🇫🇷
masterguru
2026-09-04 10:50:22
(1 hour ago)
URL file extension is restricted by policy. String match within ".ani/ .asa/ .asax/ .ascx/ .backup/ ...
show more
URL file extension is restricted by policy. String match within ".ani/ .asa/ .asax/ .ascx/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .compositefont/ .config/ .conf/ .crt/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dist/ .dll/ .dos/ .dpkg-dist/ .drv/ .gadget/ .hta/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .inf/ .ini/ .jse/ .key/ .licx/ .lnk/ .log/ .mdb/ .msc/ .ocx/ .old/ .pass/ .pdb/ .pfx/ .pif/ .pem/ .pol/ .prf/ .printer/ .pwd/ .rdb/ .rdp/ .reg/ .resources/ .resx/ .scr/ .sct/ .shs/ .sql/ .swp/ .sys/ .tlb/ .tmp/ .url/ .vb/ .vbe/ .vbs/ .vbproj/ .vsdisco/ .vxd/ .webinfo/ .ws/ .wsc/ .wsf/ .wsh/ .xsd/ .xsx/" at TX:extension. (920440-196)
show less
Hacking
🇺🇸
WizardsToolkit
2026-09-04 07:56:17
(3 hours ago)
tried to access forbidden files; attempted to access /storage/logs/laravel.log
Web App Attack
🇩🇪
ISPLtd
2026-09-04 05:48:15
(6 hours ago)
Sep 4 02:48:13 34.11.107.6 TCP SPT=49882 DPT=80 SYN
Sep 4 02:48:13 34.11.107.6 TCP SPT=49908 DPT=8 ...
show more
Sep 4 02:48:13 34.11.107.6 TCP SPT=49882 DPT=80 SYN
Sep 4 02:48:13 34.11.107.6 TCP SPT=49908 DPT=80 SYN
Sep 4 02:48:13 34.11.107.6 TCP SPT=49896 DPT=80 SYN
Sep 4 02
...
show less
DDoS Attack
🇬🇧
consul.to
2026-09-04 05:47:05
(6 hours ago)
Web attack/malicious scanning detected
Web App Attack
🇸🇪
vaia.cloud
2026-09-04 05:10:04
(6 hours ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
🇮🇳
evicky2002
2026-08-31 00:01:03
(4 days ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
🇸🇪
SkyDancer
2026-08-30 01:46:30
(5 days ago)
Multiple unauthorized attempts to access using wrong credentials. Attack automatically blocked by Sk ...
show more
Multiple unauthorized attempts to access using wrong credentials. Attack automatically blocked by SkyDancer Ai. EXT-SYS-Vx
show less
Hacking
Brute-Force
SSH
🇺🇸
helios.live
2026-08-29 03:38:36
(6 days ago)
2026/08/29 03:38:35 [error] 2630220#2630220: *1469296 access forbidden by rule, client: 34.11.107.6, ...
show more
2026/08/29 03:38:35 [error] 2630220#2630220: *1469296 access forbidden by rule, client: 34.11.107.6, server: kocervpn.com, request: "GET /.env.local HTTP/1.1", host: "kocervpn.com"
2026/08/29 03:38:35 [error] 2630220#2630220: *1469296 access forbidden by rule, client: 34.11.107.6, server: kocervpn.com, request: "GET /.env HTTP/1.1", host: "kocervpn.com"
2026/08/29 03:38:35 [error] 2630220#2630220: *1469296 access forbidden by rule, client: 34.11.107.6, server: kocervpn.com, request: "GET /.env.production HTTP/1.1", host: "kocervpn.com"
2026/08/29 03:38:35 [error] 2630220#2630220: *1470143 access forbidden by rule, client: 34.11.107.6, server: kocervpn.com, request: "GET /.env.example HTTP/1.1", host: "kocervpn.com"
2026/08/29 03:38:35 [error] 2630220#2630220: *1470143 access forbidden by rule, client: 34.11.107.6, server: kocervpn.com, request: "GET /.env.bak HTTP/1.1", host: "kocervpn.com"
...
show less
Web App Attack
Anonymous
2026-08-29 03:16:55
(6 days ago)
GET /.env.bak HTTP/1.1
...
Web App Attack
🇮🇩
Burayot
2026-08-29 03:02:12
(6 days ago)
LF_MODSEC: (mod_security) mod_security (id:949110) triggered by 34.11.107.6 (US/United States/6.107. ...
show more
LF_MODSEC: (mod_security) mod_security (id:949110) triggered by 34.11.107.6 (US/United States/6.107.11.34.bc.googleusercontent.com): 2 in the last 3600 secs
show less
Web App Attack
🇮🇹
Inartis
2026-08-29 02:48:45
(6 days ago)
34.11.107.6 - - [29/Aug/2026:04:48:43 +0200] "GET /.env.old HTTP/1.1" 404 47669 "-" "crusader-worker ...
show more
34.11.107.6 - - [29/Aug/2026:04:48:43 +0200] "GET /.env.old HTTP/1.1" 404 47669 "-" "crusader-worker/1.0"
34.11.107.6 - - [29/Aug/2026:04:48:43 +0200] "GET /.env.production HTTP/1.1" 404 47685 "-" "crusader-worker/1.0"
34.11.107.6 - - [29/Aug/2026:04:48:43 +0200] "GET /.env.example HTTP/1.1" 404 47677 "-" "crusader-worker/1.0"
...
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-29 02:07:38
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 34.11.107.6 (6.107.11.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.11.107.6 (6.107.11.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 22:07:31.533260 2026] [security2:error] [pid 282146:tid 282162] [client 34.11.107.6:49970] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.mjkotob.com.oplconnect.com"] [uri "/.env.production"] [unique_id "apI-4wNfDYkvhC1rmnp7lwAAAQw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-29 01:48:13
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 34.11.107.6 (6.107.11.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.11.107.6 (6.107.11.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 21:48:06.943862 2026] [security2:error] [pid 30702:tid 30702] [client 34.11.107.6:48178] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.mexicanfriedicecreammix.lemontreefoods.com"] [uri "/.env.save"] [unique_id "apI6Vmb-KcvNIkq285I-VAAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
✨
2026-08-29 01:18:20
(6 days ago)
Domain : pleskcontrolpanel
Rule : env
2026-08-29 01:17:14 79.171.34.94 GET /.env - 8880 - 34.11.107. ...
show more
Domain : pleskcontrolpanel
Rule : env
2026-08-29 01:17:14 79.171.34.94 GET /.env - 8880 - 34.11.107.6 crusader-worker/1.0 - 404 0 2 79 - -
show less
Hacking
SQL Injection
🇬🇧
andypiper
2026-08-29 01:00:28
(6 days ago)
CrowdSec ban for AbuseIPDB Top List
Brute-Force
Web App Attack