Anonymous
2026-09-03 02:00:41
(3 days ago)
Auto-reported by Fail2Ban (NPM-Auth)
Web App Attack
🇳🇱
homeshowdomain.nl
2026-09-02 21:59:07
(3 days ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-09-01.
show less
Web App Attack
SSH
Hacking
🇬🇧
openstrike.co.uk
2026-09-02 05:13:16
(3 days ago)
13 attacks on env grabbing URLs, PHP URLs:
GET /.env.bak HTTP/1.1
GET /wp-config.php.swp HTTP/1.1
Hacking
Web App Attack
🇳🇱
homeshowdomain.nl
2026-09-01 21:59:17
(4 days ago)
Auto-ban: >3000 req/min op 2026-09-01
Web App Attack
SSH
Hacking
🇺🇸
TPI-Abuse
2026-09-01 13:46:26
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 35.252.222.161 (161.222.252.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.252.222.161 (161.222.252.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 09:46:23.669918 2026] [security2:error] [pid 29466:tid 29466] [client 35.252.222.161:39802] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.von-s.com"] [uri "/wp-config.php.bak"] [unique_id "apbXL9gTFNcQPHI6YNoFNQAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇮
as211431.net
2026-09-01 13:13:18
(4 days ago)
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET meth ...
show more
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET method)
Endpoint: /wp-config.php.bak
UA: crusader-worker/1.0
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
🇩🇪
raph
2026-09-01 12:20:21
(4 days ago)
[Wordpress] crawler /wp-admin/*, /wp-content/*, etc.
Bad Web Bot
Web App Attack
🇳🇱
e.fierstra
2026-09-01 12:08:30
(4 days ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
🇵🇱
itsvic.dev
2026-09-01 11:11:41
(4 days ago)
35.252.222.161 - - [01/Sep/2026:11:11:40 +0000] "wings.itsvic.dev" "GET /.env.save HTTP/1.1" 404 14 ...
show more
35.252.222.161 - - [01/Sep/2026:11:11:40 +0000] "wings.itsvic.dev" "GET /.env.save HTTP/1.1" 404 14 "-" "crusader-worker/1.0"
35.252.222.161 - - [01/Sep/2026:11:11:40 +0000] "wings.itsvic.dev" "GET /.env.bak HTTP/1.1" 404 14 "-" "crusader-worker/1.0"
35.252.222.161 - - [01/Sep/2026:11:11:40 +0000] "wings.itsvic.dev" "GET /wp-config.php~ HTTP/1.1" 404 14 "-" "crusader-worker/1.0"
...
show less
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-01 11:07:34
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 35.252.222.161 (161.222.252.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.252.222.161 (161.222.252.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 07:07:29.028365 2026] [security2:error] [pid 8517:tid 8517] [client 35.252.222.161:48478] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.boat-registration-hong-kong.com"] [uri "/.env.prod"] [unique_id "apax8SnoHhB2eK4e1bb9nQAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-01 10:25:56
(4 days ago)
Auto-reported by Fail2Ban (NPM-Auth)
Web App Attack
🇫🇷
masterguru
2026-09-01 10:22:52
(4 days ago)
Restricted File Access Attempt. Matched phrase ".env" at REQUEST_FILENAME. (930130-197)
Hacking
Web App Attack
🇨🇭
leo1305
2026-09-01 10:22:26
(4 days ago)
CrowdSec detection | scenario: http-sensitive-files
Web App Attack
Exploited Host
🇩🇪
ger-stg-sifi1
2026-09-01 09:59:24
(4 days ago)
(wordpress) Failed wordpress login using wp-login.php or xmlrpc.php
Web App Attack
🇺🇸
TPI-Abuse
2026-09-01 09:14:46
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 35.252.222.161 (161.222.252.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.252.222.161 (161.222.252.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 05:14:38.354281 2026] [security2:error] [pid 7608:tid 7608] [client 35.252.222.161:53194] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sympalais.boens.org"] [uri "/.env"] [unique_id "apaXfhfA-I2O4tOYes-2SAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack