Anonymous
2026-09-05 10:45:29
(6 hours ago)
[Sat Sep 05 12:45:28.607036 2026] [access_compat:error] [pid 27917] [client 107.167.184.13:49934] AH ...
show more
[Sat Sep 05 12:45:28.607036 2026] [access_compat:error] [pid 27917] [client 107.167.184.13:49934] AH01797: client denied by server configuration: /var/www/html/backend
[Sat Sep 05 12:45:28.618232 2026] [access_compat:error] [pid 27841] [client 107.167.184.13:49970] AH01797: client denied by server configuration: /var/www/html/public
[Sat Sep 05 12:45:28.618564 2026] [access_compat:error] [pid 27918] [client 107.167.184.13:49912] AH01797: client denied by server configuration: /var/www/html/.git
...
show less
Web App Attack
🇹🇷
pashait
2026-09-05 07:30:44
(10 hours ago)
Auto-blocked by Seczar SecureOps — IPS Web Attack Signature (1 events in 5min) at 2026-09-05 07:30
Web App Attack
Bad Web Bot
🇺🇸
antlac1
2026-09-05 06:45:55
(10 hours ago)
crowdsecurity/http-probing
Brute-Force
Web App Attack
🇦🇺
CalmBrain
2026-09-05 06:45:48
(10 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
🇳🇱
homeshowdomain.nl
2026-09-04 21:59:14
(19 hours ago)
Auto-ban: >3000 req/min op 2026-09-04
Web App Attack
SSH
Hacking
🇩🇪
LRob
2026-09-04 15:01:20
(1 day ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /.env.local (+10 more) | 2026-09-04 15:01 UTC
show less
Hacking
Web App Attack
🇩🇪
dbmwebdesign
2026-09-04 14:15:08
(1 day ago)
WAF repeated trigger detected by Fail2Ban in plesk-modsecurity jail
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 13:21:36
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 107.167.184.13 (13.184.167.107.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 107.167.184.13 (13.184.167.107.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 09:21:29.688863 2026] [security2:error] [pid 743424:tid 743424] [client 107.167.184.13:37562] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cofias.net"] [uri "/wp-config.php.bak"] [unique_id "aprF2c0steJSHfDhGvwPqAAAADo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 13:06:34
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 107.167.184.13 (13.184.167.107.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 107.167.184.13 (13.184.167.107.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 09:06:29.729440 2026] [security2:error] [pid 9411:tid 9411] [client 107.167.184.13:47806] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "shannonraevocalstudio.com"] [uri "/.env.local"] [unique_id "aprCVapYF0KagYAYFZIRDwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-04 12:54:11
(1 day ago)
(config_exploit_scan) Configuratie Scanner / Nep GPTBot 107.167.184.13 (TW/Taiwan/13.184.167.107.bc. ...
show more
(config_exploit_scan) Configuratie Scanner / Nep GPTBot 107.167.184.13 (TW/Taiwan/13.184.167.107.bc.googleusercontent.com): 3 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 107.167.184.13 - - [04/Sep/2026:14:54:08 +0200] "GET /.env.save HTTP/1.1" 406 4830 "-" "crusader-worker/1.0"
107.167.184.13 - - [04/Sep/2026:14:54:08 +0200] "GET /.env.example HTTP/1.1" 406 4831 "-" "crusader-worker/1.0"
107.167.184.13 - - [04/Sep/2026:14:54:08 +0200] "GET /.env.old HTTP/1.1" 406 4830 "-" "crusader-worker/1.0"
show less
Port Scan
🇺🇸
TPI-Abuse
2026-09-04 12:35:57
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 107.167.184.13 (13.184.167.107.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 107.167.184.13 (13.184.167.107.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 08:35:51.946828 2026] [security2:error] [pid 9999:tid 9999] [client 107.167.184.13:46524] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "glendaleheritage.org"] [uri "/.env.prod"] [unique_id "apq7JxXkmWb22iXi2PxQYwAAACA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
mnsf
2026-09-04 12:05:17
(1 day ago)
Scanning/Probing (20)
Brute-Force
Web App Attack
Anonymous
2026-09-04 12:02:05
(1 day ago)
Bot / scanning and/or hacking attempts: GET /.env.production HTTP/1.1, GET /actuator/configprops HTT ...
show more
Bot / scanning and/or hacking attempts: GET /.env.production HTTP/1.1, GET /actuator/configprops HTTP/1.1, GET /.env.prod HTTP/1.1, GET /.env.old HTTP/1.1
show less
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 12:00:18
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 107.167.184.13 (13.184.167.107.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 107.167.184.13 (13.184.167.107.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 08:00:09.472148 2026] [security2:error] [pid 23006:tid 23084] [client 107.167.184.13:59514] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "thatspecial.com"] [uri "/.env.backup"] [unique_id "apqyyeK_eLa5AsS1DMl2NQAAAQs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
COMAITE
2026-09-04 11:19:04
(1 day ago)
Suspicious URL access.
Web App Attack