🇫🇷
service Informatique
2026-08-28 04:00:37
(3 days ago)
GET /wp-config
Web App Attack
🇳🇱
Eric
2026-08-27 21:21:01
(3 days ago)
[Thu Aug 27 21:21:01.143430 2026] [security2:error] [pid 3678749:tid 3678749] [client 34.23.17.167:3 ...
show more
[Thu Aug 27 21:21:01.143430 2026] [security2:error] [pid 3678749:tid 3678749] [client 34.23.17.167:35588] [client 34.23.17.167] ModSecurity: Warning. Pattern match "^[\\\\d.:]+$" at REQUEST_HEADERS:host. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "736"] [id "920350"] [msg "Host header is a numeric IP address"] [data "94.209.38.171"] [severity "WARNING"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "94.209.38.171"] [uri "/.env"] [unique_id "apCqPeTFjskNaJjLV8nTFQAAAAY"]
[Thu Aug 27 21:21:01.144238 2026] [security2:error] [pid 3678749:tid 3678749] [client 34.23.17.167:35588] [client 34.23.17.167] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "
...
show less
Hacking
Web App Attack
🇷🇺
lns.bz
2026-08-27 20:59:48
(3 days ago)
.env scanning [RU.MTW]
Web App Attack
🇳🇴
jad-abuse
2026-08-27 20:31:42
(3 days ago)
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: env_probe ...
show more
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: env_probe, scanner_ua, source_backup, actuator, config_backup, ignition_debug. Observed by 1 sensor(s); 19 hits.
show less
Hacking
Web App Attack
🇵🇱
webadmin
2026-08-27 20:23:15
(3 days ago)
2026-08-27T22:23:15.117619+02:00 tytan csmpro-api[3056]: [error] client: 34.23.17.167 server: 195.11 ...
show more
2026-08-27T22:23:15.117619+02:00 tytan csmpro-api[3056]: [error] client: 34.23.17.167 server: 195.116.29.58, request: "GET", url: http://195.116.29.58/.env [404]: Not Found
2026-08-27T22:23:15.117619+02:00 tytan csmpro-api[3056]: [error] client: 34.23.17.167 server: 195.116.29.58, request: "GET", url: http://195.116.29.58/.env.save [404]: Not Found
2026-08-27T22:23:15.117619+02:00 tytan csmpro-api[3056]: [error] client: 34.23.17.167 server: 195.116.29.58, request: "GET", url: http://195.116.29.58/.env.dev [404]: Not Found
2026-08-27T22:23:15.117619+02:00 tytan csmpro-api[3056]: [error] client: 34.23.17.167 server: 195.116.29.58, request: "GET", url: http://195.116.29.58/.env.production [404]: Not Found
show less
Web App Attack
🇩🇪
Balthasar Morpheus Jörmundur (JKweb Service)
2026-08-27 19:33:53
(3 days ago)
JKweb Security: Severe and dangerous web attack detected. Vulnerability Wordpress Scanning, Director ...
show more
JKweb Security: Severe and dangerous web attack detected. Vulnerability Wordpress Scanning, Directory Brute-Forcing / Content Discovery, Predictable Resource Location / Forced Browsing, Scan for administration and debugging interfaces of modern frameworks, Scan for Spring Boot Actuator Leaks, Scan for Cloud & Infrastructure Credentials, Scan for Database & Backup Dumps, Scan for IDE- und Editor-Configurations, Scan for CI/CD Pipelines & GitHub Workflows etc. The Attacker is permanently banned by Fail2Ban, configurate by JKweb Security a brand of JKweb Service.
show less
Port Scan
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-27 19:24:33
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.23.17.167 (167.17.23.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.23.17.167 (167.17.23.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 15:24:27.147934 2026] [security2:error] [pid 27348:tid 27348] [client 34.23.17.167:55136] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.me.ctemdr.com"] [uri "/.env"] [unique_id "apCO610vAYy_gPUZAKmDLAAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
WeCloudit-Anti-Abuse
2026-08-27 18:50:34
(3 days ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
🇫🇷
dynamix
2026-08-27 18:09:26
(3 days ago)
Multiple WAF Violations
Web App Attack
🇺🇸
TPI-Abuse
2026-08-27 17:57:24
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.23.17.167 (167.17.23.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.23.17.167 (167.17.23.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 13:57:17.315697 2026] [security2:error] [pid 15828:tid 15828] [client 34.23.17.167:58010] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "pembrokefinance.com"] [uri "/.env.bak"] [unique_id "apB6fT-vAocOWfpZDcSsEwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-27 17:41:11
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.23.17.167 (167.17.23.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.23.17.167 (167.17.23.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 13:41:05.071119 2026] [security2:error] [pid 22340:tid 22340] [client 34.23.17.167:32900] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.clarkns.ryanc.net"] [uri "/.env.prod"] [unique_id "apB2sfvN6kksspJkIggScQAAACI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-27 16:37:45
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.23.17.167 (167.17.23.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.23.17.167 (167.17.23.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 12:37:39.789405 2026] [security2:error] [pid 12844:tid 12844] [client 34.23.17.167:44394] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "badwaterclaims.com"] [uri "/wp-config.php~"] [unique_id "apBn0_F2tgUtzGwEhEfbrQAAAB8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-27 15:16:57
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.23.17.167 (167.17.23.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.23.17.167 (167.17.23.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 11:16:51.380530 2026] [security2:error] [pid 503:tid 503] [client 34.23.17.167:40104] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "winestoria.com"] [uri "/.env.prod"] [unique_id "apBU45uyz7rI33n2oIynKwAAACE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-27 15:10:09
(3 days ago)
| Suspicious URL access.
Web App Attack
Hacking
SQL Injection
🇷🇴
clauss
2026-08-27 13:18:17
(3 days ago)
34.23.17.167 - - [27/Aug/2026:16:18:16 +0300] "GET /.env.old HTTP/1.1" 403 358 "-" "crusader-worker/ ...
show more
34.23.17.167 - - [27/Aug/2026:16:18:16 +0300] "GET /.env.old HTTP/1.1" 403 358 "-" "crusader-worker/1.0"
34.23.17.167 - - [27/Aug/2026:16:18:16 +0300] "GET /.env.production HTTP/1.1" 403 358 "-" "crusader-worker/1.0"
...
show less
Web App Attack