Anonymous
2026-09-22 15:50:18
(4 minutes ago)
34.21.169.200 - - [22/Sep/2026:15:50:17 +0000] "GET /.env.example HTTP/1.1" 404 153 "-" "crusader-wo ...
show more
34.21.169.200 - - [22/Sep/2026:15:50:17 +0000] "GET /.env.example HTTP/1.1" 404 153 "-" "crusader-worker/1.0" "-" "opt-out.schmittel-it.de"
...
show less
Hacking
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 14:51:30
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.21.169.200 (200.169.21.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.21.169.200 (200.169.21.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 10:51:26.009640 2026] [security2:error] [pid 520:tid 520] [client 34.21.169.200:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.kidswithcamerasmovie.com"] [uri "/.env.production"] [unique_id "arKV7pgjzswljqaRnKA2hgAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-22 14:50:02
(1 hour ago)
suspicious request in access.log
Web App Attack
๐ง๐ท
Halux
2026-09-22 14:28:09
(1 hour ago)
34.21.169.200 Probing protected path or service
Web App Attack
๐ฉ๐ช
LRob
2026-09-22 14:28:03
(1 hour ago)
This address is looking for secret files on our sites: .git directories, .env files, credential and ...
show more
This address is looking for secret files on our sites: .git directories, .env files, credential and configuration files, database dumps, backups. This is a targeted search for credentials to break into the sites, blocked at the first request. Please check the machine behind it for an attack tool or malware. | method: GET | path: /.env.production (+12 more) | 2026-09-22 14:28 UTC
show less
Hacking
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-09-22 13:56:16
(1 hour ago)
[22/Sep/2026:16:56:16 +0300] -- 34.21.169.200 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.env ...
show more
[22/Sep/2026:16:56:16 +0300] -- 34.21.169.200 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.env.production HTTP/1.1
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
FD-IX
2026-09-22 13:43:12
(2 hours ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 13:39:06
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.21.169.200 (200.169.21.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.21.169.200 (200.169.21.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 09:39:00.031251 2026] [security2:error] [pid 22758:tid 22758] [client 34.21.169.200:46848] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "hertzan.com"] [uri "/.env.backup"] [unique_id "arKE9D960DV8nYnQdtN8vwAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 12:35:08
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.21.169.200 (200.169.21.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.21.169.200 (200.169.21.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 08:35:03.182768 2026] [security2:error] [pid 27281:tid 27281] [client 34.21.169.200:48818] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "dvdmasters.com"] [uri "/.env"] [unique_id "arJ19xCbCi4Y5j8nK3N0DQAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 12:16:17
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.21.169.200 (200.169.21.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.21.169.200 (200.169.21.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 08:16:09.816690 2026] [security2:error] [pid 27223:tid 27264] [client 34.21.169.200:60310] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "dermatologistcoloradosprings.com"] [uri "/.env.bak"] [unique_id "arJxif1kW2THq_56-DKhOAAAAJU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 11:53:19
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.21.169.200 (200.169.21.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.21.169.200 (200.169.21.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 07:53:13.974003 2026] [security2:error] [pid 4223:tid 4223] [client 34.21.169.200:40478] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.unwaved.com"] [uri "/wp-config.php~"] [unique_id "arJsKSXMnK1RfIMnnfdIWgAAACQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
debestelapp
2026-09-22 11:40:11
(4 hours ago)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 11:28:32
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.21.169.200 (200.169.21.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.21.169.200 (200.169.21.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 07:28:27.168471 2026] [security2:error] [pid 6026:tid 6026] [client 34.21.169.200:36802] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "carolmaalouf.com"] [uri "/wp-config.php.swp"] [unique_id "arJmW8rWGk4rRtXa7fD0_QAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
VHosting
2026-09-22 11:25:05
(4 hours ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐ซ๐ท
masterguru
2026-09-22 11:10:40
(4 hours ago)
Restricted File Access Attempt. Matched phrase ".env" at REQUEST_FILENAME. (930130-193)
Hacking
Web App Attack