๐ฉ๐ช
McClay
2026-08-28 17:03:03
(5 days ago)
HTTP-404 spam:34.23.143.29 - - [28/Aug/2026:19:03:03 +0200] "GET /.env.old HTTP/1.1" 404 5192 "-" "c ...
show more
HTTP-404 spam:34.23.143.29 - - [28/Aug/2026:19:03:03 +0200] "GET /.env.old HTTP/1.1" 404 5192 "-" "crusader-worker/1.0"
34.23.143.29 - - [28/Aug/2026:19:03:03 +0200] "GET /.env.prod HTTP/1.1" 404 5193 "-" "crusader-worker/1.0"
34.23.143.29 - - [28/Aug/2026:19:03:03 +0200] "GET /.env.dev HTTP/1.1" 404 5192 "-" "crusader-worker/1.0"
34.23.143.29 - - [28/Aug/2026:19:03:03 +0200] "GET /.env HTTP/1.1" 404 5193 "-" "crusader-worker/1.0"
34.23.143.29 - - [28/Aug/2026:19:03:03 +0200] "GET /.env.production HTTP/1.1" 404 5192 "-" "crusader-worker/1.0"
34.23.143.29 - - [28/Aug/2026:19:03:03 +0200] "GET /.env.save HTTP/1.1" 404 5191 "-" "crusader-worker/1.0"
34.23.143.29 - - [28/Aug/2026:19:03:03 +0200] "GET /_ignition/health-check HTTP/1.1" 404 5191 "-" "crusader-worker/1.0"
34.23.143.29 - - [28/Aug/2026:19:03:03 +0200] "GET /.env.bak HTTP/1.1" 404 5191 "-" "crusader-worker/1.0"
34.23.143.29 - - [28/Aug/2026:19:03:03 +0200] "GET /env HTTP/1.1" 404 5193 "-" "crusader-worker/1.0"
34.23.143.29 - - [28/Aug/2026:19
...
show less
Web App Attack
Anonymous
2026-08-28 16:55:01
(5 days ago)
suspicious request in access.log
Web App Attack
๐ธ๐ช
Esko
2026-08-28 16:42:01
(5 days ago)
34.23.143.29 - - [28/Aug/2026:16:42:01 +0000] "GET /.env.backup HTTP/1.1" 488 0 "-" "crusader-worker ...
show more
34.23.143.29 - - [28/Aug/2026:16:42:01 +0000] "GET /.env.backup HTTP/1.1" 488 0 "-" "crusader-worker/1.0"
show less
Web App Attack
Anonymous
2026-08-28 16:36:55
(5 days ago)
[server.tmg.gr] httpd-config-scan: sites=www.sportscardiologycongress.com; logs=/var/log/httpd/domai ...
show more
[server.tmg.gr] httpd-config-scan: sites=www.sportscardiologycongress.com; logs=/var/log/httpd/domains/sportscardiologycongress.com.log; samples=/wp-config.php.bak | /.env.example | /.env.dev
show less
Hacking
Web App Attack
๐ณ๐ฑ
Mangelot Hosting
2026-08-28 16:33:54
(5 days ago)
(wp_config_access) srv103 WordPress wp-config Scan 34.23.143.29 (US/United States/29.143.23.34.bc.go ...
show more
(wp_config_access) srv103 WordPress wp-config Scan 34.23.143.29 (US/United States/29.143.23.34.bc.googleusercontent.com): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs:
show less
Web App Attack
Anonymous
2026-08-28 16:33:05
(5 days ago)
Bot / scanning and/or hacking attempts: GET /storage/logs/laravel.log HTTP/1.1, GET /.env.bak HTTP/1 ...
show more
Bot / scanning and/or hacking attempts: GET /storage/logs/laravel.log HTTP/1.1, GET /.env.bak HTTP/1.1, GET /.env.production HTTP/1.1, GET /crusader-404-probe HTTP/1.1, GET /env HTTP/1.1, GET /_ignition/health-check HTTP/1.1, GET /.env HTTP/1.1, GET /.env.prod HTTP/1.1, GET /.env.save HTTP/1.1, GET /.env.dev HTTP/1.1, GET /wp-config.php~ HTTP/1.1, GET /.env.local HTTP/1.1, GET /wp-config.php.swp HTTP/1.1, GET /.env.backup HTTP/1.1, GET /wp-config.php.bak HTTP/1.1, GET /.env.old HTTP/1.1, GET /actuator/configprops HTTP/1.1
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 16:22:47
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 34.23.143.29 (29.143.23.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.23.143.29 (29.143.23.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 12:22:43.125832 2026] [security2:error] [pid 15473:tid 15473] [client 34.23.143.29:46218] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.hayatmotifi.com.kircali.net"] [uri "/.env.bak"] [unique_id "apG107LMNItwlNBJ0oOWfAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Hazzard
2026-08-28 15:20:15
(5 days ago)
(mod_security) mod_security triggered on hostname [redacted]): (CF_ENABLE)
SQL Injection
๐บ๐ธ
TPI-Abuse
2026-08-28 15:20:08
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 34.23.143.29 (29.143.23.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.23.143.29 (29.143.23.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 11:20:01.920455 2026] [security2:error] [pid 11134:tid 11134] [client 34.23.143.29:50366] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.mkkfactory.com"] [uri "/.env.example"] [unique_id "apGnIfSPviTVtU73Uhr2pQAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-08-28 15:02:37
(5 days ago)
Multiple WAF Violations
Web App Attack
๐ฉ๐ช
SCHAPPY
2026-08-28 14:20:27
(5 days ago)
Malicious activity from IP detected: crowdsecurity/http-sensitive-files.
Web App Attack
Hacking
๐ซ๐ท
masterguru
2026-08-28 13:33:40
(5 days ago)
Attempt to access a backup or working file. Pattern match "\\\\. (920500-193)
Hacking
๐บ๐ธ
mnsf
2026-08-28 13:06:37
(5 days ago)
Scanning/Probing (20)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 12:14:27
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 34.23.143.29 (29.143.23.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.23.143.29 (29.143.23.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 08:14:22.892250 2026] [security2:error] [pid 16605:tid 16605] [client 34.23.143.29:35696] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "boyt.org"] [uri "/.env.local"] [unique_id "apF7nk6_GNXseKvVnzvQ2QAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
verlon
2026-08-28 12:06:48
(5 days ago)
2026/08/28 14:06:45 [error] 384241#384241: *705823 access forbidden by rule, client: 34.23.143.29, s ...
show more
2026/08/28 14:06:45 [error] 384241#384241: *705823 access forbidden by rule, client: 34.23.143.29, server: gcomfort.hu, request: "GET /.env.old HTTP/2.0", host: "gcomfort.hu"
2026/08/28 14:06:45 [error] 384241#384241: *705825 access forbidden by rule, client: 34.23.143.29, server: gcomfort.hu, request: "GET /.env.bak HTTP/2.0", host: "gcomfort.hu"
2026/08/28 14:06:45 [error] 384241#384241: *705826 access forbidden by rule, client: 34.23.143.29, server: gcomfort.hu, request: "GET /.env.save HTTP/2.0", host: "gcomfort.hu"
...
show less
Hacking
Web App Attack