🇩🇪
Ano_Nym
2026-09-05 06:49:17
(11 hours ago)
CrowdSec IDS alert on VPS 85.215.198.123 (DE). Scenario: crowdsecurity/http-sensitive-files
Web App Attack
🇬🇧
openstrike.co.uk
2026-09-05 05:14:20
(12 hours ago)
13 attacks on PHP URLs, env grabbing URLs:
GET /wp-config.php~ HTTP/1.1
GET /.env.example HTTP/1.1
Web App Attack
Hacking
🇳🇱
homeshowdomain.nl
2026-09-04 22:02:52
(19 hours ago)
Auto-ban: >3000 req/min op 2026-09-04
Web App Attack
SSH
Hacking
Anonymous
2026-09-04 15:24:51
(1 day ago)
[server.tmg.gr] httpd-config-scan: sites=www.crisis-management2023.gr; logs=/var/log/httpd/domains/c ...
show more
[server.tmg.gr] httpd-config-scan: sites=www.crisis-management2023.gr; logs=/var/log/httpd/domains/crisis-management2023.gr.log; samples=/actuator/configprops | /.env.prod | /wp-config.php~
show less
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 15:17:20
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.247.237.42 (42.237.247.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.247.237.42 (42.237.247.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 11:17:17.538318 2026] [security2:error] [pid 13311:tid 13311] [client 35.247.237.42:36426] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.smilingorc.com"] [uri "/.env.save"] [unique_id "aprg_TBOOUSPPG44zq8QLAAAACY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 14:41:52
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.247.237.42 (42.237.247.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.247.237.42 (42.237.247.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 10:41:45.030287 2026] [security2:error] [pid 22288:tid 22351] [client 35.247.237.42:53336] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "saryatech.pershia.net"] [uri "/.env"] [unique_id "aprYqerYmpX3tlK6b6xmRgAAAYI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
yitzhaq
2026-09-04 13:31:16
(1 day ago)
35.247.237.42 - - [04/Sep/2026:15:31:13 +0200] "GET /wp-config.php~ HTTP/1.1" 404 4219 "-" "crusader ...
show more
35.247.237.42 - - [04/Sep/2026:15:31:13 +0200] "GET /wp-config.php~ HTTP/1.1" 404 4219 "-" "crusader-worker/1.0"
35.247.237.42 - - [04/Sep/2026:15:31:13 +0200] "GET /wp-config.php.bak HTTP/1.1" 404 4219 "-" "crusader-worker/1.0"
35.247.237.42 - - [04/Sep/2026:15:31:13 +0200] "GET /.env.save HTTP/1.1" 404 4219 "-" "crusader-worker/1.0"
35.247.237.42 - - [04/Sep/2026:15:31:13 +0200] "GET /.env HTTP/1.1" 404 4219 "-" "crusader-worker/1.0"
35.247.237.42 - - [04/Sep/2026:15:31:13 +0200] "GET /_ignition/health-check HTTP/1.1" 404 4219 "-" "crusader-worker/1.0"
35.247.237.42 - - [04/Sep/2026:15:31:13 +0200] "GET /.env.example HTTP/1.1" 404 4219 "-" "crusader-worker/1.0"
35.247.237.42 - - [04/Sep/2026:15:31:13 +0200] "GET /.env.prod HTTP/1.1" 404 4219 "-" "crusader-worker/1.0"
35.247.237.42 - - [04/Sep/2026:15:31:13 +0200] "GET /.env.backup HTTP/1.1" 404 4219 "-" "crusader-worker/1.0"
35.247.237.42 - - [04/Sep/2026:15:31:13 +0200] "GET /actuator/configprops HTTP/1.1" 404 4219 "-" "crusader-wor
show less
Web App Attack
Brute-Force
🇺🇸
TPI-Abuse
2026-09-04 12:31:56
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.247.237.42 (42.237.247.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.247.237.42 (42.237.247.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 08:31:50.250688 2026] [security2:error] [pid 20172:tid 20172] [client 35.247.237.42:48620] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ftp.rimworld.com"] [uri "/.env"] [unique_id "apq6NgBSKFAaTyvT-JYOCAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 11:03:43
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.247.237.42 (42.237.247.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.247.237.42 (42.237.247.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 07:03:38.149241 2026] [security2:error] [pid 27164:tid 27164] [client 35.247.237.42:42738] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "hrmroofing.wholesalelivelobsters.com"] [uri "/.env.backup"] [unique_id "apqlig7jmmq8yX7agiEdSwAAACU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 10:17:56
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.247.237.42 (42.237.247.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.247.237.42 (42.237.247.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 06:17:50.263706 2026] [security2:error] [pid 19518:tid 19518] [client 35.247.237.42:50402] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "perlcreative.perlcreativedesign.com"] [uri "/wp-config.php.bak"] [unique_id "apqazru7Wyg6LHPim8iKPwAAACM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
XICTRON
2026-09-04 10:05:06
(1 day ago)
ModSecurity rule violation detected by Fail2Ban
Web App Attack
🇸🇪
vaia.cloud
2026-09-04 09:20:03
(1 day ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
🇳🇱
debestelapp
2026-09-04 08:35:11
(1 day ago)
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 08:28:29
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.247.237.42 (42.237.247.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.247.237.42 (42.237.247.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 04:28:24.055916 2026] [security2:error] [pid 9582:tid 9582] [client 35.247.237.42:40464] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.battlestem.com"] [uri "/.env.example"] [unique_id "apqBKMNRHiiIpV4dT2sfBwAAAEA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
masterguru
2026-09-04 08:24:26
(1 day ago)
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 35.247.237.42 (BR/Brazil/42.237.247.3 ...
show more
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 35.247.237.42 (BR/Brazil/42.237.247.35.bc.googleusercontent.com): 1 in the last 3600 secs (0-195)
show less
Hacking