🇧🇾
lns.bz
2026-09-05 07:43:05
(7 hours ago)
.env scanning [BY]
Web App Attack
🇫🇷
Baking333
2026-09-05 07:04:53
(8 hours ago)
[redacted] 34.14.68.199 - - [05/Sep/2026:08:04:50 +0100] "GET /.[redacted] HTTP/1.1" 307 5690 "-" "c ...
show more
[redacted] 34.14.68.199 - - [05/Sep/2026:08:04:50 +0100] "GET /.[redacted] HTTP/1.1" 307 5690 "-" "crusader-worker/1.0" [redacted] 34.14.68.199 - - [05/Sep/2026:08:04:50 +0100] "GET /.[redacted] HTTP/1.1" 307 5690 "-" "crusader-worker/1.0"
show less
Bad Web Bot
Web App Attack
Anonymous
2026-09-05 06:41:23
(8 hours ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack
🇫🇷
pm33
2026-09-05 04:25:37
(10 hours ago)
Wordpress login attempts
Brute-Force
🇺🇸
TPI-Abuse
2026-09-04 14:15:27
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.14.68.199 (199.68.14.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.14.68.199 (199.68.14.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 10:15:23.170896 2026] [security2:error] [pid 11290:tid 11290] [client 34.14.68.199:48674] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "wokedreamer.com"] [uri "/wp-config.php.bak"] [unique_id "aprSe55xKIC8nmZDRdQR7QAAAEE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
Interceptor_HQ
2026-09-04 13:44:58
(1 day ago)
request_uri: /wp-config.php~ -- automatic report --
Brute-Force
Hacking
🇬🇧
blik2108
2026-09-04 13:33:18
(1 day ago)
34.14.68.199 - - [04/Sep/2026:13:33:16 +0000] "GET /.env HTTP/1.1" 404 3431 "-" "crusader-worker/1.0 ...
show more
34.14.68.199 - - [04/Sep/2026:13:33:16 +0000] "GET /.env HTTP/1.1" 404 3431 "-" "crusader-worker/1.0" "-"
34.14.68.199 - - [04/Sep/2026:13:33:16 +0000] "GET /.env.production HTTP/1.1" 404 3431 "-" "crusader-worker/1.0" "-"
34.14.68.199 - - [04/Sep/2026:13:33:16 +0000] "GET /.env.backup HTTP/1.1" 404 3431 "-" "crusader-worker/1.0" "-"
34.14.68.199 - - [04/Sep/2026:13:33:16 +0000] "GET /_ignition/health-check HTTP/1.1" 404 3431 "-" "crusader-worker/1.0" "-"
34.14.68.199 - - [04/Sep/2026:13:33:16 +0000] "GET /.env.prod HTTP/1.1" 404 3431 "-" "crusader-worker/1.0" "-"
34.14.68.199 - - [04/Sep/2026:13:33:16 +0000] "GET /.env.old HTTP/1.1" 404 3431 "-" "crusader-worker/1.0" "-"
34.14.68.199 - - [04/Sep/2026:13:33:17 +0000] "GET /.env.local HTTP/1.1" 404 3431 "-" "crusader-worker/1.0" "-"
34.14.68.199 - - [04/Sep/2026:13:33:17 +0000] "GET /.env.dev HTTP/1.1" 404 3431 "-" "crusader-worker/1.0" "-"
...
show less
Web App Attack
🇩🇪
Vegascosmetics
2026-09-04 12:51:20
(1 day ago)
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after matched multi-pattern attack signatur ...
show more
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after matched multi-pattern attack signature. Evidence: AttackPattern: /env\s (Match: /env )
show less
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 12:46:38
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.14.68.199 (199.68.14.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.14.68.199 (199.68.14.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 08:46:32.440732 2026] [security2:error] [pid 23321:tid 23321] [client 34.14.68.199:48398] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "armstrongpartnersllc.com.ssl-grp.com"] [uri "/.env.example"] [unique_id "apq9qGQOkZsdwLo9uweFtQAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
LRob
2026-09-04 11:58:53
(1 day ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /wp-config.php.swp (+12 more) | 2026-09-04 11:58 UTC
show less
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 11:45:26
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.14.68.199 (199.68.14.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.14.68.199 (199.68.14.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 07:45:21.429643 2026] [security2:error] [pid 7304:tid 7304] [client 34.14.68.199:54104] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.30daysout.com"] [uri "/wp-config.php~"] [unique_id "apqvUdzJX1gMIzv2kpR6TgAAACk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 10:34:03
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.14.68.199 (199.68.14.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.14.68.199 (199.68.14.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 06:33:56.240073 2026] [security2:error] [pid 21827:tid 21827] [client 34.14.68.199:59940] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "amfa76.com"] [uri "/.env.bak"] [unique_id "apqelC9O9AQnTw_7PXxcUwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 10:04:53
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.14.68.199 (199.68.14.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.14.68.199 (199.68.14.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 06:04:46.020478 2026] [security2:error] [pid 22668:tid 22668] [client 34.14.68.199:53648] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.oligofoundry.com"] [uri "/.env.dev"] [unique_id "apqXvv4czrgCJkGVv1q6jwAAACI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇿🇦
conure.sh
2026-09-04 10:04:21
(1 day ago)
csagent: score 20.0: secrets grab x2; 1 domain(s) in 0s
Web App Attack
🇺🇸
CBJ
2026-09-04 09:25:25
(1 day ago)
fail2ban: apache-filepath-recon
...
Web App Attack