🇧🇾
lns.bz
2026-09-06 06:04:56
(1 hour ago)
.env scanning [BY]
Web App Attack
🇩🇪
LRob
2026-09-06 03:56:40
(3 hours ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /.vscode/mcp.json (+1 more) | 2026-09-06 03:56 UTC
show less
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 03:32:25
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.22.90.58 (58.90.22.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.22.90.58 (58.90.22.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 23:32:18.863315 2026] [security2:error] [pid 28176:tid 28176] [client 34.22.90.58:54262] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "premaindustrial.com"] [uri "/.env.example"] [unique_id "apzewodKOpv8chtyXZYSbQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 01:58:57
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.22.90.58 (58.90.22.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.22.90.58 (58.90.22.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 21:58:50.530963 2026] [security2:error] [pid 3314:tid 3314] [client 34.22.90.58:48310] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "maledon.com"] [uri "/.env"] [unique_id "apzI2m43Szwf0nXDS-ns6gAAADw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
e.fierstra
2026-09-06 01:49:04
(5 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
🇬🇧
consul.to
2026-09-06 01:19:47
(6 hours ago)
Web attack/malicious scanning detected
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 00:32:53
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.22.90.58 (58.90.22.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.22.90.58 (58.90.22.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 20:32:48.806401 2026] [security2:error] [pid 29211:tid 29211] [client 34.22.90.58:45950] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bodyworkbydallas.com"] [uri "/.env.production"] [unique_id "apy0sCQgyDTa00FOma2oJwAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
antlac1
2026-09-06 00:32:31
(7 hours ago)
crowdsecurity/http-probing
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 23:56:26
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.22.90.58 (58.90.22.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.22.90.58 (58.90.22.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 19:56:19.761125 2026] [security2:error] [pid 13457:tid 13457] [client 34.22.90.58:41710] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.ik3co.com"] [uri "/wp-config.php~"] [unique_id "apysI0FV1ZWS3dOnrjh0OAAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 23:38:09
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.22.90.58 (58.90.22.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.22.90.58 (58.90.22.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 19:38:02.097130 2026] [security2:error] [pid 11715:tid 11715] [client 34.22.90.58:37500] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "grmvrr.com"] [uri "/wp-config.php.bak"] [unique_id "apyn2t2wqNLI2G4XCIm7cQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-05 22:54:53
(8 hours ago)
[da.kdns.gr] httpd-config-scan: logs=/var/log/httpd/access_log; samples=/.env | /.env.old | /.env.ba ...
show more
[da.kdns.gr] httpd-config-scan: logs=/var/log/httpd/access_log; samples=/.env | /.env.old | /.env.bak
show less
Hacking
Web App Attack
🇳🇱
BlueWire Hosting
2026-09-05 22:53:41
(8 hours ago)
Probing websites for vulnerabilities
Web App Attack
🇳🇱
SysAdmin Dylan
2026-09-05 22:39:26
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.22.90.58 (KR/South Korea/58.90.22.34.bc.goog ...
show more
(mod_security) mod_security (id:210492) triggered by 34.22.90.58 (KR/South Korea/58.90.22.34.bc.googleusercontent.com): 10 in the last 3600 secs
show less
Brute-Force
🇺🇸
TPI-Abuse
2026-09-05 22:33:07
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.22.90.58 (58.90.22.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.22.90.58 (58.90.22.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 18:33:01.520407 2026] [security2:error] [pid 26895:tid 26895] [client 34.22.90.58:54798] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "tomartsmedia.org"] [uri "/.env.backup"] [unique_id "apyYncwEBwbnGdCinJnxFgAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
mnsf
2026-09-05 22:05:58
(9 hours ago)
Scanning/Probing (11)
Brute-Force
Web App Attack