π©πͺ
wpadm4
2026-08-01 17:13:26
(9 hours ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
π¨π
4server
2026-08-01 17:10:14
(9 hours ago)
[SatAug0119:10:10.1219432026][security2:error][pid176352:tid176678][client34.175.57.98:0]ModSecurity ...
show more
[SatAug0119:10:10.1219432026][security2:error][pid176352:tid176678][client34.175.57.98:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\".env\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"365\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"walter-worndli.ch\"][uri\"/.env\"][unique_id\"am4ociJOhK1YbDc7mz6EuAAAAJM\"]
show less
Hacking
Web App Attack
π©πͺ
barbarella
2026-08-01 16:50:45
(10 hours ago)
Multiple (10) times attack on https port 443: Configuration snooping in .env file (GET /.env.backup) ...
show more
Multiple (10) times attack on https port 443: Configuration snooping in .env file (GET /.env.backup)
18:50:45 Configuration snooping in .env file (GET /.env)
18:50:45 Configuration snooping in .env file (GET /.env.save)
18:50:45 Configuration snooping in .env file (GET /.env.prod)
18:50:45 Configuration snooping in .env file (GET /.env.bak)
18:50:45 Configuration snooping in .env file (GET /.env.local)
18:50:45 Configuration snooping in .env file (GET /.env.dev)
18:50:45 Configuration snooping in .env file (GET /.env.production)
18:50:45 Configuration snooping in .env file (GET /.env.example)
show less
Hacking
Web App Attack
πΊπ¦
URAN Publishing Service
2026-08-01 16:39:42
(10 hours ago)
Multiple unauthorized connection attempts
Web App Attack
π³π±
e.fierstra
2026-08-01 16:18:13
(10 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
Anonymous
2026-08-01 16:10:05
(10 hours ago)
| Suspicious URL access.
Web App Attack
Hacking
SQL Injection
π©πͺ
DEV-DNS
2026-08-01 16:08:22
(10 hours ago)
(mod_security) mod_security triggered on hostname [redacted])
SQL Injection
π«π·
masterguru
2026-08-01 15:30:40
(11 hours ago)
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 34.175.57.98 (ES/Spain/98.57.175.34.b ...
show more
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 34.175.57.98 (ES/Spain/98.57.175.34.bc.googleusercontent.com): 2 in the last 3600 secs (0-196)
show less
Hacking
πΊπΈ
TPI-Abuse
2026-08-01 15:26:46
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.175.57.98 (98.57.175.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.175.57.98 (98.57.175.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 11:26:42.456896 2026] [security2:error] [pid 555926:tid 555926] [client 34.175.57.98:54630] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.angove.biz"] [uri "/.env.production"] [unique_id "am4QMhUyIN06YKiv22AisQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
big-cloud.nl
2026-08-01 15:21:49
(11 hours ago)
Try to access /.env
Web App Attack
πΊπΈ
lavnet.net
2026-08-01 15:00:59
(12 hours ago)
34.175.57.98 - - [01/Aug/2026:15:00:59 +0000] "GET /.env.dev HTTP/1.1" 404 6038 "-" "crusader-worker ...
show more
34.175.57.98 - - [01/Aug/2026:15:00:59 +0000] "GET /.env.dev HTTP/1.1" 404 6038 "-" "crusader-worker/1.0"
34.175.57.98 - - [01/Aug/2026:15:00:59 +0000] "GET /.env.old HTTP/1.1" 404 6039 "-" "crusader-worker/1.0"
34.175.57.98 - - [01/Aug/2026:15:00:59 +0000] "GET /.env.save HTTP/1.1" 404 6039 "-" "crusader-worker/1.0"
34.175.57.98 - - [01/Aug/2026:15:00:59 +0000] "GET /.env.prod HTTP/1.1" 404 6039 "-" "crusader-worker/1.0"
34.175.57.98 - - [01/Aug/2026:15:00:59 +0000] "GET /.env.example HTTP/1.1" 404 6040 "-" "crusader-worker/1.0"
34.175.57.98 - - [01/Aug/2026:15:00:59 +0000] "GET /.env.production HTTP/1.1" 404 6038 "-" "crusader-worker/1.0"
...
show less
Brute-Force
πΊπΈ
TPI-Abuse
2026-08-01 14:27:07
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.175.57.98 (98.57.175.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.175.57.98 (98.57.175.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 10:26:58.817541 2026] [security2:error] [pid 900976:tid 900987] [client 34.175.57.98:47822] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mouserart.com"] [uri "/.env.save"] [unique_id "am4CMscl5iHDiW1DCppmegAAAIg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-01 13:52:04
(13 hours ago)
(mod_security) mod_security (id:949110) triggered by 34.175.57.98 (98.57.175.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:949110) triggered by 34.175.57.98 (98.57.175.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 09:52:00.236339 2026] [security2:error] [pid 1990611:tid 1990611] [client 34.175.57.98:38598] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "www.equiprentalsales.crazycontrols.com"] [uri "/.env.production"] [unique_id "am36AFHNj0TkFdS7KxB7BgAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
neckaralb-admin.de
2026-08-01 13:25:25
(13 hours ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-01 13:25:24
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.175.57.98 (98.57.175.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.175.57.98 (98.57.175.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 09:25:16.126789 2026] [security2:error] [pid 569969:tid 569995] [client 34.175.57.98:37816] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.lawyercalifornia.net.aafm.us"] [uri "/.env.old"] [unique_id "am3zvMUts0Y2lkkgQSidzAAAAJc"]
show less
Brute-Force
Bad Web Bot
Web App Attack