Anonymous
2026-09-01 13:01:02
(19 hours ago)
[da.kdns.gr] httpd-config-scan: logs=/var/log/httpd/access_log; samples=/.env.backup | /.env.save | ...
show more
[da.kdns.gr] httpd-config-scan: logs=/var/log/httpd/access_log; samples=/.env.backup | /.env.save | /.env.bak
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 12:26:40
(20 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.126.173.140 (140.173.126.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.126.173.140 (140.173.126.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 08:26:33.167942 2026] [security2:error] [pid 19542:tid 19542] [client 34.126.173.140:35838] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "carefreesol.com"] [uri "/wp-config.php.bak"] [unique_id "apbEeR_lTORsgSQOjYmfkQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
patrisei
2026-09-01 11:15:20
(21 hours ago)
You are now banned for 10 years by Schiffdorf-West Patrol. Trigger: crowdsecurity/http-sensitive-fil ...
show more
You are now banned for 10 years by Schiffdorf-West Patrol. Trigger: crowdsecurity/http-sensitive-files
show less
Port Scan
Web App Attack
๐ฉ๐ช
FD-IX
2026-09-01 11:10:48
(21 hours ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 11:10:18
(21 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.126.173.140 (140.173.126.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.126.173.140 (140.173.126.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 07:10:14.760430 2026] [security2:error] [pid 9378:tid 9378] [client 34.126.173.140:45682] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.astrology7.com"] [uri "/.env.bak"] [unique_id "apaylrDCwtOYAlNYEjIMVwAAACw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฒ๐พ
Rizzy
2026-09-01 10:18:34
(22 hours ago)
Multiple WAF Violations
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 10:02:18
(22 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.126.173.140 (140.173.126.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.126.173.140 (140.173.126.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 06:02:11.950289 2026] [security2:error] [pid 18384:tid 18396] [client 34.126.173.140:42048] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "frank.aafm.us"] [uri "/.env.bak"] [unique_id "apaio42cWXFxcFZVhtXM9AAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 09:12:57
(23 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.126.173.140 (140.173.126.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.126.173.140 (140.173.126.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 05:12:52.115159 2026] [security2:error] [pid 8010:tid 8010] [client 34.126.173.140:60754] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "168www.merlinaerospace.com"] [uri "/.env.backup"] [unique_id "apaXFIODlQ6ULyIkyTjfPwAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
kkw
2026-09-01 08:27:46
(1 day ago)
[REDACTED] 34.126.173.140 - - [01/Sep/2026:10:27:45 +0200] "GET /.env.bak HTTP/1.1" 301 4693 "-" "cr ...
show more
[REDACTED] 34.126.173.140 - - [01/Sep/2026:10:27:45 +0200] "GET /.env.bak HTTP/1.1" 301 4693 "-" "crusader-worker/1.0"
... (mode: searching http-sensitive-files)
show less
Bad Web Bot
Web App Attack
Anonymous
2026-09-01 08:10:01
(1 day ago)
suspicious request in access.log
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 07:39:15
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.126.173.140 (140.173.126.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.126.173.140 (140.173.126.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 03:39:09.179288 2026] [security2:error] [pid 7273:tid 7273] [client 34.126.173.140:52354] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "yakaloco.tracybur.net"] [uri "/.env"] [unique_id "apaBHWLXOArIYmHePDUWCwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-01 07:10:56
(1 day ago)
(config_exploit_scan) Configuratie Scanner / Nep GPTBot 34.126.173.140 (SG/Singapore/140.173.126.34. ...
show more
(config_exploit_scan) Configuratie Scanner / Nep GPTBot 34.126.173.140 (SG/Singapore/140.173.126.34.bc.googleusercontent.com): 3 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 34.126.173.140 - - [01/Sep/2026:09:10:51 +0200] "GET /.env.dev HTTP/1.1" 406 4831 "-" "crusader-worker/1.0"
34.126.173.140 - - [01/Sep/2026:09:10:51 +0200] "GET /.env.save HTTP/1.1" 406 4832 "-" "crusader-worker/1.0"
34.126.173.140 - - [01/Sep/2026:09:10:51 +0200] "GET /.env HTTP/1.1" 406 4831 "-" "crusader-worker/1.0"
show less
Port Scan
๐บ๐ฆ
URAN Publishing Service
2026-09-01 07:05:15
(1 day ago)
[01/Sep/2026:10:05:14 +0300] -- 34.126.173.140 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.en ...
show more
[01/Sep/2026:10:05:14 +0300] -- 34.126.173.140 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.env.local HTTP/1.1
show less
Bad Web Bot
Web App Attack
๐ฌ๐ง
consul.to
2026-09-01 06:28:39
(1 day ago)
Web attack/malicious scanning detected
Web App Attack
Anonymous
2026-09-01 06:15:58
(1 day ago)
Web application attack detected.
Web App Attack