🇺🇸
brightenfield
2026-09-07 06:50:44
(17 hours ago)
Web App Attack
Web App Attack
🇩🇪
pltcldvlpr
2026-09-06 15:44:32
(1 day ago)
CMS/framework probe: 8.235.12.253 - - [06/Sep/2026:17:44:31 +0200] "GET /backup.zip HTTP/1.1" 404 56 ...
show more
CMS/framework probe: 8.235.12.253 - - [06/Sep/2026:17:44:31 +0200] "GET /backup.zip HTTP/1.1" 404 564 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0 Safari/537.36" asn=396982 org="Google LLC" country=US
8.235.12.253 - - [06/Sep/2026:17:44:32 +0200] "GET /backup.tar.gz HTTP/1.1" 404 564 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0 Safari/537.36" asn=396982 org="Google LLC" country=US
8.235.12.253 - - [06/Sep/2026:17:44:32 +0200] "GET /backup.tgz HTTP/1.1" 404 564 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0 Safari/537.36" asn=396982 org="Google LLC" country=US
8.235.12.253 - - [06/Sep/2026:17:44:32 +0200] "GET /backup.tar HTTP/1.1" 404 564 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0 Safari/537.36" asn=396982 org="Google LLC" country=US
8.235.12.253 - - [06/Sep/2026:17:44:32 +0200] "GET /backup.sql.bz2 HTTP/1.1" 404
...
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 03:50:26
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 8.235.12.253 (253.12.235.8.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 8.235.12.253 (253.12.235.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 23:50:22.007936 2026] [security2:error] [pid 17630:tid 17630] [client 8.235.12.253:34200] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.beatthegm.com"] [uri "/.env.old"] [unique_id "apzi_nZQumLks2_AOAMFLAAAAFY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 02:32:41
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 8.235.12.253 (253.12.235.8.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 8.235.12.253 (253.12.235.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 22:32:33.604813 2026] [security2:error] [pid 23074:tid 23074] [client 8.235.12.253:53058] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "files.nautos-usa.com"] [uri "/.env.prod"] [unique_id "apzQwcEfVG-XPwWuLEy6fgAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 02:04:53
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 8.235.12.253 (253.12.235.8.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 8.235.12.253 (253.12.235.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 22:04:47.198479 2026] [security2:error] [pid 22210:tid 22210] [client 8.235.12.253:37436] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mcdonalds.jbaydeliveries.com"] [uri "/wp-config.php.bak"] [unique_id "apzKP3QPMGjJHtFF4bk2SQAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
✨
2026-09-06 01:39:09
(1 day ago)
Domain : icontraining.co.uk
Rule : env
2026-09-06 01:37:46 W3SVC713 PLESK72 ***hidden-privacy*** GET ...
show more
Domain : icontraining.co.uk
Rule : env
2026-09-06 01:37:46 W3SVC713 PLESK72 ***hidden-privacy*** GET /.env.example - 80 - 8.235.12.253 HTTP/1.1 crusader-worker/1.0 - - icontraining.co.uk 404 0 2 1534 102 719 - -
show less
Hacking
SQL Injection
🇩🇪
paissangroup
2026-09-06 01:33:04
(1 day ago)
Multiple WAF Violations
Web App Attack
🇬🇧
Aetherweb Ark
2026-09-06 01:15:03
(1 day ago)
(mod_security) mod_security (id:949110) triggered by 8.235.12.253 (US/United States/253.12.235.8.bc. ...
show more
(mod_security) mod_security (id:949110) triggered by 8.235.12.253 (US/United States/253.12.235.8.bc.googleusercontent.com): N in the last X secs
show less
Web App Attack
🇬🇧
consul.to
2026-09-06 00:33:14
(1 day ago)
Web attack/malicious scanning detected
Web App Attack
🇨🇭
4server
2026-09-06 00:21:37
(1 day ago)
[SunSep0602:21:30.3973802026][security2:error][pid2403132:tid2403397][client8.235.12.253:0]ModSecuri ...
show more
[SunSep0602:21:30.3973802026][security2:error][pid2403132:tid2403397][client8.235.12.253:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\".env\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"610\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"labaita-lanzo.it\"][uri\"/.env.local\"][unique_id\"apyyCqxMFo8Nas83U5fJzwAAAAs\"]
show less
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 23:54:56
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 8.235.12.253 (253.12.235.8.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 8.235.12.253 (253.12.235.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 19:54:50.250840 2026] [security2:error] [pid 22459:tid 22459] [client 8.235.12.253:47054] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.qwik-wash.com"] [uri "/.env"] [unique_id "apyryhnX7-TqWFFgsP-dygAAACo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇲🇾
Rizzy
2026-09-05 23:48:05
(2 days ago)
Multiple WAF Violations
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 23:29:23
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 8.235.12.253 (253.12.235.8.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 8.235.12.253 (253.12.235.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 19:29:18.879980 2026] [security2:error] [pid 9930:tid 9930] [client 8.235.12.253:57234] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htaccess" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.haerringer.com"] [uri "/.htaccess"] [unique_id "apylzvpv8MLoJS3A6kJi2QAAAFQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
Starburst SysOp Team
2026-09-05 23:14:05
(2 days ago)
Restricted File Access Attempt. Matched phrase ".env" at REQUEST_FILENAME. (930130-mnz6-7)
Hacking
Web App Attack
🇺🇸
mnsf
2026-09-05 23:05:24
(2 days ago)
Scanning/Probing (20)
Brute-Force
Web App Attack