Anonymous
2026-09-05 08:05:05
(6 hours ago)
WAF repeated trigger detected by Fail2Ban
Web App Attack
🇺🇸
zwebvigil
2026-09-05 06:54:12
(7 hours ago)
34.20.226.39 [04/Sep/2026:23:54:12 -0700] "GET /.env HTTP/1.1" 404 2673 "-" port=54246 "crusader-wo ...
show more
34.20.226.39 [04/Sep/2026:23:54:12 -0700] "GET /.env HTTP/1.1" 404 2673 "-" port=54246 "crusader-worker/1.0" "-" "-" "<ipaddr>" 972
34.20.226.39 [04/Sep/2026:23:54:12 -0700] "GET /.env.backup HTTP/1.1" 404 2687 "-" port=54296 "crusader-worker/1.0" "-" "-" "<ipaddr>" 627
34.20.226.39 [04/Sep/2026:23:54:12 -0700] "GET /.env.local HTTP/1.1" 404 2685 "-" port=54250 "crusader-worker/1.0" "-" "-" "<ipaddr>" 3163
34.20.226.39 [04/Sep/2026:23:54:12 -0700] "GET /.env.production HTTP/1.1" 404 2695 "-" port=54264 "crusader-worker/1.0" "-" "-" "<ipaddr>" 1191
34.20.226.39 [04/Sep/2026:23:54:12 -0700] "GET /.env.prod HTTP/1.1" 404 2683 "-" port=54280 "crusader-worker/1.0" "-" "-" "<ipaddr>" 2251
34.20.226.39 [04/Sep/2026:23:54:12 -0700] "GET /.env.bak HTTP/1.1" 404 2681 "-" port=54300 "crusader-worker/1.0" "-" "-"
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 14:49:12
(23 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.20.226.39 (39.226.20.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.20.226.39 (39.226.20.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 10:49:06.515720 2026] [security2:error] [pid 29394:tid 29394] [client 34.20.226.39:58322] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "carpascarpe.com"] [uri "/.env"] [unique_id "apraYiW-q2GwJXI-jMM2PQAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 14:06:14
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.20.226.39 (39.226.20.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.20.226.39 (39.226.20.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 10:06:10.161700 2026] [security2:error] [pid 23006:tid 23123] [client 34.20.226.39:53190] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.sellmantitle.com"] [uri "/.env.prod"] [unique_id "aprQUuK_eLa5AsS1DMl8qwAAARc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
big-cloud.nl
2026-09-04 13:24:13
(1 day ago)
Try to access /.env
Web App Attack
🇫🇷
COMAITE
2026-09-04 12:55:19
(1 day ago)
Suspicious URL access.
Web App Attack
🇬🇧
consul.to
2026-09-04 12:17:24
(1 day ago)
Web attack/malicious scanning detected
Web App Attack
🇺🇸
mnsf
2026-09-04 11:05:29
(1 day ago)
Scanning/Probing (20)
Brute-Force
Web App Attack
🇩🇪
FeG Deutschland
2026-09-04 10:56:10
(1 day ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
Anonymous
2026-09-04 10:53:43
(1 day ago)
Scanner hitting /wp-config.php.swp on natsgw.ara-oman.com (GOOGL-2) — aaguard
Brute-Force
Port Scan
🇺🇸
TPI-Abuse
2026-09-04 10:40:21
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.20.226.39 (39.226.20.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.20.226.39 (39.226.20.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 06:40:17.171684 2026] [security2:error] [pid 22464:tid 22464] [client 34.20.226.39:51272] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "aldrich.us"] [uri "/.env.prod"] [unique_id "apqgEfFA-AZx-IQpK2i65QAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
dpsbs
2026-09-04 10:15:08
(1 day ago)
multiple ips intrustions detected
Hacking
🇺🇸
TPI-Abuse
2026-09-04 09:58:20
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.20.226.39 (39.226.20.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.20.226.39 (39.226.20.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 05:58:15.960019 2026] [security2:error] [pid 27211:tid 27211] [client 34.20.226.39:57136] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ns1.davisllp.com"] [uri "/wp-config.php~"] [unique_id "apqWNxNG0eJlZQy_c65LDQAAACM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 09:36:42
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.20.226.39 (39.226.20.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.20.226.39 (39.226.20.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 05:36:39.439943 2026] [security2:error] [pid 2824999:tid 2825131] [client 34.20.226.39:58982] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "gryphix2014.thesdgriffingroup.com"] [uri "/.env.bak"] [unique_id "apqRJ1pNFp6v8WbXhINBmwAAAM0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇸🇪
vaia.cloud
2026-09-04 08:25:03
(1 day ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack