๐ธ๐ช
Per-Erik Runebert
2026-08-29 08:39:21
(2 days ago)
Excessive unauthorized requests
Hacking
๐ฉ๐ช
neckaralb-admin.de
2026-08-28 15:26:04
(3 days ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
๐ธ๐ช
nekopavel
2026-08-28 15:21:37
(3 days ago)
35.245.93.117 - - [28/Aug/2026:17:21:36 +0200]"GET /.env HTTP/1.1" 404 1456"-" bmw.pavel.gg "crusade ...
show more
35.245.93.117 - - [28/Aug/2026:17:21:36 +0200]"GET /.env HTTP/1.1" 404 1456"-" bmw.pavel.gg "crusader-worker/1.0""0.000" "-""Washington" "US"
35.245.93.117 - - [28/Aug/2026:17:21:36 +0200]"GET /.env.old HTTP/1.1" 404 1456"-" bmw.pavel.gg "crusader-worker/1.0""0.000" "-""Washington" "US"
35.245.93.117 - - [28/Aug/2026:17:21:36 +0200]"GET /.env.backup HTTP/1.1" 404 1456"-" bmw.pavel.gg "crusader-worker/1.0""0.000" "-""Washington" "US"
...
show less
Hacking
Bad Web Bot
Web App Attack
๐น๐ท
Threat.live
2026-08-28 14:45:02
(3 days ago)
Suspicious Connection Attempts
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-08-28 14:37:40
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 35.245.93.117 (117.93.245.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.245.93.117 (117.93.245.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 10:37:33.294566 2026] [security2:error] [pid 27422:tid 27422] [client 35.245.93.117:46312] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bassboatmagazine.com"] [uri "/.env.bak"] [unique_id "apGdLf7t3RLZ4S78CqAH9wAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-08-28 13:55:47
(3 days ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 13:54:37
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 35.245.93.117 (117.93.245.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.245.93.117 (117.93.245.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 09:54:31.082369 2026] [security2:error] [pid 20184:tid 20184] [client 35.245.93.117:37068] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.angelsofrhodeisland.com.alanmariotti.com"] [uri "/wp-config.php.bak"] [unique_id "apGTF7F1qcp7YJNk-gwzJQAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
eber965
2026-08-28 13:26:01
(3 days ago)
[Fri Aug 28 09:26:00 2026] [authz_core:error] [pid 2501168:tid 140216513849088] [client 35.245.93.11 ...
show more
[Fri Aug 28 09:26:00 2026] [authz_core:error] [pid 2501168:tid 140216513849088] [client 35.245.93.117:41756] AH01630: client denied by server configuration: /var/www/html/.env.production
[Fri Aug 28 09:26:00 2026] [authz_core:error] [pid 2624682:tid 140216513849088] [client 35.245.93.117:41736] AH01630: client denied by server configuration: /var/www/html/.env
[Fri Aug 28 09:26:00 2026] [authz_core:error] [pid 2624682:tid 140215574324992] [client 35.245.93.117:41744] AH01630: client denied by server configuration: /var/www/html/.env.local
[Fri Aug 28 09:26:00 2026] [authz_core:error] [pid 2624682:tid 140216228628224] [client 35.245.93.117:41760] AH01630: client denied by server configuration: /var/www/html/.env.prod
[Fri Aug 28 09:26:00 2026] [authz_core:error] [pid 2624682:tid 140216505456384] [client 35.245.93.117:41774] AH01630: client denied by server configuration: /var/www/html/.env.backup
...
show less
Brute-Force
๐บ๐ธ
JustMeHere
2026-08-28 13:01:06
(3 days ago)
[Fri Aug 28 09:01:02.040722 2026] [security2:error] [pid 1313:tid 1346] [client 35.245.93.117:53704] ...
show more
[Fri Aug 28 09:01:02.040722 2026] [security2:error] [pid 1313:tid 1346] [client 35.245.93.117:53704] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:blocking_inbound_anomaly_score. [file "/etc/httpd/modsecurity.d/activated_rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "233"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [ver "OWASP_CRS/4.15.0"] [tag "anomaly-evaluation"] [tag "OWASP_CRS"] [hostname "php.yorknation.com"] [uri "/.env.bak"] [unique_id "apGGjh8uuhrrAdRVES7qFgAAAMU"]
...
show less
Web App Attack
Anonymous
2026-08-28 13:00:02
(3 days ago)
suspicious request in access.log
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-08-28 12:51:14
(3 days ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐ฉ๐ช
Lino Project
2026-08-28 12:31:22
(3 days ago)
CrowdSec abuse IP report (host SRV-2) Scenario: crowdsecurity/http-sensitive-files
Hacking
๐บ๐ธ
TPI-Abuse
2026-08-28 12:26:41
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 35.245.93.117 (117.93.245.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.245.93.117 (117.93.245.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 08:26:35.310057 2026] [security2:error] [pid 10770:tid 10770] [client 35.245.93.117:36610] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "understory.us"] [uri "/wp-config.php~"] [unique_id "apF-e6AO98azmh0GRmyCygAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ธ๐ช
vaia.cloud
2026-08-28 12:15:02
(3 days ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
๐ฟ๐ฆ
conure.sh
2026-08-28 11:41:46
(3 days ago)
csagent: score 20.0: wp-config backup grab x2; 1 domain(s) in 0s
Web App Attack