🇫🇷
LRNP
2026-09-06 06:13:00
(2 hours ago)
_:443 8.235.114.156 - - [06/Sep/2026:06:12:55 +0000] "GET /.env HTTP/1.1" 404 146 "-" "crusader-work ...
show more
_:443 8.235.114.156 - - [06/Sep/2026:06:12:55 +0000] "GET /.env HTTP/1.1" 404 146 "-" "crusader-worker/1.0"
...
show less
Bad Web Bot
Web App Attack
🇳🇱
melroy89
2026-09-06 03:50:29
(5 hours ago)
8.235.114.156 - - [06/Sep/2026:05:49:28 +0200] "GET /.env.example HTTP/1.1" 404 0 "-" "crusader-wor ...
show more
8.235.114.156 - - [06/Sep/2026:05:49:28 +0200] "GET /.env.example HTTP/1.1" 404 0 "-" "crusader-worker/1.0" "cryptofather.melroy.org" 0.013
8.235.114.156 - - [06/Sep/2026:05:49:28 +0200] "GET /storage/logs/laravel.log HTTP/1.1" 404 0 "-" "crusader-worker/1.0" "cryptofather.melroy.org" 0.015
8.235.114.156 - - [06/Sep/2026:05:49:28 +0200] "GET /actuator/configprops HTTP/1.1" 404 0 "-" "crusader-worker/1.0" "cryptofather.melroy.org" 0.014
8.235.114.156 - - [06/Sep/2026:05:49:28 +0200] "GET /_ignition/health-check HTTP/1.1" 404 0 "-" "crusader-worker/1.0" "cryptofather.melroy.org" 0.015
8.235.114.156 - - [06/Sep/2026:05:49:28 +0200] "GET /wp-config.php.swp HTTP/1.1" 404 0 "-" "crusader-worker/1.0" "cryptofather.melroy.org" 0.013
8.235.114.156 - - [06/Sep/2026:05:49:28 +0200] "GET /.env.prod HTTP/1.1" 404 0 "-" "crusader-worker/1.0" "cryptofather.melroy.org" 0.014
8.235.114.156 - - [06/Sep/2026:05:49:28 +0200] "GET /.env.save HTTP/1.1" 404 0 "-" "crusader-worker/1.0" "cryptofather.me
...
show less
Web App Attack
Anonymous
2026-09-06 03:33:23
(5 hours ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 03:21:41
(5 hours ago)
(mod_security) mod_security (id:210730) triggered by 8.235.114.156 (156.114.235.8.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 8.235.114.156 (156.114.235.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 23:21:37.490726 2026] [security2:error] [pid 19762:tid 19762] [client 8.235.114.156:56374] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||brewingermany.com.mardensmith.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "brewingermany.com.mardensmith.com"] [uri "/database.sql"] [unique_id "apzcQTouZr8Xib98AkP8YgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 03:01:44
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 8.235.114.156 (156.114.235.8.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 8.235.114.156 (156.114.235.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 23:01:40.635935 2026] [security2:error] [pid 7392:tid 7392] [client 8.235.114.156:54152] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.krugmans.net"] [uri "/wp-config.php.swp"] [unique_id "apzXlI2OaN_s542TEAsJUQAAAFk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
dynamix
2026-09-06 03:01:09
(5 hours ago)
Multiple WAF Violations
Web App Attack
🇩🇪
Hary74656
2026-09-06 02:45:16
(6 hours ago)
Fail2Ban on schani.hostmi.at: jail=apache-modsecurity, failures=3. No raw log data included.
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 02:33:56
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 8.235.114.156 (156.114.235.8.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 8.235.114.156 (156.114.235.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 22:33:51.423907 2026] [security2:error] [pid 3631970:tid 3631970] [client 8.235.114.156:50266] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "francisfindings.com"] [uri "/.env.bak"] [unique_id "apzRD_o0IU3p3XPrAHHmJAAAACU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇴
jad-abuse
2026-09-06 02:26:42
(6 hours ago)
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: env_probe ...
show more
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: env_probe, scanner_ua, source_backup, actuator, ignition_debug, config_backup. Observed by 1 sensor(s); 42 hits.
show less
Hacking
Web App Attack
🇫🇷
masterguru
2026-09-06 01:47:00
(7 hours ago)
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 8.235.114.156 (US/United States/156.1 ...
show more
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 8.235.114.156 (US/United States/156.114.235.8.bc.googleusercontent.com): 1 in the last 3600 secs (0-195)
show less
Hacking
🇩🇪
raph
2026-09-05 23:08:26
(9 hours ago)
[Wordpress] crawler /wp-admin/*, /wp-content/*, etc.
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 22:50:34
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 8.235.114.156 (156.114.235.8.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 8.235.114.156 (156.114.235.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 18:50:27.056347 2026] [security2:error] [pid 22111:tid 22117] [client 8.235.114.156:36014] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "djkirby.com"] [uri "/.env"] [unique_id "apycs3yjxZ7umzwoNPDegwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 22:11:18
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 8.235.114.156 (156.114.235.8.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 8.235.114.156 (156.114.235.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 18:11:12.223534 2026] [security2:error] [pid 11104:tid 11104] [client 8.235.114.156:45618] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.discountbusinessholidaycards.com"] [uri "/.env"] [unique_id "apyTgHbv_jgbmHo0yXfH1wAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
consul.to
2026-09-05 21:40:26
(11 hours ago)
Web attack/malicious scanning detected
Web App Attack
🇪🇸
elcruzado.es
2026-09-05 21:07:03
(11 hours ago)
(mod_security) mod_security triggered on hostname [redacted] 8.235.114.156 (US/United States/156.114 ...
show more
(mod_security) mod_security triggered on hostname [redacted] 8.235.114.156 (US/United States/156.114.235.8.bc.googleusercontent.com)
show less
SQL Injection