.46.243.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.243.46.100 (100.46.243.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 18:06:33.369945 2026] [security2:error] [pid 24580:tid 24595] [client 35.243.46.100:36304] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "lapulperiagirona.com.webcraftestudio.com"] [uri "/.env.dev"] [unique_id "apIGaYm99ISEuRCsFl97tgAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-28 21:59:51
(1 week ago)
Banned by Fail2Ban on server
Web App Attack
🇳🇱
homeshowdomain.nl
2026-08-28 21:59:48
(1 week ago)
Auto-ban: >3000 req/min op 2026-08-28
Web App Attack
SSH
Hacking
🇺🇸
TPI-Abuse
2026-08-28 21:15:16
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 35.243.46.100 (100.46.243.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.243.46.100 (100.46.243.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 17:15:12.410972 2026] [security2:error] [pid 3356582:tid 3356702] [client 35.243.46.100:41706] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.fandgins.antidote-it.com"] [uri "/wp-config.php~"] [unique_id "apH6YH_CS5Z3k2TFNp5EoAAAAIU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇨🇦
polycoda
2026-08-28 20:55:21
(1 week ago)
AutoBlock: 🎯 Vulnerability Scanner (Non Decay-Based)
Hacking
Web App Attack
🇩🇪
big-cloud.nl
2026-08-28 20:32:13
(1 week ago)
Try to access /.env
Web App Attack