🇳🇱
homeshowdomain.nl
2026-08-29 22:00:40
(12 hours ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-08-28.
show less
Web App Attack
SSH
Hacking
🇺🇸
TPI-Abuse
2026-08-29 01:30:18
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.28.228.123 (123.228.28.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.28.228.123 (123.228.28.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 21:30:14.243987 2026] [security2:error] [pid 2627:tid 2627] [client 34.28.228.123:42206] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mexicanfriedicecream.com"] [uri "/.env.example"] [unique_id "apI2JlIFBiCbSUylTvsxVgAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-29 01:20:41
(1 day ago)
(config_exploit_scan) Configuratie Scanner / Nep GPTBot 34.28.228.123 (US/United States/123.228.28.3 ...
show more
(config_exploit_scan) Configuratie Scanner / Nep GPTBot 34.28.228.123 (US/United States/123.228.28.34.bc.googleusercontent.com): 3 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 34.28.228.123 - - [29/Aug/2026:03:20:39 +0200] "GET /.env.production HTTP/1.1" 406 4830 "-" "crusader-worker/1.0"
34.28.228.123 - - [29/Aug/2026:03:20:39 +0200] "GET /.env.dev HTTP/1.1" 406 4830 "-" "crusader-worker/1.0"
34.28.228.123 - - [29/Aug/2026:03:20:39 +0200] "GET /.env.prod HTTP/1.1" 406 4830 "-" "crusader-worker/1.0"
show less
Port Scan
🇩🇪
LRob
2026-08-29 01:11:32
(1 day ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /wp-config.php.swp (+12 more) | 2026-08-29 01:11 UTC
show less
Hacking
Web App Attack
🇨🇭
ca
2026-08-29 00:31:13
(1 day ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
🇺🇸
mnsf
2026-08-29 00:08:34
(1 day ago)
Abuse Detected (12)
Brute-Force
Web App Attack
🇧🇪
Saec
2026-08-28 23:54:01
(1 day ago)
Jarvis auto-ban: CF top attacker on saec.me (26 hits, US)
Port Scan
Web App Attack
🇬🇧
dwmosaics
2026-08-28 23:53:54
(1 day ago)
"GET /.env.example HTTP/1.1" 404 4977 "-" "crusader-worker/1.0"
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-08-28 23:50:10
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.28.228.123 (123.228.28.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.28.228.123 (123.228.28.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 19:50:04.698019 2026] [security2:error] [pid 19741:tid 19741] [client 34.28.228.123:33172] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.ultratec.com.mx.activethinkers.net"] [uri "/.env.backup"] [unique_id "apIerOM9LxIVUDsnjfnoeQAAADM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
Petros Stefanakis
2026-08-28 23:39:42
(1 day ago)
(mod_security) mod_security triggered on hostname [redacted] 34.28.228.123 (US/United States/123.228 ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.28.228.123 (US/United States/123.228.28.34.bc.googleusercontent.com)
show less
SQL Injection
🇺🇸
factor1
2026-08-28 23:18:12
(1 day ago)
CrowdSec at saturn Reports Abuse
Web App Attack
🇺🇸
TPI-Abuse
2026-08-28 23:10:57
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.28.228.123 (123.228.28.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.28.228.123 (123.228.28.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 19:10:51.920118 2026] [security2:error] [pid 23855:tid 23855] [client 34.28.228.123:44168] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.chaletparkaparts.com.handankoc.net"] [uri "/.env.save"] [unique_id "apIVe9OnoCIdLqL6PCAktQAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
lns.bz
2026-08-28 22:54:16
(1 day ago)
Too many 404 requests [DOPP]
Web App Attack
🇺🇸
TPI-Abuse
2026-08-28 22:47:45
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.28.228.123 (123.228.28.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.28.228.123 (123.228.28.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 18:47:38.024289 2026] [security2:error] [pid 5963:tid 5963] [client 34.28.228.123:41680] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "toepert.net"] [uri "/.env.local"] [unique_id "apIQCgIRQd0-7l_d75_T4QAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇮
mnazibo
2026-08-28 22:00:08
(1 day ago)
Date: 29/Aug/2026 00:57:23 | Reported IP: 34.28.228.123 mod_security | id: 930130 | US/group.my_doma ...
show more
Date: 29/Aug/2026 00:57:23 | Reported IP: 34.28.228.123 mod_security | id: 930130 | US/group.my_domain/- | Connections: 18 | Blocked: Permanent Block: [LF_MODSEC] | URIs: /%2eenv; /.env; /.env.; /.env/; //.env; /.ENV; /.env.backup; /.env.bak; /.env.dev; /.env.example; /.env.local; /.env.old; /.env.prod; /.env.production; /.env.save; /wp-config.php~; /wp-config.php.bak; /wp-config.php.swp | Logs: Restricted File Access Attempt
show less
SQL Injection
Brute-Force
Bad Web Bot