๐ฉ๐ช
dbmwebdesign
2026-09-02 04:00:09
(12 hours ago)
Repeated probing for non-existent PHP exploit paths blocked by Fail2Ban
Web App Attack
๐บ๐ธ
mnsf
2026-09-02 00:05:34
(16 hours ago)
Scanning/Probing (20)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 14:02:12
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.106.212.165 (165.212.106.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.106.212.165 (165.212.106.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 10:02:08.569689 2026] [security2:error] [pid 24047:tid 24047] [client 34.106.212.165:36220] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.spyasociados.com"] [uri "/wp-config.php~"] [unique_id "apba4MXllWm0Y5iYfsI2egAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
ANTI SCANNER
2026-09-01 13:15:12
(1 day ago)
Scanner : /.env.local
Web Spam
๐ง๐ฌ
HighWay
2026-09-01 13:00:26
(1 day ago)
34.106.212.165 - - [01/Sep/2026:13:00:20 +0000] "GET /.env.local HTTP/1.1" 404 5522 "-" "crusader-wo ...
show more
34.106.212.165 - - [01/Sep/2026:13:00:20 +0000] "GET /.env.local HTTP/1.1" 404 5522 "-" "crusader-worker/1.0"
34.106.212.165 - - [01/Sep/2026:13:00:20 +0000] "GET /.env.production HTTP/1.1" 404 5522 "-" "crusader-worker/1.0"
34.106.212.165 - - [01/Sep/2026:13:00:20 +0000] "GET /.env.old HTTP/1.1" 404 5522 "-" "crusader-worker/1.0"
...
show less
Port Scan
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 12:38:39
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.106.212.165 (165.212.106.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.106.212.165 (165.212.106.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 08:38:31.048915 2026] [security2:error] [pid 3692:tid 3692] [client 34.106.212.165:42426] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "chrismcc.com"] [uri "/.env.bak"] [unique_id "apbHR8ii6P-nJWYQVHcNMwAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 12:21:24
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.106.212.165 (165.212.106.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.106.212.165 (165.212.106.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 08:21:18.663550 2026] [security2:error] [pid 29323:tid 29575] [client 34.106.212.165:47794] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sandiegosamsolo.com.workconfident.com"] [uri "/.env"] [unique_id "apbDPoL9jUd1Jc6zHxscBAAAAMg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob
2026-09-01 11:09:28
(1 day ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /wp-config.php.bak (+12 more) | 2026-09-01 11:09 UTC
show less
Hacking
Web App Attack
๐ฉ๐ช
Lino Project
2026-09-01 10:48:28
(1 day ago)
CrowdSec abuse IP report (host SRV-2) Scenario: crowdsecurity/http-sensitive-files
Hacking
๐ซ๐ท
COMAITE
2026-09-01 09:29:12
(1 day ago)
Suspicious URL access.
Web App Attack
๐บ๐ธ
Lee Daniel
2026-09-01 09:27:25
(1 day ago)
34.106.212.165 - - [01/Sep/2026:05:27:25 -0400] "GET /.env HTTP/1.1" 403 6300 "-" "crusader-worker/1 ...
show more
34.106.212.165 - - [01/Sep/2026:05:27:25 -0400] "GET /.env HTTP/1.1" 403 6300 "-" "crusader-worker/1.0"
...
show less
DDoS Attack
Web Spam
Email Spam
Port Scan
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 09:15:07
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.106.212.165 (165.212.106.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.106.212.165 (165.212.106.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 05:15:02.311012 2026] [security2:error] [pid 10970:tid 10970] [client 34.106.212.165:35540] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "tavo.info"] [uri "/.env.old"] [unique_id "apaXlsmyhKT1CqTaQ14IfgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 08:30:57
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.106.212.165 (165.212.106.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.106.212.165 (165.212.106.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 04:30:53.157532 2026] [security2:error] [pid 25479:tid 25479] [client 34.106.212.165:41364] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "marinestorage.com"] [uri "/wp-config.php.bak"] [unique_id "apaNPbpTA-tGdAO2qyzhSQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ธ๐ช
vaia.cloud
2026-09-01 07:30:04
(1 day ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
Anonymous
2026-09-01 06:43:02
(1 day ago)
Bot / scanning and/or hacking attempts: GET /.env.example HTTP/1.1, GET /storage/logs/laravel.log HT ...
show more
Bot / scanning and/or hacking attempts: GET /.env.example HTTP/1.1, GET /storage/logs/laravel.log HTTP/1.1, GET /_ignition/health-check HTTP/1.1, GET /.env.production HTTP/1.1, GET /.env.dev HTTP/1.1, GET /.env.bak HTTP/1.1, GET /.env.local HTTP/1.1, GET /wp-config.php~ HTTP/1.1, GET /wp-config.php.swp HTTP/1.1, GET /crusader-404-probe HTTP/1.1, GET /actuator/env HTTP/1.1, GET /.env.backup HTTP/1.1
show less
Hacking
Web App Attack