🇪🇸
alferez
2026-09-05 07:02:49
(4 hours ago)
Searching .(env|sql|zip|tar|rar) files
Hacking
Exploited Host
Web App Attack
🇩🇪
tinect
2026-09-05 06:55:19
(4 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-04 15:16:58
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.20.219.133 (133.219.20.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.20.219.133 (133.219.20.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 11:16:54.138463 2026] [security2:error] [pid 22448:tid 22448] [client 34.20.219.133:34520] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.jemsfood.com"] [uri "/.env.prod"] [unique_id "aprg5qQ5nmGONguuHLXGawAAACo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
NewGastroline
2026-09-04 14:33:11
(20 hours ago)
Malicious request blocked by CrowdSec on gastro-prod1.boreus.de
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 14:08:14
(21 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.20.219.133 (133.219.20.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.20.219.133 (133.219.20.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 10:08:10.133756 2026] [security2:error] [pid 10115:tid 10115] [client 34.20.219.133:46904] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.ixd.net"] [uri "/.env.bak"] [unique_id "aprQynjGAw5fblPR01CZLAAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇻🇳
trung.fun
2026-09-04 13:41:21
(21 hours ago)
DDoS, Hack, Brute Force, Web Attack
...
DDoS Attack
Web Spam
Hacking
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 12:56:05
(22 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.20.219.133 (133.219.20.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.20.219.133 (133.219.20.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 08:56:01.240309 2026] [security2:error] [pid 4612:tid 4612] [client 34.20.219.133:45260] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "marlinlee.com"] [uri "/wp-config.php.swp"] [unique_id "apq_4VfhcMjnBqTbVckfOwAAADs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
AetherFox
2026-09-04 11:56:48
(23 hours ago)
AetherFox VoidGuard detected: [Fri Sep 04 11:56:47.200713 2026] [authz_core:error] [pid 667510:tid 6 ...
show more
AetherFox VoidGuard detected: [Fri Sep 04 11:56:47.200713 2026] [authz_core:error] [pid 667510:tid 667524] [client 34.20.219.133:38276] AH01630: client denied by server configuration: proxy:https://[MASKED]/.env
[Fri Sep 04 11:56:47.201990 2026] [authz_core:error] [pid 578009:tid 578029] [client 34.20.219.133:38290] AH01630: client denied by server configuration: proxy:https://[MASKED]/.env.local
[Fri Sep 04 11:56:47.203268 2026] [authz_core:error] [pid 578009:tid 578020] [client 34.20.219.133:38296] AH01630: client denied by server configuration: proxy:https://[MASKED]/.env.prod
[Fri Sep 04 11:56:47.203350 2026] [authz_core:error] [pid 578009:tid 578012] [client 34.20.219.133:38328] AH01630: client denied by server configuration: proxy:https://[MASKED]/crusader-404-probe
[Fri Sep 04 11:56:47.204335 2026] [authz_core:error] [pid 667510:tid 667526] [client 34.20.219.133:38446] AH01630: client denied by server configuration: proxy:https://[MASKED]/actua
...
show less
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 11:44:49
(23 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.20.219.133 (133.219.20.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.20.219.133 (133.219.20.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 07:44:42.468502 2026] [security2:error] [pid 880:tid 880] [client 34.20.219.133:53752] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.behrooz.org"] [uri "/.env.local"] [unique_id "apqvKkci16H4Hs-m-vhxXwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇦🇺
paulshipley.com.au
2026-09-04 11:31:03
(23 hours ago)
[Fri Sep 04 21:31:02.755896 2026] [security2:error] [pid 648253] [client 34.20.219.133:49514] [clien ...
show more
[Fri Sep 04 21:31:02.755896 2026] [security2:error] [pid 648253] [client 34.20.219.133:49514] [client 34.20.219.133] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/modsecurity/crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "iaki.com.au"] [uri "/.env.backup"] [unique_id "apqr9qrlWDvmIxMRXrfQaAAAACQ"]
...
show less
Web App Attack
🇺🇸
mnsf
2026-09-04 11:05:57
(1 day ago)
Scanning/Probing (20)
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 10:59:47
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.20.219.133 (133.219.20.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.20.219.133 (133.219.20.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 06:59:40.688809 2026] [security2:error] [pid 15856:tid 15856] [client 34.20.219.133:44012] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bluesbluff.com"] [uri "/.env"] [unique_id "apqknC-i3ioxFAGaOBMZEwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
consul.to
2026-09-04 10:59:45
(1 day ago)
Web attack/malicious scanning detected
Web App Attack
🇩🇪
Marc
2026-09-04 10:58:40
(1 day ago)
34.20.219.133 - - [04/Sep/2026:12:58:40 +0200] "GET /.env.save HTTP/1.1" 404 4618 "-" "crusader-work ...
show more
34.20.219.133 - - [04/Sep/2026:12:58:40 +0200] "GET /.env.save HTTP/1.1" 404 4618 "-" "crusader-worker/1.0" 34.20.219.133 - - [04/Sep/2026:12:58:40 +0200] "GET /.env.prod HTTP/1.1" 404 4617 "-" "crusader-worker/1.0" 34.20.219.133 - - [04/Sep/2026:12:58:40 +0200] "GET /.env.bak HTTP/1.1" 404 4617 "-" "crusader-worker/1.0"
show less
Brute-Force
🇸🇪
vaia.cloud
2026-09-04 10:40:04
(1 day ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack