๐ณ๐ฑ
homeshowdomain.nl
2026-08-28 22:00:56
(2 days ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-08-27.
show less
Web App Attack
SSH
Hacking
๐ซ๐ท
ACE-INFORMATIQUE.NC
2026-08-28 19:00:06
(2 days ago)
Web App Attack blocked by Fail2ban
Web App Attack
๐ฉ๐ช
Hazzard
2026-08-27 22:06:39
(3 days ago)
(mod_security) mod_security triggered on hostname [redacted]): (CF_ENABLE)
SQL Injection
๐ฉ๐ช
Michel Wijnberg
2026-08-27 21:10:11
(3 days ago)
34.31.55.226 - - [27/Aug/2026:21:10:10 +0000] "GET /.env HTTP/1.1" 444 0 "-" "crusader-worker/1.0"
. ...
show more
34.31.55.226 - - [27/Aug/2026:21:10:10 +0000] "GET /.env HTTP/1.1" 444 0 "-" "crusader-worker/1.0"
...
show less
Bad Web Bot
Web App Attack
๐ซ๐ท
COMAITE
2026-08-27 21:00:11
(3 days ago)
Suspicious URL access.
Web App Attack
๐ฉ๐ช
big-cloud.nl
2026-08-27 20:16:03
(3 days ago)
Try to access /.env
Web App Attack
Anonymous
2026-08-27 19:34:27
(3 days ago)
[Thu Aug 27 19:34:17.652025 2026] [security2:error] [pid 498891:tid 498891] [client 34.31.55.226:328 ...
show more
[Thu Aug 27 19:34:17.652025 2026] [security2:error] [pid 498891:tid 498891] [client 34.31.55.226:32834] [client 34.31.55.226] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 8)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "95.211.63.1"] [uri "/storage/logs/laravel.log"] [unique_id "apCROds0qI1kAPBvcsg8uAAAAAE"]
[Thu Aug 27 19:34:17.660117 2026] [security2:error] [pid 501722:tid 501722] [client 34.31.55.226:60966] [client 34.31.55.226] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score:
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 19:23:19
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.31.55.226 (226.55.31.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.31.55.226 (226.55.31.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 15:23:12.161450 2026] [security2:error] [pid 31749:tid 31749] [client 34.31.55.226:55586] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "paulsingdahlsen.com"] [uri "/.env.backup"] [unique_id "apCOoMHegpRaLy3ZlfbIKgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-27 18:57:04
(3 days ago)
Http Port:80 (http_status:400) - Agent:-
Web App Attack
๐ฎ๐น
clamehost.it
2026-08-27 18:08:04
(3 days ago)
Automatic report - Brute Force attack using this IP address
Brute-Force
๐ฉ๐ช
MarkGGN
2026-08-27 17:59:25
(3 days ago)
Web attack. 34.31.55.226 - - [27/Aug/2026:19:59:24 +0200] "GET /wp-config.php.swp HTTP/1.1" 401 172 ...
show more
Web attack. 34.31.55.226 - - [27/Aug/2026:19:59:24 +0200] "GET /wp-config.php.swp HTTP/1.1" 401 172 "-" "crusader-worker/1.0"
34.31.55.226 - - [27/Aug/2026:19:59:24 +0200] "GET /wp-config.php.bak HTTP/1.1" 401 172 "-" "crusader-worker/1.0"
show less
Web App Attack
๐ซ๐ท
dynamix
2026-08-27 17:39:26
(3 days ago)
Multiple WAF Violations
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-08-27 17:03:36
(3 days ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐ญ๐บ
bcsaba
2026-08-27 16:59:07
(3 days ago)
Probing for .env file:
34.31.55.226 - - [27/Aug/2026:14:13:22 +0200] "GET /.env.save HTTP/1.1" 403 1 ...
show more
Probing for .env file:
34.31.55.226 - - [27/Aug/2026:14:13:22 +0200] "GET /.env.save HTTP/1.1" 403 146 "-" "crusader-worker/1.0"
show less
Web App Attack
๐ฐ๐ท
eungyeol15
2026-08-27 16:40:23
(3 days ago)
[daon] Web scan/abuse: 1 events (web_probe). paths: GET /.env.dev -> 404. sample: 34.31.55.226 - - [ ...
show more
[daon] Web scan/abuse: 1 events (web_probe). paths: GET /.env.dev -> 404. sample: 34.31.55.226 - - [28/Aug/2026:01:40:23 +0900] "GET /.env.dev HTTP/1.1" 404 207 "-" "crusader-worker/1.0"
show less
Web App Attack
Hacking