🇫🇷
service Informatique
2026-09-06 04:00:37
(3 hours ago)
GET /wp-config
Web App Attack
🇳🇱
debestelapp
2026-09-06 03:25:10
(4 hours ago)
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 03:16:43
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.26.66.138 (138.66.26.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.26.66.138 (138.66.26.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 23:16:36.506392 2026] [security2:error] [pid 29860:tid 29860] [client 34.26.66.138:60414] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "deltasouls.darrenj.com"] [uri "/.env"] [unique_id "apzbFFbgmL-IwKmqWylhOQAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
WeCloudit-Anti-Abuse
2026-09-06 02:25:18
(5 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
🇺🇸
mnsf
2026-09-06 02:05:46
(5 hours ago)
Scanning/Probing (20)
Brute-Force
Web App Attack
🇳🇱
MM-bot
2026-09-06 01:47:34
(5 hours ago)
URL-probe: HTTP/1.1 GET request on /.env.dev (2026-09-06 03:47:34 UTC+2)
Web App Attack
Hacking
🇳🇱
Webhoster
2026-09-06 01:43:37
(6 hours ago)
CrowdSec detected crowdsecurity/http-probing on a monitored service.
Web App Attack
Anonymous
2026-09-06 01:41:36
(6 hours ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-06 01:08:48
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.26.66.138 (138.66.26.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.26.66.138 (138.66.26.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 21:08:42.264477 2026] [security2:error] [pid 19361:tid 19361] [client 34.26.66.138:56228] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.gellertdealers.com"] [uri "/.env.bak"] [unique_id "apy9GhGIoMDXWBfVQQRVXgAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-05 22:53:58
(8 hours ago)
(config_exploit_scan) Configuratie Scanner / Nep GPTBot 34.26.66.138 (US/United States/138.66.26.34. ...
show more
(config_exploit_scan) Configuratie Scanner / Nep GPTBot 34.26.66.138 (US/United States/138.66.26.34.bc.googleusercontent.com): 3 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 34.26.66.138 - - [06/Sep/2026:00:53:57 +0200] "GET /.env.backup HTTP/1.1" 406 4830 "-" "crusader-worker/1.0"
34.26.66.138 - - [06/Sep/2026:00:53:57 +0200] "GET /.env.dev HTTP/1.1" 406 4830 "-" "crusader-worker/1.0"
34.26.66.138 - - [06/Sep/2026:00:53:57 +0200] "GET /.env.old HTTP/1.1" 406 4829 "-" "crusader-worker/1.0"
show less
Port Scan
🇫🇷
SpaceHost-Server
2026-09-05 22:19:37
(9 hours ago)
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 22:15:46
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.26.66.138 (138.66.26.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.26.66.138 (138.66.26.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 18:15:40.365089 2026] [security2:error] [pid 27687:tid 27687] [client 34.26.66.138:40560] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "network.redtraffic.media"] [uri "/.env.local"] [unique_id "apyUjJs00MpNEsWD6_0yOAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
macrob
2026-09-05 21:54:20
(9 hours ago)
2026/09/05 21:54:18 [error] 1902784#1902784: *560753277 access forbidden by rule, client: 34.26.66.1 ...
show more
2026/09/05 21:54:18 [error] 1902784#1902784: *560753277 access forbidden by rule, client: 34.26.66.138, server: binixo.com, request: "GET /.env.example HTTP/2.0", host: "binixo.com"
2026/09/05 21:54:18 [error] 1902787#1902787: *560753279 access forbidden by rule, client: 34.26.66.138, server: binixo.com, request: "GET /.env.old HTTP/2.0", host: "binixo.com"
2026/09/05 21:54:18 [error] 1902787#1902787: *560753285 access forbidden by rule, client: 34.26.66.138, server: binixo.com, request: "GET /.env.save HTTP/2.0", host: "binixo.com"
...
show less
Web App Attack
🇮🇹
VHosting
2026-09-05 21:50:03
(9 hours ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 20:37:20
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.26.66.138 (138.66.26.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.26.66.138 (138.66.26.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 16:37:16.755144 2026] [security2:error] [pid 8613:tid 8613] [client 34.26.66.138:56836] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.bbproductionsonline.com"] [uri "/wp-config.php.swp"] [unique_id "apx9fDWREfaOoZfcHTutCwAAAC4"]
show less
Brute-Force
Bad Web Bot
Web App Attack