🇺🇸
TPI-Abuse
2026-09-06 03:53:39
(21 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.138.214.80 (80.214.138.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.138.214.80 (80.214.138.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 23:53:33.226051 2026] [security2:error] [pid 646:tid 646] [client 34.138.214.80:33268] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.happythanksgivingcards.com"] [uri "/.env.production"] [unique_id "apzjvUtg6QSRB-WraFWGKgAAAIY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
✨
2026-09-06 03:34:14
(22 hours ago)
Domain : cherrybites.co.za
Rule : env
2026-09-06 03:32:02 ***hidden-privacy*** GET /.env.dev - 443 - ...
show more
Domain : cherrybites.co.za
Rule : env
2026-09-06 03:32:02 ***hidden-privacy*** GET /.env.dev - 443 - 34.138.214.80 HTTP/1.1 crusader-worker/1.0 - cherrybites.co.za 500 0 64 0 97 1514 - -
show less
Hacking
SQL Injection
Anonymous
2026-09-06 03:17:06
(22 hours ago)
Blocked by ModSec and CSF
Port Scan
🇩🇪
NihiliousMonk
2026-09-06 02:54:46
(22 hours ago)
Fail2Ban report from jail npm-scanners
Bad Web Bot
Web App Attack
🇺🇸
1cyb3rpunk
2026-09-06 02:11:33
(23 hours ago)
Coordinated campaign CMP-1786835248-000: 580 IPs sharing an attack fingerprint (admin_panel_probe, a ...
show more
Coordinated campaign CMP-1786835248-000: 580 IPs sharing an attack fingerprint (admin_panel_probe, asset_directory_probe, attacker_objective_inferred, aws_creds_file_probe, aws_imds_probe, backup_file_probe). Observed on sectrace.org honeypot surface.
show less
Port Scan
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
FeG Deutschland
2026-09-06 02:00:42
(23 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 01:46:10
(23 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.138.214.80 (80.214.138.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.138.214.80 (80.214.138.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 21:46:05.473226 2026] [security2:error] [pid 7143:tid 7143] [client 34.138.214.80:38870] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "gkwire.com"] [uri "/.env.backup"] [unique_id "apzF3SxiP5qULfCOiVli1wAAAD0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
raph
2026-09-06 00:37:00
(1 day ago)
[DOT FILES] crawler *.env*, .git*, .config*, etc.
Bad Web Bot
Web App Attack
🇩🇪
LRob
2026-09-06 00:26:08
(1 day ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /.env.backup (+12 more) | 2026-09-06 00:26 UTC
show less
Hacking
Web App Attack
🇩🇪
MarkGGN
2026-09-06 00:21:34
(1 day ago)
Web attack. 34.138.214.80 - - [06/Sep/2026:02:21:34 +0200] "GET /wp-config.php.bak HTTP/1.1" 404 27 ...
show more
Web attack. 34.138.214.80 - - [06/Sep/2026:02:21:34 +0200] "GET /wp-config.php.bak HTTP/1.1" 404 27 "-" "crusader-worker/1.0"
34.138.214.80 - - [06/Sep/2026:02:21:34 +0200] "GET /wp-config.php.swp HTTP/1.1" 404 27 "-" "crusader-worker/1.0"
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 23:31:27
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.138.214.80 (80.214.138.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.138.214.80 (80.214.138.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 19:31:21.616820 2026] [security2:error] [pid 2393:tid 2393] [client 34.138.214.80:48374] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.jerryfeil.com"] [uri "/.env"] [unique_id "apymSRYCmW_UiKu3wtgDpgAAACE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
mnsf
2026-09-05 23:05:34
(1 day ago)
Scanning/Probing (20)
Brute-Force
Web App Attack
Anonymous
2026-09-05 22:49:16
(1 day ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-05 22:43:43
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.138.214.80 (80.214.138.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.138.214.80 (80.214.138.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 18:43:36.252379 2026] [security2:error] [pid 30310:tid 30310] [client 34.138.214.80:51006] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "inquisitivequincie.com"] [uri "/.env.example"] [unique_id "apybGGJ70eq9rPnQpn7FJAAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
Hazzard
2026-09-05 22:12:55
(1 day ago)
(mod_security) mod_security triggered on hostname [redacted]): (CF_ENABLE)
SQL Injection