๐ซ๐ท
SpaceHost-Server
2026-09-02 22:22:14
(2 weeks ago)
Brute-Force
Web App Attack
๐ซ๐ท
SpaceHost-Server
2026-09-01 22:21:37
(2 weeks ago)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 11:05:56
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 34.158.18.104 (104.18.158.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.158.18.104 (104.18.158.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 07:05:48.978183 2026] [security2:error] [pid 31805:tid 31805] [client 34.158.18.104:43246] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.scrunchiebutt.com"] [uri "/.env.example"] [unique_id "apaxjEs3WVb3JlKTgSuynQAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob
2026-09-01 10:54:55
(2 weeks ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /.env.dev (+12 more) | 2026-09-01 10:54 UTC
show less
Hacking
Web App Attack
Anonymous
2026-09-01 10:47:50
(2 weeks ago)
(mod_security) mod_security triggered on hostname [redacted] 34.158.18.104 (CH/Switzerland/104.18.15 ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.158.18.104 (CH/Switzerland/104.18.158.34.bc.googleusercontent.com)
show less
SQL Injection
๐ฏ๐ต
VXG-NET
2026-09-01 09:25:28
(2 weeks ago)
port=80, indicator_type=info-leak
Hacking
๐จ๐ญ
4server
2026-09-01 09:21:09
(2 weeks ago)
[TueSep0111:21:04.2826482026][security2:error][pid2674470:tid2674813][client34.158.18.104:0]ModSecur ...
show more
[TueSep0111:21:04.2826482026][security2:error][pid2674470:tid2674813][client34.158.18.104:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\"wp-config\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"610\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"supporto-ticino.ch\"][uri\"/wp-config.php~\"][unique_id\"apaZAD71I33MbiJqfg963gAAARQ\"]
show less
Hacking
Web App Attack
๐ฆ๐บ
FireGuard Server
2026-09-01 08:35:07
(2 weeks ago)
Blocked by os-abuseipdb; 74 hits, proto=tcp, ports=443
Port Scan
Hacking
Anonymous
2026-09-01 07:50:02
(2 weeks ago)
suspicious request in access.log
Web App Attack
๐ธ๐ช
vaia.cloud
2026-09-01 07:25:02
(2 weeks ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
๐ฉ๐ช
XICTRON
2026-09-01 06:40:09
(2 weeks ago)
ModSecurity rule violation detected by Fail2Ban
Web App Attack
๐ณ๐ด
jad-abuse
2026-09-01 06:32:19
(2 weeks ago)
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: env_probe ...
show more
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: env_probe, source_backup, scanner_ua, actuator, config_backup, ignition_debug. Observed by 1 sensor(s); 19 hits.
show less
Hacking
Web App Attack
๐ซ๐ท
LRNP
2026-09-01 06:17:02
(2 weeks ago)
_:443 34.158.18.104 - - [01/Sep/2026:06:17:02 +0000] "GET /.env.prod HTTP/1.1" 404 146 "-" "crusader ...
show more
_:443 34.158.18.104 - - [01/Sep/2026:06:17:02 +0000] "GET /.env.prod HTTP/1.1" 404 146 "-" "crusader-worker/1.0"
_:443 34.158.18.104 - - [01/Sep/2026:06:17:02 +0000] "GET /.env.example HTTP/1.1" 404 146 "-" "crusader-worker/1.0"
_:443 34.158.18.104 - - [01/Sep/2026:06:17:02 +0000] "GET /.env.old HTTP/1.1" 404 146 "-" "crusader-worker/1.0"
_:443 34.158.18.104 - - [01/Sep/2026:06:17:02 +0000] "GET /wp-config.php.swp HTTP/1.1" 404 146 "-" "crusader-worker/1.0"
_:443 34.158.18.104 - - [01/Sep/2026:06:17:02 +0000] "GET /.env.bak HTTP/1.1" 404 146 "-" "crusader-worker/1.0"
_:443 34.158.18.104 - - [01/Sep/2026:06:17:02 +0000] "GET /wp-config.php~ HTTP/1.1" 404 146 "-" "crusader-worker/1.0"
_:443 34.158.18.104 - - [01/Sep/2026:06:17:02 +0000] "GET /actuator/env HTTP/1.1" 404 146 "-" "crusader-worker/1.0"
_:443 34.158.18.104 - - [01/Sep/2026:06:17:02 +0000] "GET /.env.backup HTTP/1.1" 404 146 "-" "crusader-worker/1.0"
_:443 34.158.18.104 - - [01/Sep/2026:06:17:02 +0000] "GET /.env.save HTTP/1.1
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 06:06:28
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 34.158.18.104 (104.18.158.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.158.18.104 (104.18.158.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 02:06:24.008070 2026] [security2:error] [pid 20125:tid 20125] [client 34.158.18.104:38746] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.bestcountryclubs.com"] [uri "/wp-config.php.swp"] [unique_id "apZrYNLW1X_QcKQw9tF9QAAAAEk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 04:49:17
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 34.158.18.104 (104.18.158.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.158.18.104 (104.18.158.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 00:49:09.694058 2026] [security2:error] [pid 183196:tid 183228] [client 34.158.18.104:58526] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "hobfl.com"] [uri "/.env.save"] [unique_id "apZZRUhOKfD1wIxf9xI9AgAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack