๐ฌ๐ง
Apache
2026-09-06 04:42:33
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 34.106.16.64 (US/United States/64.16.106.34.bc. ...
show more
(mod_security) mod_security (id:210730) triggered by 34.106.16.64 (US/United States/64.16.106.34.bc.googleusercontent.com): 5 in the last 300 secs (CF_ENABLE)
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-06 03:49:22
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.106.16.64 (64.16.106.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.106.16.64 (64.16.106.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 23:49:15.186469 2026] [security2:error] [pid 13401:tid 13401] [client 34.106.16.64:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.dentguyvt.com"] [uri "/.env.example"] [unique_id "apziu6HG5AuGXDj2l0j_8QAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Skyrider
2026-09-06 03:32:35
(1 week ago)
crowdsecurity/http-sensitive-files
Web App Attack
๐ฉ๐ช
Nevermind
2026-09-06 01:47:52
(1 week ago)
34.106.16.64 - - [06/Sep/2026:03:47:51 +0200] "GET /.env.local HTTP/1.1" 403 6299 "-" "crusader-work ...
show more
34.106.16.64 - - [06/Sep/2026:03:47:51 +0200] "GET /.env.local HTTP/1.1" 403 6299 "-" "crusader-worker/1.0"
34.106.16.64 - - [06/Sep/2026:03:47:51 +0200] "GET /wp-config.php~ HTTP/1.1" 403 6299 "-" "crusader-worker/1.0"
34.106.16.64 - - [06/Sep/2026:03:47:51 +0200] "GET /.env HTTP/1.1" 403 6299 "-" "crusader-worker/1.0"
34.106.16.64 - - [06/Sep/2026:03:47:51 +0200] "GET /.env.old HTTP/1.1" 403 6299 "-" "crusader-worker/1.0"
...
show less
Web App Attack
๐ต๐ฑ
Budyn
2026-09-06 01:24:34
(1 week ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scan ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scanner. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: i.budyn.ovh | URI: /.env.old | UA: crusader-worker/1.0 | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
๐ฌ๐ง
andypiper
2026-09-06 01:00:57
(1 week ago)
CrowdSec ban for AbuseIPDB Top List
Brute-Force
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-09-06 00:15:22
(1 week ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐ท๐ด
iulianh
2026-09-05 21:20:36
(1 week ago)
80,443
Brute-Force
SSH
๐ณ๐ฑ
MyGlobalFlowers
2026-09-05 21:07:55
(1 week ago)
Multiple WAF Violations
Web App Attack
๐ฉ๐ช
raph
2026-09-05 21:06:03
(1 week ago)
[DOT FILES] crawler *.env*, .git*, .config*, etc.
Bad Web Bot
Web App Attack
๐ซ๐ท
AGEPCom
2026-09-05 20:54:46
(1 week ago)
Smart-Ban: IP bannie via score AbuseIPDB
Brute-Force
Web App Attack
๐ช๐ธ
alferez
2026-09-05 07:17:51
(2 weeks ago)
Searching .(env|sql|zip|tar|rar) files
Hacking
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-04 15:17:09
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 34.106.16.64 (64.16.106.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.106.16.64 (64.16.106.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 11:17:03.807818 2026] [security2:error] [pid 7117:tid 7117] [client 34.106.16.64:58994] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.2massociatesllc.com"] [uri "/.env.backup"] [unique_id "aprg7zMJT7jsqL4hk-2xKgAAAG8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-04 14:07:44
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 34.106.16.64 (64.16.106.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.106.16.64 (64.16.106.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 10:07:40.744567 2026] [security2:error] [pid 22985:tid 22985] [client 34.106.16.64:54272] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.eye7graphics.com"] [uri "/.env.save"] [unique_id "aprQrC3vGajlALPb1mZa_wAAAB8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ฟ
ptlab
2026-09-04 14:00:03
(2 weeks ago)
Detected wp_config attack from WP-host.
Hacking
Web App Attack