🇫🇷
HerrWolf
2026-09-04 14:15:03
(3 hours ago)
CrowdSec Detection: crowdsecurity/http-sensitive-files
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 14:13:48
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 8.231.104.186 (186.104.231.8.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 8.231.104.186 (186.104.231.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 10:13:43.969488 2026] [security2:error] [pid 18275:tid 18275] [client 8.231.104.186:60824] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.stkm.com"] [uri "/.env.bak"] [unique_id "aprSF-nBGqey3U0xmA1ONAAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 13:37:30
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 8.231.104.186 (186.104.231.8.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 8.231.104.186 (186.104.231.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 09:37:22.623134 2026] [security2:error] [pid 15600:tid 15600] [client 8.231.104.186:38488] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "fales.org"] [uri "/.env"] [unique_id "aprJkkgW6CPYP9t_IQBxegAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 13:16:47
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 8.231.104.186 (186.104.231.8.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 8.231.104.186 (186.104.231.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 09:16:42.944577 2026] [security2:error] [pid 23070:tid 23070] [client 8.231.104.186:43128] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "stickitvinylgraphics.themotelwest.com"] [uri "/.env.old"] [unique_id "aprEuv7PmA_XYA-tvhuB4gAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
consul.to
2026-09-04 12:03:42
(5 hours ago)
Web attack/malicious scanning detected
Web App Attack
🇵🇱
sefinek.net
2026-09-04 11:54:39
(6 hours ago)
Triggered Cloudflare WAF (firewallCustom) from IN.
Action: BLOCK | Protocol: HTTP/1.1 (GET) | Endpoi ...
show more
Triggered Cloudflare WAF (firewallCustom) from IN.
Action: BLOCK | Protocol: HTTP/1.1 (GET) | Endpoint: /%2eenv | UA: crusader-worker/1.0 • Generated by: github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
🇳🇱
WeCloudit-Anti-Abuse
2026-09-04 11:09:56
(6 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
🇩🇪
Hazzard
2026-09-04 10:59:43
(6 hours ago)
(mod_security) mod_security triggered on hostname [redacted]): (CF_ENABLE)
SQL Injection
🇺🇸
TPI-Abuse
2026-09-04 10:05:26
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 8.231.104.186 (186.104.231.8.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 8.231.104.186 (186.104.231.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 06:05:18.831228 2026] [security2:error] [pid 1494:tid 1494] [client 8.231.104.186:44224] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.nolaanimereviews.com"] [uri "/.env.backup"] [unique_id "apqX3g-YSJnHdTaPfZzZ9wAAACA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇨🇭
m_vlasov
2026-09-04 09:59:18
(7 hours ago)
SSH/Telnet honeypot: 0 login attempts, 0 sessions, 0 shell commands.
Hacking
🇩🇪
tsZero
2026-09-04 09:13:01
(8 hours ago)
Scan example: path=/.env status=200
Hacking
🇫🇷
dynamix
2026-09-04 08:28:46
(9 hours ago)
Multiple WAF Violations
Web App Attack
🇫🇷
masterguru
2026-09-04 08:23:26
(9 hours ago)
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 8.231.104.186 (IN/India/186.104.231.8 ...
show more
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 8.231.104.186 (IN/India/186.104.231.8.bc.googleusercontent.com): 1 in the last 3600 secs (0-195)
show less
Hacking
🇺🇸
TPI-Abuse
2026-09-04 08:23:00
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 8.231.104.186 (186.104.231.8.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 8.231.104.186 (186.104.231.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 04:22:55.737128 2026] [security2:error] [pid 14213:tid 14213] [client 8.231.104.186:58204] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.guardmagic.com"] [uri "/.env"] [unique_id "app_3wVrMbvaXMPsIVQkXQAAACY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
Stara
2026-09-04 08:21:18
(9 hours ago)
ModSecurity detected web attack - .env/config probing or SQLi/Code injection (Rule 949110)
Brute-Force
SSH
Web App Attack