🇩🇪
Phenix Info
2026-09-06 06:29:13
(14 hours ago)
SmallGuard.fr - Forbidden Ext.
Web App Attack
Anonymous
2026-09-06 06:21:33
(14 hours ago)
git/env leak probe
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 03:55:06
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.39.247.99 (99.247.39.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.39.247.99 (99.247.39.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 23:54:58.159838 2026] [security2:error] [pid 16551:tid 16551] [client 34.39.247.99:36522] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.spacebooger.com"] [uri "/.env.save"] [unique_id "apzkEuRuRjpzKGKxyRLczgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
XICTRON
2026-09-06 03:25:06
(17 hours ago)
ModSecurity rule violation detected by Fail2Ban
Web App Attack
🇫🇷
✨
2026-09-06 03:22:09
(17 hours ago)
Domain : dev-naturalhealthwholesale.irish
Rule : hack
2026-09-06 03:20:36 ***hidden-privacy*** GET / ...
show more
Domain : dev-naturalhealthwholesale.irish
Rule : hack
2026-09-06 03:20:36 ***hidden-privacy*** GET /wp-config.php.bak - 443 - 34.39.247.99 HTTP/1.1 crusader-worker/1.0 - dev-naturalhealthwholesale.irish 404 0 2 1583 121 196 - -
show less
Hacking
SQL Injection
Brute-Force
🇺🇸
TPI-Abuse
2026-09-06 02:27:57
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.39.247.99 (99.247.39.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.39.247.99 (99.247.39.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 22:27:53.182301 2026] [security2:error] [pid 10407:tid 10407] [client 34.39.247.99:44236] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "solutionsint.com.crestrong.com"] [uri "/.env.example"] [unique_id "apzPqTh2rSqtJvP_l06N8AAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 01:48:47
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.39.247.99 (99.247.39.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.39.247.99 (99.247.39.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 21:48:40.823020 2026] [security2:error] [pid 20569:tid 20569] [client 34.39.247.99:43618] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "rvtrips.robin5on.com"] [uri "/.env.example"] [unique_id "apzGeEPk-Yb8DslpeGG0NQAAADU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
✨
2026-09-06 01:41:09
(19 hours ago)
Domain : yourface.me.uk
Rule : env
2026-09-06 01:39:48 ***hidden-privacy***46 GET /.env.prod - 80 - ...
show more
Domain : yourface.me.uk
Rule : env
2026-09-06 01:39:48 ***hidden-privacy***46 GET /.env.prod - 80 - 34.39.247.99 HTTP/1.1 crusader-worker/1.0 - yourface.me.uk 404 0 2 1336 95 513 - -
show less
Hacking
SQL Injection
🇺🇸
TPI-Abuse
2026-09-06 01:09:23
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.39.247.99 (99.247.39.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.39.247.99 (99.247.39.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 21:09:15.356306 2026] [security2:error] [pid 17770:tid 17770] [client 34.39.247.99:60156] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.internet-brochures.com"] [uri "/.env.production"] [unique_id "apy9O9xOO1kzvFCYAjVVFgAAACU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
FD-IX
2026-09-06 00:55:55
(19 hours ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 00:37:05
(20 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.39.247.99 (99.247.39.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.39.247.99 (99.247.39.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 20:36:59.091562 2026] [security2:error] [pid 12604:tid 12604] [client 34.39.247.99:52348] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "honorherwish.org"] [uri "/.env"] [unique_id "apy1qxXH90K6HT09GwsFrAAAACY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 00:18:32
(20 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.39.247.99 (99.247.39.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.39.247.99 (99.247.39.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 20:18:26.773803 2026] [security2:error] [pid 5754:tid 5754] [client 34.39.247.99:34022] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "alphazeta.net"] [uri "/wp-config.php.swp"] [unique_id "apyxUnbHNx5PkFF1ciM4_QAAADI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
[email protected]
2026-09-06 00:16:45
(20 hours ago)
34.39.247.99 - - [06/Sep/2026:00:16:44 +0000] "GET /.env HTTP/1.1" 404 328 "-" "crusader-worker/1.0" ...
show more
34.39.247.99 - - [06/Sep/2026:00:16:44 +0000] "GET /.env HTTP/1.1" 404 328 "-" "crusader-worker/1.0"
34.39.247.99 - - [06/Sep/2026:00:16:44 +0000] "GET /.env.local HTTP/1.1" 404 328 "-" "crusader-worker/1.0"
34.39.247.99 - - [06/Sep/2026:00:16:44 +0000] "GET /.env.production HTTP/1.1" 404 328 "-" "crusader-worker/1.0"
...
show less
Web App Attack
🇫🇷
COMAITE
2026-09-05 23:56:23
(20 hours ago)
Suspicious URL access.
Web App Attack
Anonymous
2026-09-05 23:38:27
(21 hours ago)
Scan for .env Files at 2026-09-05T23:38:27+00:00
Web App Attack