๐ซ๐ท
masterguru
2026-08-29 01:27:19
(11 minutes ago)
Restricted File Access Attempt. Matched phrase ".env" at REQUEST_FILENAME. (930130-201)
Hacking
Web App Attack
๐ซ๐ฎ
JLKnoch Software GmbH
2026-08-29 01:21:59
(16 minutes ago)
CrowdSec crowdsecurity/http-probing
Brute-Force
Web App Attack
๐ฉ๐ช
Nightreaver
2026-08-29 00:55:08
(43 minutes ago)
34.27.16.216 - - [29/Aug/2026:02:55:07 0200] "GET /.env.dev HTTP/1.1" 404 438 "-" "crusader-worker/ ...
show more
34.27.16.216 - - [29/Aug/2026:02:55:07 0200] "GET /.env.dev HTTP/1.1" 404 438 "-" "crusader-worker/1.0"
34.27.16.216 - - [29/Aug/2026:02:55:07 0200] "GET /.env.local HTTP/1.1" 404 438 "-" "crusader-worker/1.0"
34.27.16.216 - - [29/Aug/2026:02:55:07 0200] "GET /.env.backup HTTP/1.1" 404 438 "-" "crusader-worker/1.0"
34.27.16.216 - - [29/Aug/2026:02:55:07 0200] "GET /.env HTTP/1.1" 404 438 "-" "crusader-worker/1.0"
34.27.16.216 - - [29/Aug/2026:02:55:07 0200] "GET /.env.example HTTP/1.1" 404 438 "-" "crusader-worker/1.0"[...]
show less
Bad Web Bot
Web App Attack
Anonymous
2026-08-29 00:46:51
(52 minutes ago)
[Drupal AbuseIPDB module] Request path is blacklisted. /wp-config.php.bak
Web App Attack
Anonymous
2026-08-29 00:41:04
(57 minutes ago)
Bot / scanning and/or hacking attempts: GET /.env.example HTTP/1.1
Hacking
Web App Attack
๐บ๐ธ
mnsf
2026-08-29 00:08:58
(1 hour ago)
Abuse Detected (20)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 23:15:15
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.27.16.216 (216.16.27.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.27.16.216 (216.16.27.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 19:15:09.411753 2026] [security2:error] [pid 9941:tid 9941] [client 34.27.16.216:42050] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "debbieparisi.com"] [uri "/.env.save"] [unique_id "apIWffldmq9sj65ot2RnXwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
spot
2026-08-28 23:03:26
(2 hours ago)
34.27.16.216 - - [29/Aug/2026:00:03:25 +0100] "GET /.env.dev HTTP/1.1" 404 4656 "-" "crusader-worker ...
show more
34.27.16.216 - - [29/Aug/2026:00:03:25 +0100] "GET /.env.dev HTTP/1.1" 404 4656 "-" "crusader-worker/1.0"
...
show less
Web App Attack
VPN IP
๐บ๐ธ
TPI-Abuse
2026-08-28 20:39:15
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.27.16.216 (216.16.27.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.27.16.216 (216.16.27.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 16:39:11.757244 2026] [security2:error] [pid 6353:tid 6353] [client 34.27.16.216:41226] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jellisonrepair.com"] [uri "/.env.prod"] [unique_id "apHx74vxNs21K7t6JyGvxgAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-08-28 18:14:39
(7 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 18:12:32
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.27.16.216 (216.16.27.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.27.16.216 (216.16.27.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 14:12:25.393446 2026] [security2:error] [pid 20643:tid 20643] [client 34.27.16.216:43048] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ericgwin.com"] [uri "/.env.backup"] [unique_id "apHPiaQByLYBQFjhbBK_FwAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Lunix
2026-08-28 18:04:22
(7 hours ago)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 17:57:00
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.27.16.216 (216.16.27.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.27.16.216 (216.16.27.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 13:56:55.505116 2026] [security2:error] [pid 3356579:tid 3356649] [client 34.27.16.216:51896] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.slelectric.com"] [uri "/.env.example"] [unique_id "apHL55L1xvMbE5J0qfPfXQAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
paissangroup
2026-08-28 17:44:10
(7 hours ago)
Multiple WAF Violations
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-08-28 17:26:29
(8 hours ago)
[28/Aug/2026:20:26:28 +0300] -- 34.27.16.216 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET /s ...
show more
[28/Aug/2026:20:26:28 +0300] -- 34.27.16.216 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET /storage/logs/laravel.log HTTP/1.1
show less
Bad Web Bot
Web App Attack