Anonymous
2026-09-06 10:27:32
(12 hours ago)
Fail2Ban: repeated malicious HTTP requests (path probing / exploit attempts) against a public web se ...
show more
Fail2Ban: repeated malicious HTTP requests (path probing / exploit attempts) against a public web server.
show less
Web App Attack
Bad Web Bot
🇧🇾
lns.bz
2026-09-06 06:27:18
(16 hours ago)
.env scanning [BY]
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 03:54:37
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.146.151.183 (183.151.146.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.146.151.183 (183.151.146.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 23:54:29.832528 2026] [security2:error] [pid 18832:tid 18832] [client 34.146.151.183:37728] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.outofthebluephotography.com"] [uri "/.env.production"] [unique_id "apzj9ebGDXMAtt7ilEVYrAAAAGY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 03:03:03
(20 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.146.151.183 (183.151.146.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.146.151.183 (183.151.146.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 23:03:00.002399 2026] [security2:error] [pid 1281:tid 1281] [client 34.146.151.183:56926] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.southernreader.com"] [uri "/.env.example"] [unique_id "apzX5HQSPII9PaxQ9k5SLQAAACQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇵🇱
mscode.pl
2026-09-06 03:02:47
(20 hours ago)
Triggered Cloudflare WAF (firewallCustom) from JP.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Prot ...
show more
Triggered Cloudflare WAF (firewallCustom) from JP.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Protocol: HTTP/1.1 (GET method)
Zone: wiki.mscode.pl
Endpoint: /
UA: crusader-worker/1.0
show less
Bad Web Bot
🇬🇧
consul.to
2026-09-06 02:35:43
(20 hours ago)
Web attack/malicious scanning detected
Web App Attack
🇳🇱
WeCloudit-Anti-Abuse
2026-09-06 02:02:56
(21 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
🇫🇷
ELYAZ
2026-09-06 01:58:23
(21 hours ago)
(y3) Failed access -byebye- from 34.146.151.183 (JP/Japan/183.151.146.34.bc.googleusercontent.com): ...
show more
(y3) Failed access -byebye- from 34.146.151.183 (JP/Japan/183.151.146.34.bc.googleusercontent.com): (CF_ENABLE)
show less
Hacking
🇩🇪
Hans Wurst
2026-09-06 01:47:29
(21 hours ago)
Many 404-Error: Suspicion of URL-Fuzzing/Bot-Scan.
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 01:08:43
(21 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.146.151.183 (183.151.146.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.146.151.183 (183.151.146.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 21:08:36.092761 2026] [security2:error] [pid 4714:tid 4714] [client 34.146.151.183:52430] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.restaurantfixture.com"] [uri "/.env.local"] [unique_id "apy9FHl3Iw_GTgGuw6jcZwAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 00:40:24
(22 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.146.151.183 (183.151.146.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.146.151.183 (183.151.146.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 20:40:18.053415 2026] [security2:error] [pid 9764:tid 9764] [client 34.146.151.183:45610] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "holtzheimer.buynorthwest.com"] [uri "/.env.dev"] [unique_id "apy2ciXkebaKoun-bJTacwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-06 00:15:47
(22 hours ago)
[server.tmg.gr] httpd-config-scan: sites=www.ikee.gr; logs=/var/log/httpd/domains/ikee.gr.log; sampl ...
show more
[server.tmg.gr] httpd-config-scan: sites=www.ikee.gr; logs=/var/log/httpd/domains/ikee.gr.log; samples=/.env | /.env.local | /.env.production
show less
Hacking
Web App Attack
Anonymous
2026-09-06 00:07:26
(22 hours ago)
34.146.151.183 - - [06/Sep/2026:00:07:25 +0000] "GET /.env.old HTTP/1.1" 302 4928 "-" "crusader-work ...
show more
34.146.151.183 - - [06/Sep/2026:00:07:25 +0000] "GET /.env.old HTTP/1.1" 302 4928 "-" "crusader-worker/1.0"
...
show less
Bad Web Bot
Web App Attack
🇳🇱
e.fierstra
2026-09-06 00:05:10
(22 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 23:56:30
(23 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.146.151.183 (183.151.146.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.146.151.183 (183.151.146.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 19:56:26.725970 2026] [security2:error] [pid 10242:tid 10242] [client 34.146.151.183:52810] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.tracytappan.net"] [uri "/.env.backup"] [unique_id "apysKrIno9PjgvuEDx7BTAAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack