๐ณ๐ฑ
homeshowdomain.nl
2026-09-23 22:03:40
(25 minutes ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-09-22.
show less
Web App Attack
SSH
Hacking
๐ต๐ฑ
sefinek.net
2026-09-22 16:58:24
(1 day ago)
Triggered Cloudflare WAF (firewallCustom) from IN.
Action: BLOCK | Protocol: HTTP/1.1 (GET) | Endpoi ...
show more
Triggered Cloudflare WAF (firewallCustom) from IN.
Action: BLOCK | Protocol: HTTP/1.1 (GET) | Endpoint: /.env. | UA: crusader-worker/1.0 โข Generated by: github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐ฉ๐ช
ddobko
2026-09-22 16:15:55
(1 day ago)
Bad Web Bot
Web App Attack
Anonymous
2026-09-22 15:53:25
(1 day ago)
GET /.env.save HTTP/1.1
...
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 15:35:53
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.14.163.14 (14.163.14.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.14.163.14 (14.163.14.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 11:35:49.871503 2026] [security2:error] [pid 2166:tid 2166] [client 34.14.163.14:34544] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ngm.office-on-the.net"] [uri "/wp-config.php.swp"] [unique_id "arKgVfdELDcKnvg35WqY4QAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
pltcldvlpr
2026-09-22 15:32:40
(1 day ago)
CMS/framework probe: 34.14.163.14 - - [22/Sep/2026:17:32:39 +0200] "GET /wp-config.php~ HTTP/1.1" 40 ...
show more
CMS/framework probe: 34.14.163.14 - - [22/Sep/2026:17:32:39 +0200] "GET /wp-config.php~ HTTP/1.1" 404 162 "-" "crusader-worker/1.0" asn=396982 org="Google LLC" country=IN
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 15:19:56
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.14.163.14 (14.163.14.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.14.163.14 (14.163.14.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 11:19:52.742109 2026] [security2:error] [pid 10926:tid 10926] [client 34.14.163.14:46482] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mrccertification.com"] [uri "/.env.example"] [unique_id "arKcmP8itwBhknUAwwTNQAAAAEI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 14:56:52
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.14.163.14 (14.163.14.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.14.163.14 (14.163.14.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 10:56:47.160879 2026] [security2:error] [pid 17805:tid 17878] [client 34.14.163.14:38220] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.thebiglies.com"] [uri "/.env.backup"] [unique_id "arKXLwve4LolRg2B5dM0CgAAAUU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐ฑ
router.al
2026-09-22 14:55:21
(1 day ago)
09/22/2026-14:55:21.625187 34.14.163.14 Protocol: 6 ET WEB_SERVER Tilde in URI - potential .php~ sou ...
show more
09/22/2026-14:55:21.625187 34.14.163.14 Protocol: 6 ET WEB_SERVER Tilde in URI - potential .php~ source disclosure vulnerability
show less
Hacking
๐ฉ๐ช
FD-IX
2026-09-22 14:54:02
(1 day ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-22 13:38:46
(1 day ago)
[ti-02al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-02al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 34.14.163.14 - - [22/Sep/2026:15:38:41 +0200] "GET /.env.bak HTTP/2.0" 403 87 "-" "crusader-worker/1.0"
...
show less
Bad Web Bot
Web App Attack
๐ฆ๐บ
2000cn.com.au
2026-09-22 13:23:41
(1 day ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐ฉ๐ช
Melle
2026-09-22 12:29:08
(1 day ago)
Blocked by CrowdSec | Scenario: crowdsecurity/http-sensitive-files | 34.14.163.14 triggered 5 events ...
show more
Blocked by CrowdSec | Scenario: crowdsecurity/http-sensitive-files | 34.14.163.14 triggered 5 events | Detected: 2026-09-22T12:29:06.878402329Z
show less
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-22 11:43:28
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.14.163.14 (14.163.14.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.14.163.14 (14.163.14.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 07:43:21.960333 2026] [security2:error] [pid 619217:tid 619217] [client 34.14.163.14:43716] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cor-ex.com"] [uri "/.env.old"] [unique_id "arJp2WAa8vn5BrYKoqc6TAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
oja
2026-09-22 11:36:15
(1 day ago)
Aggressive web scanner
Web App Attack