🇳🇱
debestelapp
2026-09-08 11:30:12
(12 hours ago)
Web App Attack
🇫🇷
masterguru
2026-09-08 05:36:11
(18 hours ago)
Restricted File Access Attempt. Matched phrase ".env" at REQUEST_FILENAME. (930130-201)
Hacking
Web App Attack
🇩🇪
gadix
2026-09-08 03:23:09
(20 hours ago)
[08/Sep/2026:05:23:08.641702 +0200] ap9_nPiAyNK89OpU5GPH_gAAAE0 35.243.70.229 51378 127.0.0.1 7081
[ ...
show more
[08/Sep/2026:05:23:08.641702 +0200] ap9_nPiAyNK89OpU5GPH_gAAAE0 35.243.70.229 51378 127.0.0.1 7081
[08/Sep/2026:05:23:08.643890 +0200] ap9_nPiAyNK89OpU5GPIAAAAAEI 35.243.70.229 51412 127.0.0.1 7081
[08/Sep/2026:05:23:08.646368 +0200] ap9_nPiAyNK89OpU5GPIAQAAAFA 35.243.70.229 51426 127.0.0.1 7081
...
show less
Web App Attack
🇦🇹
vikal
2026-09-07 07:35:40
(1 day ago)
35.243.70.229 - - [07/Sep/2026:09:35:40 +0200] "GET /.env.backup HTTP/1.1" 444 0 "-" "crusader-worke ...
show more
35.243.70.229 - - [07/Sep/2026:09:35:40 +0200] "GET /.env.backup HTTP/1.1" 444 0 "-" "crusader-worker/1.0"
...
show less
Brute-Force
SSH
Anonymous
2026-09-07 06:22:04
(1 day ago)
Aggressive web scan
Web App Attack
🇳🇱
homeshowdomain.nl
2026-09-06 22:00:27
(2 days ago)
Auto-ban: >3000 req/min op 2026-09-06
Web App Attack
SSH
Hacking
🇺🇸
TPI-Abuse
2026-09-06 06:07:07
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 35.243.70.229 (229.70.243.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.243.70.229 (229.70.243.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 02:07:01.400568 2026] [security2:error] [pid 15225:tid 15225] [client 35.243.70.229:35742] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "dodgersboosterclub.com"] [uri "/.env.prod"] [unique_id "ap0DBRUejj6nPnRJMKT0bAAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 03:55:08
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 35.243.70.229 (229.70.243.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.243.70.229 (229.70.243.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 23:54:59.717630 2026] [security2:error] [pid 11165:tid 11178] [client 35.243.70.229:50390] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.chronotar.com"] [uri "/wp-config.php.swp"] [unique_id "apzkE_1pRt8N7QnZBIkoMwAAAEo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇨🇭
zynex
2026-09-06 03:38:46
(2 days ago)
URL Probing: /wp-config.php~
Web App Attack
🇫🇷
✨
2026-09-06 03:04:20
(2 days ago)
Domain : watfordcreditunion.co.uk
Rule : env
2026-09-06 03:01:19 ***hidden-privacy*** GET /.env.old ...
show more
Domain : watfordcreditunion.co.uk
Rule : env
2026-09-06 03:01:19 ***hidden-privacy*** GET /.env.old - 443 - 35.243.70.229 HTTP/1.1 crusader-worker/1.0 - watfordcreditunion.co.uk 200 0 0 3716 104 586 - -
show less
Hacking
SQL Injection
🇺🇸
TPI-Abuse
2026-09-06 02:57:13
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 35.243.70.229 (229.70.243.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.243.70.229 (229.70.243.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 22:57:07.501858 2026] [security2:error] [pid 23349:tid 23349] [client 35.243.70.229:53066] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.madbanana.com"] [uri "/.env.backup"] [unique_id "apzWgzH4JnhYTgDpPfV9SQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
Site.eu
2026-09-06 02:54:39
(2 days ago)
Excessive multi-domain requests
Brute-Force
🇫🇷
dynamix
2026-09-06 02:46:31
(2 days ago)
Multiple WAF Violations
Web App Attack
🇨🇿
kronos
2026-09-06 02:42:01
(2 days ago)
IDS: ET WEB_SERVER Tilde in URI - potential .php~ source disclosure vulnerability | SID:2009955
Web App Attack
🇩🇪
Tamsy
2026-09-06 02:18:52
(2 days ago)
HTTPD - 4xx scan
Web App Attack