๐ฉ๐ช
maxpower
2026-09-01 09:16:25
(12 minutes ago)
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 35.245.60.236 (US/United States/236.60.2 ...
show more
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 35.245.60.236 (US/United States/236.60.245.35.bc.googleusercontent.com): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 35.245.60.236 - - [01/Sep/2026:11:16:21 +0200] "GET /wp-config.php.bak HTTP/1.1" 200 11981 "-" "crusader-worker/1.0" "-" host=svm-srl.it.emmeimpiantimilano.it
show less
Port Scan
๐ฌ๐ง
poundawebsiteltd
2026-09-01 08:20:22
(1 hour ago)
Malicious activity in general-malicious. Evidence: (apache_probe) Failed Access (403/404) 35.245.60. ...
show more
Malicious activity in general-malicious. Evidence: (apache_probe) Failed Access (403/404) 35.245.60.236 (US/United States/[REDACTED_DOMAIN]): 20 in the last 3600 secs | UA: (apache_probe) Failed Access (403/404) 35.245.60.236 (US/United States/236.60.245.35.bc.googleusercontent.com): 20 in the last 3600 secs
show less
Brute-Force
Web App Attack
Anonymous
2026-09-01 07:51:59
(1 hour ago)
[da.kdns.gr] httpd-config-scan: logs=/var/log/httpd/access_log; samples=/actuator/env | /.env.dev | ...
show more
[da.kdns.gr] httpd-config-scan: logs=/var/log/httpd/access_log; samples=/actuator/env | /.env.dev | /.env.save
show less
Hacking
Web App Attack
Anonymous
2026-09-01 07:21:21
(2 hours ago)
Web scanner: GET /wp-config.php~
Web App Attack
Hacking
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-09-01 06:21:23
(3 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-01 06:02:06
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.245.60.236 (236.60.245.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.245.60.236 (236.60.245.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 02:02:00.216789 2026] [security2:error] [pid 3911:tid 3911] [client 35.245.60.236:39804] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.karieva.com"] [uri "/wp-config.php.bak"] [unique_id "apZqWKxRmFV2vlm78bf2JAAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-01 05:44:11
(3 hours ago)
Web application attack detected.
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 05:17:10
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.245.60.236 (236.60.245.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.245.60.236 (236.60.245.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 01:17:02.152038 2026] [security2:error] [pid 15825:tid 15825] [client 35.245.60.236:44692] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "exners.com"] [uri "/.env"] [unique_id "apZfzigcr5PBilVgcq7I1gAAAC0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
Rocky Mountain Bioengineering Symposium
2026-09-01 04:41:19
(4 hours ago)
[Mon Aug 31 22:41:19.139607 2026] [authz_core:error] [pid 104381:tid 140668626232896] [client 35.245 ...
show more
[Mon Aug 31 22:41:19.139607 2026] [authz_core:error] [pid 104381:tid 140668626232896] [client 35.245.60.236:47650] AH01630: client denied by server configuration: /var/www/public_html/history/wp-config.php~
[Mon Aug 31 22:41:19.143222 2026] [authz_core:error] [pid 104381:tid 140669859370560] [client 35.245.60.236:47690] AH01630: client denied by server configuration: /var/www/public_html/history/.env.bak
[Mon Aug 31 22:41:19.145036 2026] [authz_core:error] [pid 104647:tid 140667510494784] [client 35.245.60.236:47664] AH01630: client denied by server configuration: /var/www/public_html/history/wp-config.php.swp
...
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-01 03:49:30
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.245.60.236 (236.60.245.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.245.60.236 (236.60.245.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 23:49:24.187091 2026] [security2:error] [pid 30481:tid 30481] [client 35.245.60.236:43798] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "gordonmerrill.com"] [uri "/.env.prod"] [unique_id "apZLROKXw7WatltA-IEShQAAAEo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-09-01 03:05:42
(6 hours ago)
Scanning/Probing (20)
Brute-Force
Web App Attack
๐ฉ๐ช
Bedios GmbH
2026-09-01 02:50:40
(6 hours ago)
Login credentials theft attempt
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-01 02:39:46
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.245.60.236 (236.60.245.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.245.60.236 (236.60.245.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 22:39:39.534161 2026] [security2:error] [pid 18373:tid 18373] [client 35.245.60.236:44532] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.homeschoolwv.com"] [uri "/.env.example"] [unique_id "apY661CWtnfk1q4AsGDHiwAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-09-01 02:25:45
(7 hours ago)
Multiple WAF Violations
Web App Attack
Anonymous
2026-09-01 01:45:02
(7 hours ago)
suspicious request in access.log
Web App Attack