๐ฉ๐ช
heyzg
2026-08-01 17:04:11
(5 hours ago)
HTTP secret_harvesting (observed): 10 HTTP
Brute-Force
๐ฉ๐ช
ger-stg-sifi1
2026-08-01 17:02:44
(5 hours ago)
(wordpress) Failed wordpress login using wp-login.php or xmlrpc.php
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-01 17:00:56
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.125.191.92 (92.191.125.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.125.191.92 (92.191.125.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 13:00:50.201018 2026] [security2:error] [pid 2252492:tid 2252492] [client 34.125.191.92:58194] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.madisonmedia.ai"] [uri "/.env.backup"] [unique_id "am4mQq20t5JNg3lQhg56wwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-01 16:45:50
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.125.191.92 (92.191.125.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.125.191.92 (92.191.125.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 12:45:44.898348 2026] [security2:error] [pid 31542:tid 31629] [client 34.125.191.92:35910] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "peoplewithai.bertdecoutere.name"] [uri "/.env.example"] [unique_id "am4iuLsh_2N956qOSjAp0wAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
alferez
2026-08-01 16:29:28
(6 hours ago)
Searching .(env|sql|zip|tar|rar) files
Hacking
Exploited Host
Web App Attack
Anonymous
2026-08-01 16:21:03
(6 hours ago)
Bot / scanning and/or hacking attempts: GET /.env.save HTTP/1.1, GET /.env.old HTTP/1.1, GET /.env.d ...
show more
Bot / scanning and/or hacking attempts: GET /.env.save HTTP/1.1, GET /.env.old HTTP/1.1, GET /.env.dev HTTP/1.1, GET /.env.bak HTTP/1.1, GET /.env.example HTTP/1.1, GET /.env.prod HTTP/1.1, GET /.env.local HTTP/1.1, GET /.env.backup HTTP/1.1, GET /.env.production HTTP/1.1, GET /.env HTTP/1.1
show less
Hacking
Web App Attack
๐ฎ๐น
Inartis
2026-08-01 15:41:07
(6 hours ago)
34.125.191.92 - - [01/Aug/2026:17:41:06 +0200] "GET /.env.bak HTTP/1.1" 403 5503 "-" "crusader-worke ...
show more
34.125.191.92 - - [01/Aug/2026:17:41:06 +0200] "GET /.env.bak HTTP/1.1" 403 5503 "-" "crusader-worker/1.0"
34.125.191.92 - - [01/Aug/2026:17:41:06 +0200] "GET /.env HTTP/1.1" 403 5503 "-" "crusader-worker/1.0"
34.125.191.92 - - [01/Aug/2026:17:41:06 +0200] "GET /.env.backup HTTP/1.1" 403 5503 "-" "crusader-worker/1.0"
...
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-01 15:36:55
(6 hours ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
Anonymous
2026-08-01 15:35:34
(6 hours ago)
34.125.191.92 - - [01/Aug/2026:17:35:33 +0200] "GET /.env.old HTTP/1.1" 404 60864 "-" "crusader-work ...
show more
34.125.191.92 - - [01/Aug/2026:17:35:33 +0200] "GET /.env.old HTTP/1.1" 404 60864 "-" "crusader-worker/1.0"
34.125.191.92 - - [01/Aug/2026:17:35:32 +0200] "GET /.env.old HTTP/1.1" 404 61157 "-" "crusader-worker/1.0"
34.125.191.92 - - [01/Aug/2026:17:35:33 +0200] "GET /.env.prod HTTP/1.1" 404 61157 "-" "crusader-worker/1.0"
34.125.191.92 - - [01/Aug/2026:17:35:33 +0200] "GET /.env.prod HTTP/1.1" 404 60872 "-" "crusader-worker/1.0"
34.125.191.92 - - [01/Aug/2026:17:35:33 +0200] "GET /.env.backup HTTP/1.1" 404 60864 "-" "crusader-worker/1.0"
34.125.191.92 - - [01/Aug/2026:17:35:32 +0200] "GET /.env.backup HTTP/1.1" 404 61157 "-" "crusader-worker/1.0"
34.125.191.92 - - [01/Aug/2026:17:35:33 +0200] "GET /.env.dev HTTP/1.1" 404 48790 "-" "crusader-worker/1.0"
34.125.191.92 - - [01/Aug/2026:17:35:33 +0200] "GET /.env.local HTTP/1.1" 404 60864 "-" "crusader-worker/1.0"
34.125.191.92 - - [01/Aug/2026:17:35:32 +0200] "GET /.env.local HTTP/1.1" 404 61157 "-" "crusader-worker/1.0"
34.125.191.92 -
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-08-01 14:05:33
(8 hours ago)
Scanning/Probing (20)
Brute-Force
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-08-01 13:53:20
(8 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-08-01 13:24:45
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.125.191.92 (92.191.125.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.125.191.92 (92.191.125.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 09:24:42.062738 2026] [security2:error] [pid 297898:tid 297898] [client 34.125.191.92:40332] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "fruitsinthedesert.com"] [uri "/.env.old"] [unique_id "am3zmmwrAja8EyBjspi8ywAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
4server
2026-08-01 13:12:23
(9 hours ago)
[SatAug0115:12:16.7012922026][security2:error][pid3601434:tid3601649][client34.125.191.92:0]ModSecur ...
show more
[SatAug0115:12:16.7012922026][security2:error][pid3601434:tid3601649][client34.125.191.92:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\".env\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"365\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"mdd-network.ch\"][uri\"/.env.bak\"][unique_id\"am3wsJyWI70V2cKpdy02-wAAAFQ\"]
show less
Hacking
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-08-01 13:11:24
(9 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐ฉ๐ช
barbarella
2026-08-01 12:59:53
(9 hours ago)
Multiple (10) times attack on https port 443: Configuration snooping in .env file (GET /.env.example ...
show more
Multiple (10) times attack on https port 443: Configuration snooping in .env file (GET /.env.example)
14:59:53 Configuration snooping in .env file (GET /.env.production)
14:59:53 Configuration snooping in .env file (GET /.env.save)
14:59:53 Configuration snooping in .env file (GET /.env.old)
14:59:53 Configuration snooping in .env file (GET /.env)
14:59:53 Configuration snooping in .env file (GET /.env.local)
14:59:53 Configuration snooping in .env file (GET /.env.dev)
14:59:53 Configuration snooping in .env file (GET /.env.prod)
14:59:53 Configuration snooping in .env file (GET /.env.bak)
show less
Hacking
Web App Attack