🇫🇷
aureliancnx
2026-09-08 03:42:09
(1 hour ago)
HTTP Flood
DDoS Attack
🇩🇪
LRob
2026-09-08 02:30:29
(2 hours ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /wp-config.php.swp (+12 more) | 2026-09-08 02:30 UTC
show less
Hacking
Web App Attack
🇮🇩
FallingGong2833
2026-09-07 20:12:07
(8 hours ago)
GET http 103.58.101.92 /.aider.env 404
Bad Web Bot
Web App Attack
🇫🇷
Vaction
2026-09-07 20:09:35
(8 hours ago)
34.106.194.130 - - [07/Sep/2026:22:09:34 +0200] "GET /.env.local HTTP/1.1" 404 381 "-" "crusader-wor ...
show more
34.106.194.130 - - [07/Sep/2026:22:09:34 +0200] "GET /.env.local HTTP/1.1" 404 381 "-" "crusader-worker/1.0"
show less
Hacking
Bad Web Bot
Web App Attack
🇹🇷
Threat.live
2026-09-06 06:10:03
(1 day ago)
Suspicious Connection Attempts
Brute-Force
🇬🇧
openstrike.co.uk
2026-09-06 05:13:15
(1 day ago)
13 attacks on PHP URLs, env grabbing URLs:
GET /wp-config.php~ HTTP/1.1
GET /.env.old HTTP/1.1
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-06 03:52:37
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.106.194.130 (130.194.106.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.106.194.130 (130.194.106.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 23:52:31.686500 2026] [security2:error] [pid 17172:tid 17172] [client 34.106.194.130:48792] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.chitsey.com"] [uri "/wp-config.php~"] [unique_id "apzjfx1eb79ZT--_54icJAAAADg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-06 03:30:09
(2 days ago)
Aggressive web scan
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 03:00:19
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.106.194.130 (130.194.106.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.106.194.130 (130.194.106.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 23:00:10.388480 2026] [security2:error] [pid 19172:tid 19172] [client 34.106.194.130:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.nyemdr.org"] [uri "/.env.dev"] [unique_id "apzXOjO3Uk4LRpJUnxlMmgAAAIk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇦
URAN Publishing Service
2026-09-06 02:19:46
(2 days ago)
[06/Sep/2026:05:19:45 +0300] -- 34.106.194.130 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET ...
show more
[06/Sep/2026:05:19:45 +0300] -- 34.106.194.130 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET /storage/logs/laravel.log HTTP/1.1
show less
Bad Web Bot
Web App Attack
🇳🇿
realstuffie
2026-09-06 02:07:01
(2 days ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-06 01:09:23
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.106.194.130 (130.194.106.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.106.194.130 (130.194.106.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 21:09:17.436590 2026] [security2:error] [pid 5072:tid 5072] [client 34.106.194.130:46210] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.jellisonrepair.com"] [uri "/.env.local"] [unique_id "apy9PQGAUcGd4XoEMC2WAwAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
mnsf
2026-09-06 01:05:36
(2 days ago)
Scanning/Probing (20)
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 00:48:01
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.106.194.130 (130.194.106.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.106.194.130 (130.194.106.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 20:47:55.729202 2026] [security2:error] [pid 15818:tid 15818] [client 34.106.194.130:58018] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.scottcarper.com"] [uri "/.env.prod"] [unique_id "apy4O7YlWoFP4XLuo2D1oAAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 00:22:54
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.106.194.130 (130.194.106.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.106.194.130 (130.194.106.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 20:22:46.786414 2026] [security2:error] [pid 20161:tid 20182] [client 34.106.194.130:36602] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "learndoexplore.com"] [uri "/wp-config.php.swp"] [unique_id "apyyVs_VgwQvGGlVJ-nXrQAAAFM"]
show less
Brute-Force
Bad Web Bot
Web App Attack