๐ช๐ธ
alferez
2026-08-01 17:33:29
(14 hours ago)
Searching .(env|sql|zip|tar|rar) files
Hacking
Exploited Host
Web App Attack
Anonymous
2026-08-01 16:53:02
(14 hours ago)
Bot / scanning and/or hacking attempts: GET /.env.save HTTP/1.1, GET /.env.bak HTTP/1.1, GET /.env.e ...
show more
Bot / scanning and/or hacking attempts: GET /.env.save HTTP/1.1, GET /.env.bak HTTP/1.1, GET /.env.example HTTP/1.1, GET /.env HTTP/1.1, GET /.env.dev HTTP/1.1, GET /.env.production HTTP/1.1, GET /.env.prod HTTP/1.1, GET /.env.local HTTP/1.1, GET /.env.backup HTTP/1.1, GET /.env.old HTTP/1.1
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-01 16:40:08
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.101.229.32 (32.229.101.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.101.229.32 (32.229.101.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 12:40:00.849258 2026] [security2:error] [pid 234939:tid 234939] [client 34.101.229.32:50420] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.bizzybeejunkremoval.soviaenterprises.com"] [uri "/.env.bak"] [unique_id "am4hYMIDp3S617k12Eq1YQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob
2026-08-01 16:16:34
(15 hours ago)
CrowdSec: crowdsecurity/http-sensitive-files | req: /.env.bak | 5 distinct paths | UA: crusader-work ...
show more
CrowdSec: crowdsecurity/http-sensitive-files | req: /.env.bak | 5 distinct paths | UA: crusader-worker/1.0
show less
Hacking
๐ซ๐ฎ
mnazibo
2026-08-01 16:15:44
(15 hours ago)
Date: Aug 01 19:13:41 2026 EAT | Reported IP: 34.101.229.32 mod_security | id: 920440 930130 949110 ...
show more
Date: Aug 01 19:13:41 2026 EAT | Reported IP: 34.101.229.32 mod_security | id: 920440 930130 949110 | ID/usernameab.my_domain/- | Connections: 1 | Blocked: Permanent Block: [LF_MODSEC] | Logs: ; URL file extension is restricted by policy; URL file extension is restricted by policy; URL file extension is restricted by policy; URL file extension is restricted by policy; Restricted File Access Attempt; Restricted File Access Attempt; Restricted File Access Attempt; Restricted File Access Attempt; Restricted File Access Attempt; Restricted File Access Attempt; Restricted File Access Attempt; Restricted File Access Attempt; Restricted File Access Attempt; Restricted File Access Attempt; Inbound Anomaly Score Exceeded (Total Score: 10); Inbound Anomaly Score Exceeded (Total Score: 10); Inbound Anomaly Score Exceeded (Total Score: 10); Inbound Anomaly Score Exceeded (Total Score: 10); Inbound Anomaly Score Exceeded (Total Score: 5); Inbound An
show less
SQL Injection
Brute-Force
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-08-01 15:52:19
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.101.229.32 (32.229.101.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.101.229.32 (32.229.101.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 11:52:12.005942 2026] [security2:error] [pid 2905792:tid 2905799] [client 34.101.229.32:33838] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kimbleproperties.com"] [uri "/.env.backup"] [unique_id "am4WLKgTNrrL8heozGr2jwAAAEU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
gws-hostmaster
2026-08-01 15:26:50
(16 hours ago)
[Sat Aug 01 16:26:49.936236 2026] [authz_core:error] [pid 1975220] [client 34.101.229.32:0] AH01630: ...
show more
[Sat Aug 01 16:26:49.936236 2026] [authz_core:error] [pid 1975220] [client 34.101.229.32:0] AH01630: client denied by server configuration: /var/www/vhosts/iqvisuals.uk/store.iqvisuals.uk/.env.save
[Sat Aug 01 16:26:49.938125 2026] [authz_core:error] [pid 1997311] [client 34.101.229.32:0] AH01630: client denied by server configuration: /var/www/vhosts/iqvisuals.uk/store.iqvisuals.uk/.env.bak
[Sat Aug 01 16:26:49.939732 2026] [authz_core:error] [pid 1975221] [client 34.101.229.32:0] AH01630: client denied by server configuration: /var/www/vhosts/iqvisuals.uk/store.iqvisuals.uk/.env.production
[Sat Aug 01 16:26:49.940911 2026] [authz_core:error] [pid 1975219] [client 34.101.229.32:0] AH01630: client denied by server configuration: /var/www/vhosts/iqvisuals.uk/store.iqvisuals.uk/.env.prod
[Sat Aug 01 16:26:49.941999 2026] [authz_core:error] [pid 1975222] [client 34.101.229.32:0] AH01630: client denied by server configuration: /var/www/vhosts/iqvisuals.uk/store.iqvisuals.uk/.env.dev
...
show less
Web App Attack
๐ฉ๐ช
Balthasar Morpheus Jรถrmundur (JKweb Service)
2026-08-01 15:24:10
(16 hours ago)
JKweb Security: Severe and dangerous web attack detected. Vulnerability Wordpress Scanning, Director ...
show more
JKweb Security: Severe and dangerous web attack detected. Vulnerability Wordpress Scanning, Directory Brute-Forcing / Content Discovery, Predictable Resource Location / Forced Browsing, Scan for administration and debugging interfaces of modern frameworks, Scan for Spring Boot Actuator Leaks, Scan for Cloud & Infrastructure Credentials, Scan for Database & Backup Dumps, Scan for IDE- und Editor-Configurations, Scan for CI/CD Pipelines & GitHub Workflows etc. The Attacker is permanently banned by Fail2Ban, configurate by JKweb Security a brand of JKweb Service.
show less
Port Scan
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-01 15:17:42
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.101.229.32 (32.229.101.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.101.229.32 (32.229.101.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 11:17:37.469716 2026] [security2:error] [pid 32176:tid 32176] [client 34.101.229.32:45850] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kirbyimc.com"] [uri "/.env.dev"] [unique_id "am4OEYGA2BueQwMS_PQs4QAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-01 14:58:59
(16 hours ago)
(mod_security) mod_security (id:949110) triggered by 34.101.229.32 (32.229.101.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:949110) triggered by 34.101.229.32 (32.229.101.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 10:58:55.371526 2026] [security2:error] [pid 2046489:tid 2046489] [client 34.101.229.32:43990] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "hallemann.com"] [uri "/.env.dev"] [unique_id "am4Jr07vEnh-fD1n_kniowAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
4server
2026-08-01 14:24:32
(17 hours ago)
[SatAug0116:24:29.0935412026][security2:error][pid3823551:tid3823823][client34.101.229.32:0]ModSecur ...
show more
[SatAug0116:24:29.0935412026][security2:error][pid3823551:tid3823823][client34.101.229.32:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\".env\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"365\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"autodiscover.janus-advisory.ch\"][uri\"/.env.bak\"][unique_id\"am4BnRvrKmGi8iJ2Q00zqAAAAQs\"]
show less
Hacking
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-08-01 14:12:35
(17 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-08-01 14:05:28
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.101.229.32 (32.229.101.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.101.229.32 (32.229.101.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 10:05:24.879074 2026] [security2:error] [pid 1727278:tid 1727278] [client 34.101.229.32:42284] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bazzoli.com"] [uri "/.env.prod"] [unique_id "am39JCb4mmGRkzm14cua2AAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Baking333
2026-08-01 13:50:23
(17 hours ago)
[redacted] 34.101.229.32 - - [01/Aug/2026:14:50:21 +0100] "GET /.[redacted] HTTP/1.1" 302 6768 0/504 ...
show more
[redacted] 34.101.229.32 - - [01/Aug/2026:14:50:21 +0100] "GET /.[redacted] HTTP/1.1" 302 6768 0/50497 "-" "crusader-worker/1.0" [redacted] 34.101.229.32 - - [01/Aug/2026:14:50:21 +0100] "GET /.[redacted] HTTP/1.1" 302 6768 0/70191 "-" "crusader-worker/1.0" [redacted] 34.101.229.32 - - [01/Aug/2026:14:50:21 +0100] "GET /.[redacted] HTTP/1.1" 302 6768 0/55518 "-" "crusader-worker/1.0" [redacted] 34.101.229.32 - - [01/Aug/2026:14:50:21 +0100] "GET /.env HTTP/1.1" 302 6768 0/79862 "-" "crusader-worker/1.0" [redacted] 34.101.229.32 - - [01/Aug/2026:14:50:21 +0100] "GET /.[redacted] HTTP/1.1" 302 6768 0/50528 "-" "crusader-worker/1.0"
show less
Bad Web Bot
Web App Attack
๐ฌ๐ง
consul.to
2026-08-01 13:36:11
(18 hours ago)
Web attack/malicious scanning detected
Web App Attack