🇬🇧
consul.to
2026-08-29 02:57:55
(16 hours ago)
Web attack/malicious scanning detected
Web App Attack
🇫🇷
arsonist
2026-08-29 02:01:19
(17 hours ago)
This IP accessed the path /.env.prod, which is banned. Powered by ListenCaddy
Bad Web Bot
Web App Attack
🇩🇪
Marc
2026-08-29 01:08:38
(18 hours ago)
34.173.171.46 - - [29/Aug/2026:03:08:37 +0200] "GET /.env.dev HTTP/1.1" 404 4616 "-" "crusader-worke ...
show more
34.173.171.46 - - [29/Aug/2026:03:08:37 +0200] "GET /.env.dev HTTP/1.1" 404 4616 "-" "crusader-worker/1.0" 34.173.171.46 - - [29/Aug/2026:03:08:37 +0200] "GET /.env.save HTTP/1.1" 404 4617 "-" "crusader-worker/1.0" 34.173.171.46 - - [29/Aug/2026:03:08:37 +0200] "GET /.env.bak HTTP/1.1" 404 4618 "-" "crusader-worker/1.0"
show less
Brute-Force
🇫🇮
paissangroup
2026-08-29 00:47:29
(18 hours ago)
Multiple WAF Violations
Web App Attack
🇩🇪
barbarella
2026-08-28 22:41:11
(20 hours ago)
Multiple (23) times attack on https port 443: Configuration snooping in .env file (GET /.env.dev)
...
show more
Multiple (23) times attack on https port 443: Configuration snooping in .env file (GET /.env.dev)
00:41:11 Configuration snooping with .env file (GET /.env)
00:41:11 Configuration snooping in .env file (GET /.env.save)
00:41:11 Configuration snooping in .env file (GET /.env.example)
00:41:11 Configuration snooping in .env file (GET /.env.prod)
00:41:11 Configuration snooping in .env file (GET /.env.bak)
00:41:11 Laravel web application framework vulnerability attack (GET /storage/logs/laravel.log)
00:41:11 Configuration snooping in .env file (GET /.env.old)
00:41:11 Tried to access Wordpress files (GET /wp-config.php~)
show less
Hacking
Web App Attack
🇬🇧
OptimusGO
2026-08-28 21:11:39
(22 hours ago)
Malicious activity detected: web_attack
Server: commstackbc (185.127.18.66)
Attack: web_attack
Time ...
show more
Malicious activity detected: web_attack
Server: commstackbc (185.127.18.66)
Attack: web_attack
Timestamp: 2026-08-28 22:11:39 UTC
Log evidence:
08/28/2026-22:11:38.265016 [**] [1:2009955:15] ET WEB_SERVER Tilde in URI - potential .php~ source disclosure vulnerability [**] [Classification: Web Application Attack] [Priority: 1] {TCP} 34.173.171.46:34236 -> 185.127.18.66:80
08/28/2026-22:11:38.259368 [wDrop] [**] [1:7000911:2] FINSERV CRITICAL: Environment File Access [**] [Classification: Web Application Attack] [Priority: 1] {TCP} 34.173.171.46:34226 -> 185.127.18.66:80
show less
Port Scan
Brute-Force
🇬🇧
Aetherweb Ark
2026-08-28 20:32:41
(22 hours ago)
(mod_security) mod_security (id:949110) triggered by 34.173.171.46 (US/United States/46.171.173.34.b ...
show more
(mod_security) mod_security (id:949110) triggered by 34.173.171.46 (US/United States/46.171.173.34.bc.googleusercontent.com): N in the last X secs
show less
Web App Attack
🇹🇷
hostopya.com
2026-08-28 20:19:20
(23 hours ago)
[plesk-apache] 6 failed attempt(s). Log: [Fri Aug 28 23:19:19.361641 2026] [access_compat:error] [pi ...
show more
[plesk-apache] 6 failed attempt(s). Log: [Fri Aug 28 23:19:19.361641 2026] [access_compat:error] [pid 731409] [client 34.173.171.46:0] AH01797: client denied by server configuration: /var/www/vhosts/sweet-ritchie.94-156-11-6.plesk.page/httpdocs/.env.production|[Fri Aug 28 23:19:19.364972 2026] [access_compat:error] [pid 641900] [client 34.173.171.46:0] AH01797: client denied by server configuration: /var/www/vhosts/sweet-ritchie.94-156-11-6.plesk.page/httpdocs/.env.backup|[Fri Aug 28 23:19:19.371763 2026] [access_compat:error] [pid 561503] [client 34.173.171.46:0] AH01797: client denied by server configuration: /var/www/vhosts/sweet-ritchie.94-156-11-6.plesk.page/httpdocs/.env|[Fri Aug 28 23:19:19.375030 2026] [access_compat:error] [pid 636917] [client 34.173.171.46:0] AH01797: client denied by server configuration: /var/www/vhosts/sweet-ritchie.94-156-11-6.plesk.page/httpdocs/.env.dev|[Fri Aug 28 23:19:19.382402 2026] [access_compat:error] [pid 641900] [client 34.173.171.46:0
show less
Brute-Force
Web App Attack
🇫🇮
YF
2026-08-28 19:30:49
(1 day ago)
WordPress config file probe
Web App Attack
🇫🇮
000rosiu
2026-08-28 19:16:11
(1 day ago)
Triggered Cloudflare WAF (firewallCustom) from US.
Action: BLOCK | Protocol: HTTP/1.1 (GET) | Endpoi ...
show more
Triggered Cloudflare WAF (firewallCustom) from US.
Action: BLOCK | Protocol: HTTP/1.1 (GET) | Endpoint: /.env. | UA: crusader-worker/1.0 • Generated by: github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
🇺🇦
URAN Publishing Service
2026-08-28 19:03:28
(1 day ago)
[28/Aug/2026:22:03:28 +0300] -- 34.173.171.46 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET / ...
show more
[28/Aug/2026:22:03:28 +0300] -- 34.173.171.46 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET /.env.bak HTTP/1.1
show less
Bad Web Bot
Web App Attack
Anonymous
2026-08-28 18:53:42
(1 day ago)
Web Attack ENV File Scanning Attempt
Web App Attack
🇫🇮
oh.mg
2026-08-28 18:40:23
(1 day ago)
[Fri Aug 28 20:40:22.446290 2026] [security2:error] [pid 3867598:tid 3867622] [client 34.173.171.46: ...
show more
[Fri Aug 28 20:40:22.446290 2026] [security2:error] [pid 3867598:tid 3867622] [client 34.173.171.46:49526] [client 34.173.171.46] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:blocking_inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "233"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [ver "OWASP_CRS/4.10.0-dev"] [tag "anomaly-evaluation"] [tag "OWASP_CRS"] [hostname "oh.ke"] [uri "/wp-config.php~"] [unique_id "apHWFkviOvSW0SjhnEnDDgAAAFY"]
[Fri Aug 28 20:40:22.447305 2026] [security2:error] [pid 3868505:tid 3868536] [client 34.173.171.46:49488] [client 34.173.171.46] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:blocking_inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "233"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [ver "OWASP_CRS/4.10.0-dev"] [t
...
show less
Web App Attack
Bad Web Bot
🇩🇪
dbmwebdesign
2026-08-28 17:40:04
(1 day ago)
WAF repeated trigger detected by Fail2Ban in plesk-modsecurity jail
Web App Attack
🇦🇹
Pingger Shikkoken
2026-08-28 16:46:59
(1 day ago)
2026-08-28T16:46:59+00:00 iskariot kernel: AbuseIPDB-Blacklist-Dropped: IN=ens3 OUT=ServerBridge MAC ...
show more
2026-08-28T16:46:59+00:00 iskariot kernel: AbuseIPDB-Blacklist-Dropped: IN=ens3 OUT=ServerBridge MAC=b6:ab:74:e6:2e:14:2c:dd:e9:13:03:d9:08:00 SRC=34.173.171.46 DST=10.1.1.2 LEN=60 TOS=0x00 PREC=0x60 TTL=55 ID=46021 DF PROTO=TCP SPT=34252 DPT=443 WINDOW=65320 RES=0x00 SYN URGP=0 2026-08-28T16:46:59+00:00 iskariot kernel: AbuseIPDB-Blacklist-Dropped: IN=ens3 OUT=ServerBridge MAC=b6:ab:74:e6:2e:14:2c:dd:e9:13:03:d9:08:00 SRC=34.173.171.46 DST=10.1.1.2 LEN=60 TOS=0x00 PREC=0x60 TTL=55 ID=58745 DF PROTO=TCP SPT=34250 DPT=443 WINDOW=65320 RES=0x00 SYN URGP=0 2026-08-28T16:46:59+00:00 iskariot kernel: AbuseIPDB-Blacklist-Dropped: IN=ens3 OUT=ServerBridge MAC=b6:ab:74:e6:2e:14:2c:dd:e9:13:03:d9:08:00 SRC=34.173.171.46 DST=10.1.1.2 LEN=60 TOS=0x00 PREC=0x60 TTL=55 ID=25200 DF PROTO=TCP SPT=34292 DPT=443 WINDOW=65320 RES=0x00 SYN URGP=0 ...
show less
Hacking
Bad Web Bot