🇺🇸
kosada.com
2026-09-06 06:33:44
(1 day ago)
Repeated exploit attempts, for example: /actuator/configprops /actuator/ (HTTP/1.1 port 443)
Web App Attack
🇫🇷
COMAITE
2026-09-06 03:31:42
(1 day ago)
Suspicious URL access.
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 02:29:01
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.180.98.52 (52.98.180.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.180.98.52 (52.98.180.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 22:28:54.826319 2026] [security2:error] [pid 24682:tid 24688] [client 34.180.98.52:44714] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "smtpseguro.absurdotron.com"] [uri "/.env.save"] [unique_id "apzP5nh4BOPFfcuw8ENvoAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
dynamix
2026-09-06 01:59:35
(1 day ago)
Multiple WAF Violations
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 01:44:46
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.180.98.52 (52.98.180.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.180.98.52 (52.98.180.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 21:44:38.547936 2026] [security2:error] [pid 28660:tid 28660] [client 34.180.98.52:39310] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ftp.cartiologyfilms.com"] [uri "/.env.production"] [unique_id "apzFhuiwfR-gN5kciXA_4AAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
Holger
2026-09-06 01:41:37
(1 day ago)
URL probing: GET /.env
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 01:21:25
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.180.98.52 (52.98.180.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.180.98.52 (52.98.180.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 21:21:18.624550 2026] [security2:error] [pid 24390:tid 24390] [client 34.180.98.52:48692] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "tell-me-first.com"] [uri "/.env.dev"] [unique_id "apzADmhPkiEpHSC2dQCk8gAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
WeCloudit-Anti-Abuse
2026-09-06 00:35:48
(1 day ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-06 00:05:13
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.180.98.52 (52.98.180.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.180.98.52 (52.98.180.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 20:05:07.543952 2026] [security2:error] [pid 20798:tid 20798] [client 34.180.98.52:56846] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "oxygenfarm.com"] [uri "/.env.dev"] [unique_id "apyuMyTGP10mcCokKx3B_wAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 23:49:31
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.180.98.52 (52.98.180.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.180.98.52 (52.98.180.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 19:49:25.049054 2026] [security2:error] [pid 18251:tid 18251] [client 34.180.98.52:45254] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "goochcompanies.com"] [uri "/.env.prod"] [unique_id "apyqhUjuqFOCof0sPAM-dgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
Bedios GmbH
2026-09-05 23:29:15
(1 day ago)
Login credentials theft attempt
Hacking
🇺🇸
TPI-Abuse
2026-09-05 23:21:56
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.180.98.52 (52.98.180.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.180.98.52 (52.98.180.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 19:21:49.607640 2026] [security2:error] [pid 11731:tid 11795] [client 34.180.98.52:34314] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "lawyerflorida.net.aafm.us"] [uri "/wp-config.php.swp"] [unique_id "apykDZsU0UwcvWhlsZpSUAAAAcQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇱🇹
NotACaptcha
2026-09-05 22:35:40
(1 day ago)
webserver:443 [06/Sep/2026] "GET /.env.dev HTTP/1.1" 404 5605 "-" "crusader-worker/1.0"
webserver:4 ...
show more
webserver:443 [06/Sep/2026] "GET /.env.dev HTTP/1.1" 404 5605 "-" "crusader-worker/1.0"
webserver:443 [06/Sep/2026] "GET /.env.backup HTTP/1.1" 404 5605 "-" "crusader-worker/1.0"
webserver:443 [06/Sep/2026] "GET /.env.production HTTP/1.1" 404 5605 "-" "crusader-worker/1.0"
webserver:443 [06/Sep/2026] "GET /_ignition/health-check HTTP/1.1" 404 5605 "-" "crusader-worker/1.0"
webserver:443 [06/Sep/2026] "GET /.env.local HTTP/1.1" 404 5605 "-" "crusader-worker/1.0"
webserver:443 [06/Sep/2026] "GET /crusader-404-probe HTTP/1.1" 404 5605 "-" "crusader-worker/1.0"
webserver:443 [06/Sep/2026] "GET /storage/logs/laravel.log HTTP/1.1" 404 5605 "-" "crusader-worker/1.0"
webserver:443 [06/Sep/2026] "GET /.env.old HTTP/1.1" 404 5605 "-" "crusader-worker/1.0"
webserver:443 [06/Sep/2026] "GET /.env.bak HTTP/1.1" 404 5605 "-" "crusader-worker/1.0"
webserver:443 [06/Sep/2026] "GET /wp-config.php.swp HTTP/1.1" 404 5605 "-" "crusader-worker/1.0"
webserver:443 [06/Sep/2026] "GET /.env.prod HTTP...
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 21:54:13
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.180.98.52 (52.98.180.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.180.98.52 (52.98.180.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 17:54:07.940020 2026] [security2:error] [pid 7549:tid 7549] [client 34.180.98.52:39764] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "biketurtlehill.com"] [uri "/.env.backup"] [unique_id "apyPf8Zxv-RDhIA56qMCjQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇦🇺
nzhost.co.nz
2026-09-05 21:39:30
(1 day ago)
$f2bV_matches
Hacking
Brute-Force