Anonymous
2026-07-29 07:00:00
(1 month ago)
Apache probe; attempts=297; exact paths: /.env | /.env.backup | /.env.backup1 | /.env.backup2 | /.en ...
show more
Apache probe; attempts=297; exact paths: /.env | /.env.backup | /.env.backup1 | /.env.backup2 | /.env.bak | /.env.ci | /.env.dev | /.env.development | /.env.dist | /.env.docker | /.env.example | /.env.json | /.env.live | /.env.local | /.env.old | /.env.preprod | /.env.prod | /.env.production | /.env.remote | /.env.sample | /.env.save | /.env.stage | /.env.staging | /.env.swp | /.env.test | /.env.txt | /.env.uat | /.env.yaml | /.env.yml | /.env~ | /.git/.env | /.git/config | /.git/config/ | /actions/.env | /admin-panel/.env | /admin/.env | /administrator/.env | /angular/.env | /ansible/.env | /api/.env | /api/dev/.env | /api/staging/.env | /api/v1/.env | /api/v2/.env | /api/v3/.env | /app/.env | /application/.env | /apps/.env | /assets/.env | /aws/.env | /azure/.env | /backend/.env | /backup/.env | /backups/.env | /beta/.env | /bin/.env | /bootstrap/.env | /brevo/.env | /build/.env | /buildkite/.env | /bulk/. | ... [205 exact paths total]
show less
Web App Attack
🇧🇪
taivas.nl
2026-07-28 04:32:52
(1 month ago)
Many_bad_calls
Web App Attack
🇬🇧
consul.to
2026-07-27 22:08:58
(1 month ago)
Web attack/malicious scanning detected
Web App Attack
🇺🇸
TPI-Abuse
2026-07-27 22:06:03
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 34.221.132.33 (ec2-34-221-132-33.us-west-2.comp ...
show more
(mod_security) mod_security (id:210492) triggered by 34.221.132.33 (ec2-34-221-132-33.us-west-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 18:05:58.933176 2026] [security2:error] [pid 217271:tid 217271] [client 34.221.132.33:45756] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.jwphotodesign.jonathanwilson.me"] [uri "/.git/config"] [unique_id "amfWRmmTtGejoPjoZCJFlAAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-07-27 20:54:50
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 34.221.132.33 (ec2-34-221-132-33.us-west-2.comp ...
show more
(mod_security) mod_security (id:210492) triggered by 34.221.132.33 (ec2-34-221-132-33.us-west-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 16:54:42.943860 2026] [security2:error] [pid 2104566:tid 2104566] [client 34.221.132.33:56800] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.jvwebinars.vanemby.com"] [uri "/.git/config"] [unique_id "amfFkipRsAyslo9Tgl_8jgAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇸🇪
vaia.cloud
2026-07-27 20:10:02
(1 month ago)
crowdsecurity/http-admin-interface-probing
Brute-Force
Web App Attack
🇳🇱
Site.eu
2026-07-27 18:59:18
(1 month ago)
Excessive multi-domain requests
Brute-Force
Anonymous
2026-07-27 17:09:43
(1 month ago)
(caddyscan) Scanner path probe from 34.221.132.33 (US/United States/ec2-34-221-132-33.us-west-2.comp ...
show more
(caddyscan) Scanner path probe from 34.221.132.33 (US/United States/ec2-34-221-132-33.us-west-2.compute.amazonaws.com): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 2627 34.221.132.33 - - [27/Jul/2026:17:09:39 +0000] "GET /.git/config HTTP/1.1"
[REDACTED] 200 2627 34.221.132.33 - - [27/Jul/2026:17:09:39 +0000] "GET /.env HTTP/1.1"
[REDACTED] 200 2627 34.221.132.33 - - [27/Jul/2026:17:09:39 +0000] "GET /.env.local HTTP/1.1"
[REDACTED] 200 2627 34.221.132.33 - - [27/Jul/2026:17:09:39 +0000] "GET /.env.production HTTP/1.1"
[REDACTED] 200 2627 34.221.132.33 - - [27/Jul/2026:17:09:39 +0000] "GET /.env.staging HTTP/1.1"
show less
Port Scan
🇺🇸
TPI-Abuse
2026-07-27 16:14:00
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 34.221.132.33 (ec2-34-221-132-33.us-west-2.comp ...
show more
(mod_security) mod_security (id:210492) triggered by 34.221.132.33 (ec2-34-221-132-33.us-west-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 12:13:54.842322 2026] [security2:error] [pid 14752:tid 14752] [client 34.221.132.33:48706] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.justkoolit.onlyincanada-eh.com"] [uri "/.git/config"] [unique_id "ameDwqdGXoiiw9fGZFtgHQAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
Lee Daniel
2026-07-27 14:09:53
(1 month ago)
34.221.132.33 - - [27/Jul/2026:10:09:53 -0400] "GET /.env HTTP/1.1" 403 6309 "-" "Mozilla/5.0 (X11; ...
show more
34.221.132.33 - - [27/Jul/2026:10:09:53 -0400] "GET /.env HTTP/1.1" 403 6309 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
DDoS Attack
Web Spam
Email Spam
Port Scan
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
dynamix
2026-07-27 12:19:16
(1 month ago)
Multiple WAF Violations
Web App Attack
🇺🇸
TPI-Abuse
2026-07-27 12:18:32
(1 month ago)
(mod_security) mod_security (id:210730) triggered by 34.221.132.33 (ec2-34-221-132-33.us-west-2.comp ...
show more
(mod_security) mod_security (id:210730) triggered by 34.221.132.33 (ec2-34-221-132-33.us-west-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 08:18:28.580004 2026] [security2:error] [pid 3244688:tid 3244688] [client 34.221.132.33:35628] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.just4uscrubs.quickasawink.org|F|2"] [data ".env.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.just4uscrubs.quickasawink.org"] [uri "/.env.bak"] [unique_id "amdMlMp4qFKGHWhWFOXSWQAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-07-27 10:52:13
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 34.221.132.33 (ec2-34-221-132-33.us-west-2.comp ...
show more
(mod_security) mod_security (id:210492) triggered by 34.221.132.33 (ec2-34-221-132-33.us-west-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 06:52:07.942498 2026] [security2:error] [pid 2318221:tid 2318376] [client 34.221.132.33:44820] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.jurisdoctorate.org.aafm.us"] [uri "/.git/config"] [unique_id "amc4V4flpnRwa9G8FTuQ-AAAAYU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
masterguru
2026-07-27 10:39:24
(1 month ago)
Restricted File Access Attempt. Matched phrase ".git/" at REQUEST_FILENAME. (930130-193)
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-07-27 09:45:46
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 34.221.132.33 (ec2-34-221-132-33.us-west-2.comp ...
show more
(mod_security) mod_security (id:210492) triggered by 34.221.132.33 (ec2-34-221-132-33.us-west-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 05:45:40.939775 2026] [security2:error] [pid 102447:tid 102483] [client 34.221.132.33:60886] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.jupitermaturin.com.venezuelaguia.com"] [uri "/.git/config"] [unique_id "amcoxCkyUcHb3CyVF0PmKwAAAIQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack