π³π±
homeshowdomain.nl
2026-08-28 22:01:21
(2 days ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-08-27.
show less
Web App Attack
SSH
Hacking
Anonymous
2026-08-27 19:30:13
(3 days ago)
| Suspicious URL access.
Web App Attack
Hacking
SQL Injection
π¨π
zynex
2026-08-27 18:43:45
(3 days ago)
URL Probing: /.env
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-27 18:21:47
(3 days ago)
(mod_security) mod_security (id:949110) triggered by 34.138.203.153 (153.203.138.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:949110) triggered by 34.138.203.153 (153.203.138.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 14:21:41.568216 2026] [security2:error] [pid 24711:tid 24711] [client 34.138.203.153:57246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "nevawade.com"] [uri "/.env.backup"] [unique_id "apCANfV4N-Y9Af5IFLtCPgAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π«π·
COMAITE
2026-08-27 18:11:43
(3 days ago)
Suspicious URL access.
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-27 17:45:48
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.138.203.153 (153.203.138.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.138.203.153 (153.203.138.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 13:45:44.172698 2026] [security2:error] [pid 18424:tid 18424] [client 34.138.203.153:46704] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.aeongames.com"] [uri "/.env.save"] [unique_id "apB3yHtfr4IGd20G-mK0YgAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-27 17:06:10
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.138.203.153 (153.203.138.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.138.203.153 (153.203.138.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 13:06:06.393955 2026] [security2:error] [pid 16188:tid 16188] [client 34.138.203.153:50498] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.ava-world.com"] [uri "/.env.bak"] [unique_id "apBufpiyybGNLU3tKEf4ewAAAC4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-27 16:58:42
(3 days ago)
Banned by Fail2Ban on server
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-27 16:42:19
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.138.203.153 (153.203.138.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.138.203.153 (153.203.138.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 12:42:14.166682 2026] [security2:error] [pid 30184:tid 30184] [client 34.138.203.153:43964] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "deckmasterscompany.com"] [uri "/.env.old"] [unique_id "apBo5lTtWMD901KLsXnnTwAAADE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-27 15:57:29
(3 days ago)
34.138.203.153 - - [27/Aug/2026:10:57:28 -0500] "GET /.env.production HTTP/1.1" 403 199 "-" "crusade ...
show more
34.138.203.153 - - [27/Aug/2026:10:57:28 -0500] "GET /.env.production HTTP/1.1" 403 199 "-" "crusader-worker/1.0" 104.22.56.141
34.138.203.153 - - [27/Aug/2026:10:57:28 -0500] "GET /.env.bak HTTP/1.1" 403 199 "-" "crusader-worker/1.0" 104.22.56.140
34.138.203.153 - - [27/Aug/2026:10:57:28 -0500] "GET /.env.prod HTTP/1.1" 403 199 "-" "crusader-worker/1.0" 104.22.56.141
34.138.203.153 - - [27/Aug/2026:10:57:28 -0500] "GET /.env.old HTTP/1.1" 403 199 "-" "crusader-worker/1.0" 104.22.1.237
34.138.203.153 - - [27/Aug/2026:10:57:28 -0500] "GET /.env.dev HTTP/1.1" 403 199 "-" "crusader-worker/1.0" 104.22.1.237
34.138.203.153 - - [27/Aug/2026:10:57:28 -0500] "GET /.env.local HTTP/1.1" 403 199 "-" "crusader-worker/1.0" 104.22.56.140
34.138.203.153 - - [27/Aug/2026:10:57:28 -0500] "GET /.env.example HTTP/1.1" 403 199 "-" "crusader-worker/1.0" 104.22.56.140
34.138.203.153 - - [27/Aug/2026:10:57:28 -0500] "GET /.env.backup HTTP/1.1" 403 199 "-" "crusader-worker/1.0" 104.22.24.183
34.138.203.153 -
...
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
WeCloudit-Anti-Abuse
2026-08-27 15:31:59
(3 days ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
πΊπΈ
TPI-Abuse
2026-08-27 15:29:08
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.138.203.153 (153.203.138.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.138.203.153 (153.203.138.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 11:29:02.861619 2026] [security2:error] [pid 13213:tid 13213] [client 34.138.203.153:53950] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.jewelcraft.dewsales.com"] [uri "/.env.production"] [unique_id "apBXvrjb20fcz6S2P-etTAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΈπͺ
vaia.cloud
2026-08-27 14:40:04
(3 days ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-27 14:12:03
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.138.203.153 (153.203.138.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.138.203.153 (153.203.138.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 10:11:56.590581 2026] [security2:error] [pid 15873:tid 15894] [client 34.138.203.153:35184] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.mirawaresolutions.michaelrandon.com"] [uri "/.env.backup"] [unique_id "apBFrOsA1x8tugfxoFnJLQAAAJI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
mnsf
2026-08-27 14:05:58
(3 days ago)
Scanning/Probing (20)
Brute-Force
Web App Attack