๐ฉ๐ช
LRob
2026-09-01 05:22:52
(14 hours ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /.env.backup (+12 more) | 2026-09-01 05:22 UTC
show less
Hacking
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-09-01 05:12:05
(15 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐ฉ๐ช
Bedios GmbH
2026-09-01 04:45:00
(15 hours ago)
Login credentials theft attempt
Hacking
๐ฉ๐ช
Viveronese
2026-09-01 04:36:41
(15 hours ago)
HTTP vulnerability scanning
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 03:44:12
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.255.63.10 (10.63.255.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.255.63.10 (10.63.255.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 23:44:05.410112 2026] [security2:error] [pid 14145:tid 14145] [client 35.255.63.10:60174] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "americaskitchencoach.com"] [uri "/.env.example"] [unique_id "apZKBR4FE0SkPGu1dXa8lQAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 02:42:14
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.255.63.10 (10.63.255.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.255.63.10 (10.63.255.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 22:42:09.655920 2026] [security2:error] [pid 23430:tid 23430] [client 35.255.63.10:38172] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bamedica.com"] [uri "/wp-config.php~"] [unique_id "apY7ge-Iv47nQRDT_L_M5gAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-09-01 02:24:00
(17 hours ago)
Multiple WAF Violations
Web App Attack
๐ธ๐ช
vaia.cloud
2026-09-01 01:15:02
(19 hours ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
๐ฌ๐ง
Aetherweb Ark
2026-09-01 00:36:04
(19 hours ago)
(mod_security) mod_security (id:949110) triggered by 35.255.63.10 (US/United States/10.63.255.35.bc. ...
show more
(mod_security) mod_security (id:949110) triggered by 35.255.63.10 (US/United States/10.63.255.35.bc.googleusercontent.com): N in the last X secs
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 00:17:03
(20 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.255.63.10 (10.63.255.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.255.63.10 (10.63.255.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 20:16:58.292178 2026] [security2:error] [pid 4081:tid 4081] [client 35.255.63.10:57544] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.kinnen.org"] [uri "/.env.production"] [unique_id "apYZemMmtReGVNU2WSwyFAAAAHk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-31 23:53:12
(20 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.255.63.10 (10.63.255.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.255.63.10 (10.63.255.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 19:53:06.898279 2026] [security2:error] [pid 20727:tid 20727] [client 35.255.63.10:56580] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "compmansys.com"] [uri "/.env.example"] [unique_id "apYT4p9kAJhLfZOcd-O1DAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-08-31 22:38:11
(21 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐ฎ๐น
VHosting
2026-08-31 21:40:04
(22 hours ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐ณ๐ด
Abuse Buster
2026-08-31 21:22:18
(22 hours ago)
35.255.63.10 - - [31/Aug/2026:23:22:16 +0200] "GET /.env HTTP/1.1" 444 0 "-" "crusader-worker/1.0"
3 ...
show more
35.255.63.10 - - [31/Aug/2026:23:22:16 +0200] "GET /.env HTTP/1.1" 444 0 "-" "crusader-worker/1.0"
35.255.63.10 - - [31/Aug/2026:23:22:16 +0200] "GET /.env HTTP/1.1" 301 162 "-" "crusader-worker/1.0"
...
show less
Web App Attack