🇺🇸
pszsh
2026-09-06 01:17:22
(35 minutes ago)
Automated probing for exposed secrets and version-control internals: 3 requests for non-existent sen ...
show more
Automated probing for exposed secrets and version-control internals: 3 requests for non-existent sensitive paths, e.g. /.env.prod /.env.dev /.env.local. Observed by an nginx reputation gate; no credentials or user data involved.
show less
Web App Attack
🇫🇮
pixiekat
2026-09-06 00:20:49
(1 hour ago)
[Sun Sep 06 01:20:48.920295 2026] [authz_core:error] [pid 550793:tid 550821] [client 34.106.32.58:51 ...
show more
[Sun Sep 06 01:20:48.920295 2026] [authz_core:error] [pid 550793:tid 550821] [client 34.106.32.58:51500] AH01630: client denied by server configuration: /mnt/HC_Volume_105148208/vhosts/matomo/.env.bak
[Sun Sep 06 01:20:48.923502 2026] [authz_core:error] [pid 550714:tid 550777] [client 34.106.32.58:51472] AH01630: client denied by server configuration: /mnt/HC_Volume_105148208/vhosts/matomo/.env.backup
[Sun Sep 06 01:20:48.924644 2026] [authz_core:error] [pid 550793:tid 550833] [client 34.106.32.58:51620] AH01630: client denied by server configuration: /mnt/HC_Volume_105148208/vhosts/matomo/.env
[Sun Sep 06 01:20:48.927359 2026] [authz_core:error] [pid 550793:tid 550823] [client 34.106.32.58:51602] AH01630: client denied by server configuration: /mnt/HC_Volume_105148208/vhosts/matomo/.env.old
[Sun Sep 06 01:20:48.929763 2026] [authz_core:error] [pid 550793:tid 550824] [client 34.106.32.58:51548] AH01630: client denied by server configuration: /mnt/HC_Volume_105148208/vhosts/matomo/.env.
...
show less
Brute-Force
🇺🇸
TPI-Abuse
2026-09-06 00:09:52
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.106.32.58 (58.32.106.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.106.32.58 (58.32.106.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 20:09:44.746116 2026] [security2:error] [pid 11731:tid 11791] [client 34.106.32.58:43038] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "officialseniorworldgolfranking.com"] [uri "/.env.dev"] [unique_id "apyvSJsU0UwcvWhlsZppOAAAAcA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇴
jad-abuse
2026-09-05 23:51:05
(2 hours ago)
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: env_probe ...
show more
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: env_probe, source_backup, scanner_ua, actuator, ignition_debug, config_backup. Observed by 1 sensor(s); 26 hits.
show less
Hacking
Web App Attack
🇫🇷
dynamix
2026-09-05 23:01:12
(2 hours ago)
Multiple WAF Violations
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 22:58:32
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.106.32.58 (58.32.106.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.106.32.58 (58.32.106.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 18:58:26.025104 2026] [security2:error] [pid 23051:tid 23051] [client 34.106.32.58:56516] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.secureonebank.net"] [uri "/.env.dev"] [unique_id "apyekqhKfc7sIjQp-s7oNwAAAI8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 22:39:57
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.106.32.58 (58.32.106.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.106.32.58 (58.32.106.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 18:39:49.824265 2026] [security2:error] [pid 24682:tid 24692] [client 34.106.32.58:48078] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ftp.jd-mason.com"] [uri "/wp-config.php.bak"] [unique_id "apyaNXh4BOPFfcuw8ENeGAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
SysAdmin Dylan
2026-09-05 22:22:53
(3 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.106.32.58 (US/United States/58.32.106.34.bc. ...
show more
(mod_security) mod_security (id:210730) triggered by 34.106.32.58 (US/United States/58.32.106.34.bc.googleusercontent.com): 10 in the last 3600 secs
show less
Brute-Force
🇺🇸
TPI-Abuse
2026-09-05 22:22:36
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.106.32.58 (58.32.106.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.106.32.58 (58.32.106.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 18:22:30.636289 2026] [security2:error] [pid 28907:tid 28907] [client 34.106.32.58:47846] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htaccess" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.rwcartoons.com"] [uri "/.htaccess"] [unique_id "apyWJsHdzAMNWbHlBvH2ZAAAAJQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
e.fierstra
2026-09-05 22:13:26
(3 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
🇺🇸
mnsf
2026-09-05 21:05:37
(4 hours ago)
Scanning/Probing (20)
Brute-Force
Web App Attack
🇮🇹
VHosting
2026-09-05 20:40:03
(5 hours ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
🇳🇱
WeCloudit-Anti-Abuse
2026-09-05 20:18:16
(5 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
🇳🇱
Savvii
2026-09-05 07:46:22
(18 hours ago)
15 attempts against mh-modsecurity-ban on steel
Brute-Force
Web App Attack
🇩🇪
Nightreaver
2026-09-05 07:34:48
(18 hours ago)
34.106.32.58 - - [05/Sep/2026:09:34:47 0200] "GET /wp-config.php.bak HTTP/1.1" 404 437 "-" "crusade ...
show more
34.106.32.58 - - [05/Sep/2026:09:34:47 0200] "GET /wp-config.php.bak HTTP/1.1" 404 437 "-" "crusader-worker/1.0"
34.106.32.58 - - [05/Sep/2026:09:34:47 0200] "GET /.env.production HTTP/1.1" 404 437 "-" "crusader-worker/1.0"
34.106.32.58 - - [05/Sep/2026:09:34:47 0200] "GET /.env.example HTTP/1.1" 404 437 "-" "crusader-worker/1.0"
34.106.32.58 - - [05/Sep/2026:09:34:47 0200] "GET /.env.local HTTP/1.1" 404 437 "-" "crusader-worker/1.0"
34.106.32.58 - - [05/Sep/2026:09:34:47 0200] "GET /.env.save HTTP/1.1" 404 437 "-" "crusader-worker/1.0"[...]
show less
Bad Web Bot
Web App Attack