π©πͺ
McClay
2026-09-01 05:02:31
(11 hours ago)
HTTP-404 spam:35.247.211.34 - - [01/Sep/2026:07:02:31 +0200] "GET /wp-config.php.bak HTTP/1.1" 404 5 ...
show more
HTTP-404 spam:35.247.211.34 - - [01/Sep/2026:07:02:31 +0200] "GET /wp-config.php.bak HTTP/1.1" 404 5009 "-" "crusader-worker/1.0"
35.247.211.34 - - [01/Sep/2026:07:02:31 +0200] "GET /.env.local HTTP/1.1" 404 5009 "-" "crusader-worker/1.0"
35.247.211.34 - - [01/Sep/2026:07:02:31 +0200] "GET /.env.example HTTP/1.1" 404 5009 "-" "crusader-worker/1.0"
35.247.211.34 - - [01/Sep/2026:07:02:31 +0200] "GET /actuator/configprops HTTP/1.1" 404 5008 "-" "crusader-worker/1.0"
35.247.211.34 - - [01/Sep/2026:07:02:31 +0200] "GET /.env.backup HTTP/1.1" 404 5009 "-" "crusader-worker/1.0"
35.247.211.34 - - [01/Sep/2026:07:02:31 +0200] "GET /wp-config.php.swp HTTP/1.1" 404 5009 "-" "crusader-worker/1.0"
35.247.211.34 - - [01/Sep/2026:07:02:31 +0200] "GET /.env.production HTTP/1.1" 404 5009 "-" "crusader-worker/1.0"
35.247.211.34 - - [01/Sep/2026:07:02:31 +0200] "GET /env HTTP/1.1" 404 5010 "-" "crusader-worker/1.0"
35.247.211.34 - - [01/Sep/2026:07:02:31 +0200] "GET /.env.bak HTTP/1.1" 404 5008 "-" "crusader-worker/1
...
show less
Web App Attack
π©πͺ
tsZero
2026-09-01 04:38:27
(11 hours ago)
Scan example: path=/.env status=403
Hacking
π©πͺ
raph
2026-09-01 04:32:55
(11 hours ago)
[DOT FILES] crawler *.env*, .git*, .config*, etc.
Bad Web Bot
Web App Attack
π©πͺ
YF
2026-09-01 04:30:16
(11 hours ago)
WordPress config file probe
Web App Attack
π©πͺ
arnisolutions
2026-09-01 03:35:35
(12 hours ago)
Vulnerability scanning (requests for admin panels, shells, backup files etc.) against a production s ...
show more
Vulnerability scanning (requests for admin panels, shells, backup files etc.) against a production server. Observed on 1 day(s) between 2026-09-01 and 2026-09-01 (UTC). Sample request: GET /.env.old HTTP/2.0
show less
Web App Attack
Hacking
π¬π§
consul.to
2026-09-01 02:40:30
(13 hours ago)
Web attack/malicious scanning detected
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-01 02:23:53
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.247.211.34 (34.211.247.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.247.211.34 (34.211.247.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 22:23:49.156007 2026] [security2:error] [pid 17580:tid 17580] [client 35.247.211.34:49068] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "graftandcorruption.net"] [uri "/.env.prod"] [unique_id "apY3NX-Bgm_AWhh60aUFewAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-01 01:42:44
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.247.211.34 (34.211.247.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.247.211.34 (34.211.247.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 21:42:37.635749 2026] [security2:error] [pid 3601443:tid 3601578] [client 35.247.211.34:56990] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "gryphix2014.thesdgriffingroup.com"] [uri "/.env.local"] [unique_id "apYtjYMamFXk_PFHmfVa3AAAANE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-01 01:19:36
(14 hours ago)
Web application attack detected.
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-01 00:18:41
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.247.211.34 (34.211.247.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.247.211.34 (34.211.247.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 20:18:35.249250 2026] [security2:error] [pid 28352:tid 28352] [client 35.247.211.34:41282] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.softwarezz.net"] [uri "/wp-config.php.bak"] [unique_id "apYZ2_lY3ioR--6vtsY0QwAAACY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π«π·
dynamix
2026-08-31 23:40:48
(16 hours ago)
Multiple WAF Violations
Web App Attack
π³π±
debestelapp
2026-08-31 23:40:11
(16 hours ago)
Web App Attack
πΈπͺ
vaia.cloud
2026-08-31 23:00:01
(17 hours ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
π©πͺ
Hazzard
2026-08-31 22:49:32
(17 hours ago)
(mod_security) mod_security triggered on hostname [redacted]): (CF_ENABLE)
SQL Injection
πΊπΈ
TPI-Abuse
2026-08-31 22:48:08
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.247.211.34 (34.211.247.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.247.211.34 (34.211.247.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 18:48:03.027005 2026] [security2:error] [pid 4162:tid 4162] [client 35.247.211.34:37042] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "blog.didemozbek.com.pist.org.tr"] [uri "/.env"] [unique_id "apYEo_MlSfDUBUom13y9GwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack