πΊπΈ
ShadowWhisperer
2026-08-27 22:31:12
(2 hours ago)
HTTP GET /.env UA: crusader-worker/1.0
Web App Attack
π©πͺ
jeannelboutique
2026-08-27 21:31:19
(3 hours ago)
(mod_security) mod_security triggered on hostname [redacted] 34.30.93.42 (US/United States/42.93.30. ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.30.93.42 (US/United States/42.93.30.34.bc.googleusercontent.com)
show less
SQL Injection
π©πͺ
pltcldvlpr
2026-08-27 21:03:14
(4 hours ago)
CMS/framework probe: 34.30.93.42 - - [27/Aug/2026:23:03:13 +0200] "GET /.env HTTP/1.1" 444 0 "-" "cr ...
show more
CMS/framework probe: 34.30.93.42 - - [27/Aug/2026:23:03:13 +0200] "GET /.env HTTP/1.1" 444 0 "-" "crusader-worker/1.0" asn=396982 org="Google LLC" country=US
...
show less
Web App Attack
Anonymous
2026-08-27 20:44:41
(4 hours ago)
[Thu Aug 27 22:44:39.865966 2026] [:error] [pid 1891107:tid 1891107] [client 34.30.93.42:36858] ModS ...
show more
[Thu Aug 27 22:44:39.865966 2026] [:error] [pid 1891107:tid 1891107] [client 34.30.93.42:36858] ModSecurity: Warning. Matched "Operator `Within' with parameter `.ani/ .asa/ .asax/ .ascx/ .back/ .backup/ .bak/ .bck/ .bk/ .bkp/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .cnf/ .com/ .compositefont/ .config/ .conf/ .copy/ .crt/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dist/ .dll (447 characters omitted)' against variable `TX:EXTENSION' (Value: `.backup/' ) [file "/usr/local/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1127"] [id "920440"] [rev ""] [msg "URL file extension is restricted by policy"] [data ".backup"] [severity "2"] [ver "OWASP_CRS/4.30.0-dev"] [maturity "0"] [accuracy "0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/PROTOCOL-ENFORCEMENT"] [tag "capec/1000/210/272"] [uri "/.env.backup"] [unique_id "178786347962.808149"] [ref "o4,7o
...
show less
Web App Attack
π΅π±
lns.bz
2026-08-27 20:30:17
(4 hours ago)
Web app attack [PL.Lu]
Exploited Host
Web App Attack
π©πͺ
initsol
2026-08-27 20:16:30
(4 hours ago)
[Thu Aug 27 22:16:29.743533 2026] [authz_core:error] [pid 719458:tid 719458] [client 34.30.93.42:445 ...
show more
[Thu Aug 27 22:16:29.743533 2026] [authz_core:error] [pid 719458:tid 719458] [client 34.30.93.42:44512] AH01630: client denied by server configuration: /var/www/.env.example
[Thu Aug 27 22:16:29.743963 2026] [authz_core:error] [pid 652099:tid 652099] [client 34.30.93.42:44538] AH01630: client denied by server configuration: /var/www/storage
[Thu Aug 27 22:16:29.744284 2026] [authz_core:error] [pid 719456:tid 719456] [client 34.30.93.42:44456] AH01630: client denied by server configuration: /var/www/actuator
...
show less
Brute-Force
πΊπΈ
TPI-Abuse
2026-08-27 18:57:58
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.30.93.42 (42.93.30.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.30.93.42 (42.93.30.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 14:57:52.417855 2026] [security2:error] [pid 29012:tid 29012] [client 34.30.93.42:35958] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.rwcartoons.com"] [uri "/wp-config.php.swp"] [unique_id "apCIsAbOAY6689nBBeo17AAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π¨π¦
polycoda
2026-08-27 18:54:24
(6 hours ago)
AutoBlock: π― Vulnerability Scanner (Non Decay-Based) - βͺοΈ Excessive 30X Errors (Decay-Based)
Hacking
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-27 18:25:36
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.30.93.42 (42.93.30.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.30.93.42 (42.93.30.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 14:25:27.773851 2026] [security2:error] [pid 19622:tid 19622] [client 34.30.93.42:47780] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "rwabutazafoundation.org"] [uri "/.env.bak"] [unique_id "apCBF-PU-p2DYidsPyl41AAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-27 18:05:06
(7 hours ago)
suspicious request in access.log
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-27 17:48:51
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.30.93.42 (42.93.30.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.30.93.42 (42.93.30.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 13:48:44.697826 2026] [security2:error] [pid 24945:tid 24945] [client 34.30.93.42:35248] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.genies-bottle.nmorganist.org"] [uri "/.env.bak"] [unique_id "apB4fHPDUV_D4R2ivzY1WQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-27 17:10:16
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.30.93.42 (42.93.30.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.30.93.42 (42.93.30.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 13:10:11.733137 2026] [security2:error] [pid 23921:tid 24048] [client 34.30.93.42:49792] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.coloradospringsmardigras.aafm.us"] [uri "/.env.prod"] [unique_id "apBvcybNpIAoKLk2P_a-TgAAAgc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-27 16:37:43
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.30.93.42 (42.93.30.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.30.93.42 (42.93.30.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 12:37:36.441932 2026] [security2:error] [pid 31876:tid 31876] [client 34.30.93.42:60950] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "catalog.apuntesdeinversion.com"] [uri "/.env.local"] [unique_id "apBn0KyIYZFhnA9A6w2UnQAAACE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π―π΅
VXG-NET
2026-08-27 16:30:06
(8 hours ago)
port=80, indicator_type=info-leak
Hacking
πΊπΈ
rsa
2026-08-27 16:20:00
(8 hours ago)
GET /.env HTTP/2.0
DDoS Attack
Brute-Force
Exploited Host
Web App Attack
Hacking