🇩🇪
Marcin Stepien
2026-09-07 08:46:55
(14 hours ago)
Hit honeypot endpoint /backup.zip. Automated scanner/bot detected.
Bad Web Bot
Web App Attack
🇧🇾
lns.bz
2026-09-06 06:00:34
(1 day ago)
Too many 404 requests [BY]
Web App Attack
🇬🇧
openstrike.co.uk
2026-09-06 05:12:53
(1 day ago)
13 attacks on PHP URLs, env grabbing URLs:
GET /wp-config.php~ HTTP/1.1
GET /.env.backup HTTP/1.1
Web App Attack
Hacking
🇫🇷
✨
2026-09-06 03:06:15
(1 day ago)
Domain : wilsonmackay.co.uk
Rule : env
2026-09-06 03:02:43 ***hidden-privacy*** GET /.env.dev - 443 ...
show more
Domain : wilsonmackay.co.uk
Rule : env
2026-09-06 03:02:43 ***hidden-privacy*** GET /.env.dev - 443 - 34.22.52.222 HTTP/1.1 crusader-worker/1.0 - wilsonmackay.co.uk 301 0 0 448 98 123 - -
show less
Hacking
SQL Injection
🇩🇪
BlueWire Hosting
2026-09-06 02:35:04
(1 day ago)
High-confidence malicious configuration/VCS probe
Web App Attack
🇬🇧
Apache
2026-09-06 02:25:50
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.22.52.222 (US/United States/222.52.22.34.bc. ...
show more
(mod_security) mod_security (id:210492) triggered by 34.22.52.222 (US/United States/222.52.22.34.bc.googleusercontent.com): 5 in the last 300 secs (CF_ENABLE)
show less
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 02:25:46
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.22.52.222 (222.52.22.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.22.52.222 (222.52.22.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 22:25:40.364730 2026] [security2:error] [pid 9311:tid 9311] [client 34.22.52.222:43042] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "smid.tv"] [uri "/.env.save"] [unique_id "apzPJOsmaL2Q8nVcvGlNQgAAACc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-06 02:10:04
(1 day ago)
suspicious request in access.log
Web App Attack
🇳🇱
e.fierstra
2026-09-06 01:02:11
(1 day ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
🇩🇪
Philister11
2026-09-06 00:01:07
(1 day ago)
CrowdSec: crowdsecurity/http-sensitive-files (US/AS396982)
Web App Attack
Hacking
🇺🇸
mnsf
2026-09-05 23:05:59
(2 days ago)
Scanning/Probing (20)
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 22:59:04
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.22.52.222 (222.52.22.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.22.52.222 (222.52.22.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 18:58:57.164070 2026] [security2:error] [pid 17696:tid 17696] [client 34.22.52.222:55824] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.dryprodrain.com"] [uri "/.env.backup"] [unique_id "apyesTxAL7DWbo3QbmWXawAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇧🇷
Halux
2026-09-05 22:48:05
(2 days ago)
34.22.52.222 Probing protected path or service
Web App Attack
🇩🇪
AetherFox
2026-09-05 22:46:55
(2 days ago)
AetherFox VoidGuard detected: [Sat Sep 05 22:46:55.097281 2026] [authz_core:error] [pid 731613:tid 7 ...
show more
AetherFox VoidGuard detected: [Sat Sep 05 22:46:55.097281 2026] [authz_core:error] [pid 731613:tid 731638] [client 34.22.52.222:55208] AH01630: client denied by server configuration: proxy:https://[MASKED]/_ignition/health-check
[Sat Sep 05 22:46:55.097311 2026] [authz_core:error] [pid 731612:tid 731634] [client 34.22.52.222:55294] AH01630: client denied by server configuration: proxy:https://[MASKED]/.env.backup
[Sat Sep 05 22:46:55.097390 2026] [authz_core:error] [pid 731612:tid 731616] [client 34.22.52.222:55190] AH01630: client denied by server configuration: proxy:https://[MASKED]/.env.production
[Sat Sep 05 22:46:55.100563 2026] [authz_core:error] [pid 731613:tid 731637] [client 34.22.52.222:55224] AH01630: client denied by server configuration: proxy:https://[MASKED]/.env.save
[Sat Sep 05 22:46:55.100759 2026] [authz_core:error] [pid 731612:tid 731625] [client 34.22.52.222:55256] AH01630: client denied by server configuration: proxy:https://5.75.1
...
show less
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 22:12:34
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.22.52.222 (222.52.22.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.22.52.222 (222.52.22.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 18:12:27.395247 2026] [security2:error] [pid 11811:tid 11811] [client 34.22.52.222:55872] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.seashellinvitations.com"] [uri "/.env"] [unique_id "apyTy0dY-heLYefxJCmoPAAAAEA"]
show less
Brute-Force
Bad Web Bot
Web App Attack