Anonymous
2026-09-05 01:43:25
(21 hours ago)
"GET /.env HTTP/1.1"
Hacking
Web App Attack
🇳🇱
homeshowdomain.nl
2026-09-04 22:03:05
(1 day ago)
Auto-ban: >3000 req/min op 2026-09-04
Web App Attack
SSH
Hacking
🇺🇸
TPI-Abuse
2026-09-04 15:17:28
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 8.229.181.58 (58.181.229.8.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 8.229.181.58 (58.181.229.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 11:17:24.439976 2026] [security2:error] [pid 26070:tid 26070] [client 8.229.181.58:36698] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "crep-psych.org"] [uri "/wp-config.php~"] [unique_id "aprhBIwffmmh5B82QW7nuAAAAFQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
Vegascosmetics
2026-09-04 14:59:16
(1 day ago)
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after sensitive config/credentials exposure ...
show more
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after sensitive config/credentials exposure probe. Evidence: AttackPattern: /\.env (Match: /.env)
show less
Hacking
Brute-Force
Web App Attack
🇩🇪
todix
2026-09-04 14:06:57
(1 day ago)
WebAttack or semilar from 8.229.181.58
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 14:05:40
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 8.229.181.58 (58.181.229.8.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 8.229.181.58 (58.181.229.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 10:05:34.977840 2026] [security2:error] [pid 27875:tid 27875] [client 8.229.181.58:41250] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.scoutinsignia.com"] [uri "/wp-config.php.bak"] [unique_id "aprQLq-9jWw0tIwyZhjTVAAAADA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇸🇪
vaia.cloud
2026-09-04 13:35:08
(1 day ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
🇬🇧
consul.to
2026-09-04 13:34:22
(1 day ago)
Web attack/malicious scanning detected
Web App Attack
🇫🇷
dynamix
2026-09-04 12:48:50
(1 day ago)
Multiple WAF Violations
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 11:05:12
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 8.229.181.58 (58.181.229.8.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 8.229.181.58 (58.181.229.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 07:05:05.102362 2026] [security2:error] [pid 7242:tid 7242] [client 8.229.181.58:36934] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "huntingforebears.com"] [uri "/wp-config.php.swp"] [unique_id "apql4b1GJLyWKCb5NK9wvwAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
e.fierstra
2026-09-04 08:36:57
(1 day ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
Anonymous
2026-09-04 08:27:37
(1 day ago)
[ns31.kdns.gr] httpd-config-scan: logs=/var/log/httpd/access_log; samples=/.env.production | /wp-con ...
show more
[ns31.kdns.gr] httpd-config-scan: logs=/var/log/httpd/access_log; samples=/.env.production | /wp-config.php.swp | /.env.dev
show less
Hacking
Web App Attack
🇳🇱
WeCloudit-Anti-Abuse
2026-09-04 08:21:30
(1 day ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
🇩🇪
rh24
2026-09-04 07:20:27
(1 day ago)
(mod_security) mod_security triggered on hostname [redacted] 8.229.181.58 (US/United States/58.181.2 ...
show more
(mod_security) mod_security triggered on hostname [redacted] 8.229.181.58 (US/United States/58.181.229.8.bc.googleusercontent.com): (CF_ENABLE)
show less
SQL Injection
🇺🇸
TPI-Abuse
2026-09-04 07:06:21
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 8.229.181.58 (58.181.229.8.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 8.229.181.58 (58.181.229.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 03:06:16.299691 2026] [security2:error] [pid 20778:tid 20778] [client 8.229.181.58:45064] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mydobdate.com"] [uri "/.env.prod"] [unique_id "appt6M6ClQyVugjjCKHzYwAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack