🇧🇾
lns.bz
2026-09-05 11:55:05
(6 hours ago)
Too many 404 requests [BY]
Web App Attack
🇩🇪
ghostwarriors
2026-09-05 07:20:05
(11 hours ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack
🇩🇪
yitzhaq
2026-09-05 07:03:10
(11 hours ago)
34.187.16.27 - - [05/Sep/2026:09:03:08 +0200] "GET /wp-config.php~ HTTP/1.1" 404 4470 "-" "crusader- ...
show more
34.187.16.27 - - [05/Sep/2026:09:03:08 +0200] "GET /wp-config.php~ HTTP/1.1" 404 4470 "-" "crusader-worker/1.0"
34.187.16.27 - - [05/Sep/2026:09:03:08 +0200] "GET /wp-config.php.bak HTTP/1.1" 404 4469 "-" "crusader-worker/1.0"
34.187.16.27 - - [05/Sep/2026:09:03:08 +0200] "GET /wp-config.php.swp HTTP/1.1" 404 4469 "-" "crusader-worker/1.0"
34.187.16.27 - - [05/Sep/2026:09:03:08 +0200] "GET /.env.prod HTTP/1.1" 404 4469 "-" "crusader-worker/1.0"
34.187.16.27 - - [05/Sep/2026:09:03:08 +0200] "GET /.env.save HTTP/1.1" 404 4470 "-" "crusader-worker/1.0"
34.187.16.27 - - [05/Sep/2026:09:03:08 +0200] "GET /storage/logs/laravel.log HTTP/1.1" 404 4470 "-" "crusader-worker/1.0"
34.187.16.27 - - [05/Sep/2026:09:03:08 +0200] "GET /.env.backup HTTP/1.1" 404 4470 "-" "crusader-worker/1.0"
34.187.16.27 - - [05/Sep/2026:09:03:08 +0200] "GET /.env.local HTTP/1.1" 404 4470 "-" "crusader-worker/1.0"
34.187.16.27 - - [05/Sep/2026:09:03:08 +0200] "GET /actuator/configprops HTTP/1.1" 404 4470 "-" "crusader
show less
Web App Attack
Brute-Force
🇬🇧
openstrike.co.uk
2026-09-05 05:13:47
(13 hours ago)
13 attacks on PHP URLs, env grabbing URLs:
GET /wp-config.php.bak HTTP/1.1
GET /.env.dev HTTP/1.1
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-04 15:18:38
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.187.16.27 (27.16.187.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.187.16.27 (27.16.187.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 11:18:34.572180 2026] [security2:error] [pid 1762:tid 1762] [client 34.187.16.27:43098] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.thepianosmith.com"] [uri "/.env"] [unique_id "aprhSl0u5gnPY2WBoKKMrgAAAGM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
4server
2026-09-04 15:16:28
(1 day ago)
[FriSep0417:16:25.4944392026][security2:error][pid331944:tid332002][client34.187.16.27:0]ModSecurity ...
show more
[FriSep0417:16:25.4944392026][security2:error][pid331944:tid332002][client34.187.16.27:0]ModSecurity:Accessdeniedwithcode403\(phase2\).Stringmatchwithin\".asa/.asax/.ascx/.backup/.bak/.bat/.cdx/.cer/.cfg/.cmd/.com/.config/.conf/.cs/.csproj/.csr/.dat/.db/.dbf/.dll/.dos/.htr/.htw/.ida/.idc/.idq/.inc/.ini/.key/.licx/.lnk/.log/.mdb/.old/.pass/.pdb/.pol/.printer/.pwd/.rdb/.resources/.resx/.sql/.swp/.sys/.vb/.vbs/.vbproj/.vsdisco/.webinfo/.xsx/\"atTX:extension.[file\"/etc/apache2/conf.d/modsec_rules/00_asl_zz_strict.conf\"][line\"91\"][id\"390716\"][rev\"2\"][msg\"Atomicorp.comWAFRules:URLfileextensionisrestrictedbypolicy\"][data\".backup\"][severity\"ERROR\"][hostname\"craniosacraltherapy.ch.136-243-54-122.cpanel.site\"][uri\"/.env.backup\"][unique_id\"aprgyYAhbNVXGZlgqkKSLAAAAFY\"]
show less
Port Scan
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 14:05:46
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.187.16.27 (27.16.187.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.187.16.27 (27.16.187.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 10:05:40.308887 2026] [security2:error] [pid 16333:tid 16333] [client 34.187.16.27:54466] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.angelabcomics.com"] [uri "/.env.example"] [unique_id "aprQNOc-gum6s8jNl-1ArQAAACQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 12:32:31
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 34.187.16.27 (27.16.187.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.187.16.27 (27.16.187.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 08:32:23.062525 2026] [security2:error] [pid 3647:tid 3647] [client 34.187.16.27:55564] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||ftp.herrell.net|F|2"] [data ".log"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "ftp.herrell.net"] [uri "/storage/logs/laravel.log"] [unique_id "apq6V2KxZYEKhxHvVws4QAAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 11:46:06
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.187.16.27 (27.16.187.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.187.16.27 (27.16.187.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 07:45:59.155449 2026] [security2:error] [pid 31754:tid 31754] [client 34.187.16.27:41402] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.register-yacht-cayman.com"] [uri "/.env"] [unique_id "apqvdwm75IRB-euw8icmZQAAADk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
masterguru
2026-09-04 11:35:25
(1 day ago)
Restricted File Access Attempt. Matched phrase ".env" at REQUEST_FILENAME. (930130-201)
Hacking
Web App Attack
🇸🇪
vaia.cloud
2026-09-04 10:55:03
(1 day ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 10:00:42
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.187.16.27 (27.16.187.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.187.16.27 (27.16.187.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 06:00:32.197118 2026] [security2:error] [pid 3462:tid 3462] [client 34.187.16.27:60824] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.flhomevalue.com"] [uri "/.env"] [unique_id "apqWwHXR2JWkhwQBODzzBAAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 09:22:51
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.187.16.27 (27.16.187.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.187.16.27 (27.16.187.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 05:22:46.868066 2026] [security2:error] [pid 6457:tid 6457] [client 34.187.16.27:46270] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "louisianamasons.com"] [uri "/.env.dev"] [unique_id "apqN5tLEQeSYgcT5iBKQYAAAAEM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
masterguru
2026-09-04 09:10:34
(1 day ago)
Attempt to access a backup or working file. Pattern match "\\\\. (920500-193)
Hacking
🇫🇷
COMAITE
2026-09-04 08:24:38
(1 day ago)
Suspicious URL access.
Web App Attack