🇩🇪
LRob
2026-09-04 11:25:24
(32 minutes ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /wp-config.php.bak (+10 more) | 2026-09-04 11:25 UTC
show less
Hacking
Web App Attack
🇸🇪
vaia.cloud
2026-09-04 10:25:04
(1 hour ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 10:24:18
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.150.14.94 (94.14.150.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.150.14.94 (94.14.150.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 06:24:14.597009 2026] [security2:error] [pid 12412:tid 12412] [client 34.150.14.94:58126] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ohiobabe.com"] [uri "/.env"] [unique_id "apqcTjsbNtVEY9ceqa-YywAAADg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇨🇭
4server
2026-09-04 10:15:51
(1 hour ago)
[FriSep0412:15:47.7750152026][security2:error][pid187129:tid187382][client34.150.14.94:0]ModSecurity ...
show more
[FriSep0412:15:47.7750152026][security2:error][pid187129:tid187382][client34.150.14.94:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\".env\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"610\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"janus-advisory.ch.81-17-25-250.cpanel.site\"][uri\"/.env.backup\"][unique_id\"apqaU9NSz3wv8EK78gVf6gAAAQg\"]
show less
Hacking
Web App Attack
🇭🇺
DumaNet
2026-09-04 09:58:00
(2 hours ago)
Web app attack attempts, scanning for vulnerability.
Date: 2026 Sep 04. 10:07:16
Source IP: 34.150 ...
show more
Web app attack attempts, scanning for vulnerability.
Date: 2026 Sep 04. 10:07:16
Source IP: 34.150.14.94
Portion of the log(s):
34.150.14.94 - [04/Sep/2026:10:07:16 +0200] "GET /.env.backup HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
34.150.14.94 - [04/Sep/2026:10:07:16 +0200] "GET /storage/logs/laravel.log HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
34.150.14.94 - [04/Sep/2026:10:07:16 +0200] "GET /_ignition/health-check HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
34.150.14.94 - [04/Sep/2026:10:07:16 +0200] "GET /actuator/configprops HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
34.150.14.94 - [04/Sep/2026:10:07:16 +0200] "GET /.env.save HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
34.150.14.94 - [04/Sep/2026:10:07:16 +0200] "GET /.env.production HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
34.150.14.94 - [04/Sep/2026:10:07:16 +0200] "GET /.env.prod HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
34.150.14.94 - [04/Sep/2026:10:07:16 +0200] "GET /crusader-404-probe HTTP/1.1" 404 153 "-" "crusader-worker
show less
Web App Attack
🇮🇩
sockominfo
2026-09-04 09:00:29
(2 hours ago)
Reported by TangerangKota-CSIRT. Status: MALICIOUS
Hacking
Email Spam
🇺🇸
TPI-Abuse
2026-09-04 08:22:02
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.150.14.94 (94.14.150.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.150.14.94 (94.14.150.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 04:21:57.070199 2026] [security2:error] [pid 26575:tid 26575] [client 34.150.14.94:38998] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.the-schlosser.net"] [uri "/wp-config.php~"] [unique_id "app_pXG7KPIPfEQkwPPDiAAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇧🇾
lns.bz
2026-09-04 07:57:24
(4 hours ago)
Too many 404 requests [BY]
Web App Attack
🇳🇱
WeCloudit-Anti-Abuse
2026-09-04 07:35:40
(4 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-04 07:28:47
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.150.14.94 (94.14.150.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.150.14.94 (94.14.150.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 03:28:40.305646 2026] [security2:error] [pid 8091:tid 8091] [client 34.150.14.94:38278] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bryteandbroderick.webserviceswest.com"] [uri "/wp-config.php~"] [unique_id "appzKLduoeEuLHH_lVfZ-QAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇲🇾
Rizzy
2026-09-04 07:05:31
(4 hours ago)
Multiple WAF Violations
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 06:00:13
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.150.14.94 (94.14.150.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.150.14.94 (94.14.150.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 02:00:07.312451 2026] [security2:error] [pid 25401:tid 25401] [client 34.150.14.94:60434] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.jfexpressfr8.com"] [uri "/.env.example"] [unique_id "appeZ9Yp2b_EFabaREo-6gAAAEY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇮🇹
VHosting
2026-09-04 06:00:05
(5 hours ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
Anonymous
2026-09-04 04:47:45
(7 hours ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack
🇵🇱
mscode.pl
2026-09-04 04:04:49
(7 hours ago)
Triggered Cloudflare WAF (firewallCustom) from HK.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Prot ...
show more
Triggered Cloudflare WAF (firewallCustom) from HK.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Protocol: HTTP/1.1 (GET method)
Zone: tickets.mscode.pl
Endpoint: /
UA: crusader-worker/1.0
show less
Bad Web Bot