Anonymous
2026-09-08 12:25:02
(2 weeks ago)
suspicious request in access.log
Web App Attack
๐ฑ๐ป
garmtech.com
2026-09-08 08:11:57
(2 weeks ago)
Attempted access to sensitive endpoint (/.env.production) detected. Automated scan or unauthorized p ...
show more
Attempted access to sensitive endpoint (/.env.production) detected. Automated scan or unauthorized probing.
show less
Web App Attack
๐ฉ๐ช
BlueWire Hosting
2026-09-08 03:40:06
(2 weeks ago)
High-confidence malicious configuration/VCS probe
Web App Attack
๐ฉ๐ช
Uwe Sarpe
2026-09-06 06:26:38
(2 weeks ago)
[Sun Sep 06 08:26:37.846134 2026] [access_compat:error] [pid 33418:tid 33418] [client 34.175.191.154 ...
show more
[Sun Sep 06 08:26:37.846134 2026] [access_compat:error] [pid 33418:tid 33418] [client 34.175.191.154:57036] AH01797: client denied by server configuration: /var/www/.env.prod
[Sun Sep 06 08:26:37.848003 2026] [access_compat:error] [pid 40203:tid 40203] [client 34.175.191.154:57158] AH01797: client denied by server configuration: /var/www/storage
[Sun Sep 06 08:26:37.848572 2026] [access_compat:error] [pid 37078:tid 37078] [client 34.175.191.154:57142] AH01797: client denied by server configuration: /var/www/.env.old
[Sun Sep 06 08:26:37.850132 2026] [access_compat:error] [pid 40205:tid 40205] [client 34.175.191.154:57166] AH01797: client denied by server configuration: /var/www/crusader-404-probe
[Sun Sep 06 08:26:37.855844 2026] [access_compat:error] [pid 37043:tid 37043] [client 34.175.191.154:57020] AH01797: client denied by server configuration: /var/www/.env.dev
...
show less
Brute-Force
Web App Attack
๐บ๐ธ
decisionconcepts
2026-09-06 06:21:58
(2 weeks ago)
34.175.191.154 - - [05/Sep/2026:23:21:57 -0700] "GET /.env HTTP/1.1" 403 199 "-" "crusader-worker/1. ...
show more
34.175.191.154 - - [05/Sep/2026:23:21:57 -0700] "GET /.env HTTP/1.1" 403 199 "-" "crusader-worker/1.0"
34.175.191.154 - - [05/Sep/2026:23:21:57 -0700] "GET /.env.local HTTP/1.1" 403 199 "-" "crusader-worker/1.0"
show less
Brute-Force
SSH
๐บ๐ธ
kosada.com
2026-09-06 06:15:29
(2 weeks ago)
Repeated exploit attempts, for example: /.env.prod /.env (HTTP/1.1 port 443)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-06 03:38:23
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 34.175.191.154 (154.191.175.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.175.191.154 (154.191.175.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 23:38:19.447789 2026] [security2:error] [pid 5300:tid 5300] [client 34.175.191.154:34736] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "podbillspec.drxcontent.com"] [uri "/.env"] [unique_id "apzgK-DPs6hqoObzDXzWrQAAACU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-09-06 03:36:11
(2 weeks ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-06 03:18:21
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 34.175.191.154 (154.191.175.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.175.191.154 (154.191.175.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 23:18:15.824423 2026] [security2:error] [pid 29650:tid 29670] [client 34.175.191.154:52728] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "dermatologycolorado.com"] [uri "/.env.bak"] [unique_id "apzbdzK_Ze3cnQ1SOdhVpAAAAZE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-06 03:01:05
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 34.175.191.154 (154.191.175.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.175.191.154 (154.191.175.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 23:01:00.761039 2026] [security2:error] [pid 8548:tid 8548] [client 34.175.191.154:37140] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.forwardti.com"] [uri "/wp-config.php.bak"] [unique_id "apzXbMSt9WyBmqQtLjJeUQAAAHs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-06 02:39:09
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 34.175.191.154 (154.191.175.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.175.191.154 (154.191.175.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 22:39:02.340735 2026] [security2:error] [pid 13282:tid 13282] [client 34.175.191.154:50952] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "infalliblebible.com"] [uri "/.env.prod"] [unique_id "apzSRkiJeelgtN8_2oQspwAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FD-IX
2026-09-06 02:28:15
(2 weeks ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
Anonymous
2026-09-06 01:39:15
(2 weeks ago)
34.175.191.154 - - [06/Sep/2026:03:39:07 +0200] "GET /wp-config.php~ HTTP/1.1" 404 233132 "-" "crusa ...
show more
34.175.191.154 - - [06/Sep/2026:03:39:07 +0200] "GET /wp-config.php~ HTTP/1.1" 404 233132 "-" "crusader-worker/1.0"
34.175.191.154 - - [06/Sep/2026:03:39:07 +0200] "GET /.env.production HTTP/1.1" 404 233132 "-" "crusader-worker/1.0"
34.175.191.154 - - [06/Sep/2026:03:39:07 +0200] "GET /storage/logs/laravel.log HTTP/1.1" 404 233994 "-" "crusader-worker/1.0"
34.175.191.154 - - [06/Sep/2026:03:39:07 +0200] "GET /.env.old HTTP/1.1" 404 233132 "-" "crusader-worker/1.0"
34.175.191.154 - - [06/Sep/2026:03:39:08 +0200] "GET /.env.backup HTTP/1.1" 404 233132 "-" "crusader-worker/1.0"
34.175.191.154 - - [06/Sep/2026:03:39:07 +0200] "GET /.env.local HTTP/1.1" 404 233132 "-" "crusader-worker/1.0"
34.175.191.154 - - [06/Sep/2026:03:39:08 +0200] "GET /wp-config.php.swp HTTP/1.1" 404 233132 "-" "crusader-worker/1.0"
34.175.191.154 - - [06/Sep/2026:03:39:07 +0200] "GET /.env.example HTTP/1.1" 404 233132 "-" "crusader-worker/1.0"
34.175.191.154 - - [06/Sep/2026:03:39:09 +0200] "GET /.env.save HTTP/1.1"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-06 00:48:20
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 34.175.191.154 (154.191.175.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.175.191.154 (154.191.175.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 20:48:16.433149 2026] [security2:error] [pid 12960:tid 12960] [client 34.175.191.154:42146] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.imagea.net"] [uri "/.env.old"] [unique_id "apy4UG4Fu9rftaO81lhYdQAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-09-06 00:30:23
(2 weeks ago)
Multiple WAF Violations
Web App Attack