๐ฉ๐ช
FD-IX
2026-09-22 16:58:07
(1 week ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
Anonymous
2026-09-22 16:07:06
(1 week ago)
Automated web scanner. Requested suspicious paths: /.env.production | /.env.bak | /actuator/env | /. ...
show more
Automated web scanner. Requested suspicious paths: /.env.production | /.env.bak | /actuator/env | /.env.prod | /crusader-404-probe | /storage/logs/laravel.log | /.env | /_ignition/health-check | /.env.local | /env | /.env.dev | /.env.old | /.env.save | /.env.example | /actuator/configprops. UTC: 2026-09-22 15:57:32.
show less
Web App Attack
๐บ๐ธ
infra-monitor
2026-09-22 16:00:07
(1 week ago)
Automated ban via infra-monitor: suspicious-probe, wordpress-probe, wp-sensitive-paths, +3 more
Port Scan
Web App Attack
๐ฉ๐ช
TheDjRider
2026-09-22 14:53:47
(1 week ago)
CrowdSec detected Web application reconnaissance. Scenario: local/framework-recon. Automatic ban tri ...
show more
CrowdSec detected Web application reconnaissance. Scenario: local/framework-recon. Automatic ban triggered. Detection time (UTC): 2026-09-22T14:53:45.344293563Z. Context: http_status=403
show less
Web App Attack
๐ฉ๐ช
Hazzard
2026-09-22 14:49:11
(1 week ago)
(mod_security) mod_security triggered on hostname [redacted]): (CF_ENABLE)
SQL Injection
Anonymous
2026-09-22 14:21:36
(1 week ago)
GET /.env.backup HTTP/1.1
...
Web App Attack
๐ฒ๐พ
Rizzy
2026-09-22 14:05:20
(1 week ago)
Multiple WAF Violations
Brute-Force
Web App Attack
Anonymous
2026-09-22 14:00:03
(1 week ago)
suspicious request in access.log
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 13:33:43
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.175.61.127 (127.61.175.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.175.61.127 (127.61.175.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 09:33:38.261859 2026] [security2:error] [pid 19779:tid 19779] [client 34.175.61.127:52942] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "gurusportz.com"] [uri "/wp-config.php~"] [unique_id "arKDsquhYX38ZzX6BgxulgAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 13:11:27
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.175.61.127 (127.61.175.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.175.61.127 (127.61.175.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 09:11:21.542335 2026] [security2:error] [pid 3473:tid 3473] [client 34.175.61.127:33910] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "fluff.hiidied.com"] [uri "/.env.dev"] [unique_id "arJ-eV8vn_O69KJ0w0cNJQAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
snhosting
2026-09-22 12:30:13
(1 week ago)
34.175.61.127 - - [22/Sep/2026:14:29:56 +0200] "GET /actuator/configprops HTTP/1.1" 302 0 "-" "crusa ...
show more
34.175.61.127 - - [22/Sep/2026:14:29:56 +0200] "GET /actuator/configprops HTTP/1.1" 302 0 "-" "crusader-worker/1.0"
34.175.61.127 - - [22/Sep/2026:14:29:56 +0200] "GET /.env.old HTTP/1.1" 302 0 "-" "crusader-worker/1.0"
34.175.61.127 - - [22/Sep/2026:14:29:56 +0200] "GET /wp-config.php.bak HTTP/1.1" 302 0 "-" "crusader-worker/1.0"
34.175.61.127 - - [22/Sep/2026:14:29:56 +0200] "GET /wp-config.php.swp HTTP/1.1" 302 0 "-" "crusader-worker/1.0"
34.175.61.127 - - [22/Sep/2026:14:29:56 +0200] "GET /.env.production HTTP/1.1" 302 0 "-" "crusader-worker/1.0"
...
show less
DNS Compromise
DNS Poisoning
Phishing
Email Spam
Brute-Force
Web App Attack
SSH
๐ฌ๐ง
relianoid.com
2026-09-22 12:15:29
(1 week ago)
404 Errors Abuse detected by Relianoid OSS Load Balancer - relianoid.com
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 12:08:33
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.175.61.127 (127.61.175.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.175.61.127 (127.61.175.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 08:08:26.374545 2026] [security2:error] [pid 18475:tid 18475] [client 34.175.61.127:45606] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "darrinlauritzen.com"] [uri "/.env.production"] [unique_id "arJvusQzXumSddWIOps4aAAAADQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-22 11:57:03
(1 week ago)
[ti-05al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-05al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 34.175.61.127 - - [22/Sep/2026:13:56:45 +0200] "GET /.env.production HTTP/1.1" 403 4438 "-" "crusader-worker/1.0"
...
show less
Bad Web Bot
Web App Attack
๐ฎ๐น
VHosting
2026-09-22 11:20:03
(1 week ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack