🇩🇪
pscriptos
2026-09-05 12:40:44
(6 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
Anonymous
2026-09-05 07:33:35
(12 hours ago)
[ns27.kdns.gr] httpd-config-scan: logs=/var/log/httpd/access_log; samples=/.env | /.env.local | /.en ...
show more
[ns27.kdns.gr] httpd-config-scan: logs=/var/log/httpd/access_log; samples=/.env | /.env.local | /.env.prod
show less
Hacking
Web App Attack
🇫🇷
dynamix
2026-09-05 07:02:01
(12 hours ago)
Multiple WAF Violations
Web App Attack
🇩🇪
big-cloud.nl
2026-09-04 14:37:05
(1 day ago)
Try to access /.env
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 14:06:49
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.169.107.6 (6.107.169.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.169.107.6 (6.107.169.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 10:06:43.614935 2026] [security2:error] [pid 23004:tid 23130] [client 34.169.107.6:51354] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.birdhousefarms.com"] [uri "/wp-config.php~"] [unique_id "aprQc84Kl8MzvCwEZxJ4AQAAAIg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 13:36:47
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.169.107.6 (6.107.169.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.169.107.6 (6.107.169.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 09:36:42.227385 2026] [security2:error] [pid 10887:tid 10887] [client 34.169.107.6:33212] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "form-a-tool.com"] [uri "/.env.dev"] [unique_id "aprJavwL1jHdvgcRXNgEggAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-04 12:51:10
(1 day ago)
Blocked by ModSec and CSF
Port Scan
Anonymous
2026-09-04 12:50:01
(1 day ago)
suspicious request in access.log
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 12:13:04
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.169.107.6 (6.107.169.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.169.107.6 (6.107.169.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 08:12:58.936045 2026] [security2:error] [pid 31036:tid 31036] [client 34.169.107.6:36560] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "fallsgreatestcookies.dc406.org"] [uri "/.env.prod"] [unique_id "apq1yq4HemeYvdw8fdqrtQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 11:51:18
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.169.107.6 (6.107.169.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.169.107.6 (6.107.169.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 07:51:13.082382 2026] [security2:error] [pid 17586:tid 17586] [client 34.169.107.6:55420] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "lollytalk.com"] [uri "/.env"] [unique_id "apqwsTFEvr3PWD9zgmhbGwAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
Marc
2026-09-04 11:34:34
(1 day ago)
34.169.107.6 - - [04/Sep/2026:13:34:33 +0200] "GET /wp-config.php.swp HTTP/1.1" 404 4617 "-" "crusad ...
show more
34.169.107.6 - - [04/Sep/2026:13:34:33 +0200] "GET /wp-config.php.swp HTTP/1.1" 404 4617 "-" "crusader-worker/1.0" 34.169.107.6 - - [04/Sep/2026:13:34:33 +0200] "GET /.env HTTP/1.1" 404 4618 "-" "crusader-worker/1.0" 34.169.107.6 - - [04/Sep/2026:13:34:33 +0200] "GET /.env.local HTTP/1.1" 404 4617 "-" "crusader-worker/1.0"
show less
Brute-Force
🇺🇸
mnsf
2026-09-04 11:05:38
(1 day ago)
Abuse Detected (3)
Brute-Force
Web App Attack
🇭🇺
miszterx.hu
2026-09-04 11:01:48
(1 day ago)
XORP (haproxy): 3x HTTP 404/403/500 or handshake failure in 24h. Automated report from log_check_ipt ...
show more
XORP (haproxy): 3x HTTP 404/403/500 or handshake failure in 24h. Automated report from log_check_iptables_generator.sh (xorp.hu)
show less
Web App Attack
Anonymous
2026-09-04 11:00:06
(1 day ago)
(config_exploit_scan) Configuratie Scanner / Nep GPTBot 34.169.107.6 (US/United States/6.107.169.34. ...
show more
(config_exploit_scan) Configuratie Scanner / Nep GPTBot 34.169.107.6 (US/United States/6.107.169.34.bc.googleusercontent.com): 3 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 34.169.107.6 - - [04/Sep/2026:13:00:02 +0200] "GET /.env.dev HTTP/1.1" 406 4831 "-" "crusader-worker/1.0"
34.169.107.6 - - [04/Sep/2026:13:00:02 +0200] "GET /.env.backup HTTP/1.1" 406 4832 "-" "crusader-worker/1.0"
34.169.107.6 - - [04/Sep/2026:13:00:02 +0200] "GET /.env.local HTTP/1.1" 406 4831 "-" "crusader-worker/1.0"
show less
Port Scan
🇺🇸
TPI-Abuse
2026-09-04 10:31:18
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.169.107.6 (6.107.169.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.169.107.6 (6.107.169.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 06:31:11.160759 2026] [security2:error] [pid 4086:tid 4086] [client 34.169.107.6:59334] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "informant-systems.com"] [uri "/.env.prod"] [unique_id "apqd70xfVfgzLErFh-lo0wAAADs"]
show less
Brute-Force
Bad Web Bot
Web App Attack