๐ฌ๐ง
consul.to
2026-08-28 13:27:45
(6 hours ago)
Web attack/malicious scanning detected
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-08-28 13:08:19
(6 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐ฉ๐ช
big-cloud.nl
2026-08-28 12:51:04
(6 hours ago)
Try to access /.env
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 11:39:48
(7 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.42.113.125 (125.113.42.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.42.113.125 (125.113.42.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 07:39:40.734016 2026] [security2:error] [pid 1697:tid 1697] [client 34.42.113.125:55604] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.greentirerecycling.mapleleaf-marketing.com|F|2"] [data ".log"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.greentirerecycling.mapleleaf-marketing.com"] [uri "/storage/logs/laravel.log"] [unique_id "apFzfAIaJ0mTzpWGocAxEwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 11:23:40
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.42.113.125 (125.113.42.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.42.113.125 (125.113.42.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 07:23:32.920429 2026] [security2:error] [pid 743676:tid 744287] [client 34.42.113.125:54584] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.saskiarose.m3sxa.com"] [uri "/.env"] [unique_id "apFvtOFKZIXkdblDzY37_QAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-08-28 11:07:52
(8 hours ago)
[28/Aug/2026:14:07:51 +0300] -- 34.42.113.125 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET / ...
show more
[28/Aug/2026:14:07:51 +0300] -- 34.42.113.125 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET /.env.bak HTTP/1.1
show less
Bad Web Bot
Web App Attack
Anonymous
2026-08-28 11:00:04
(8 hours ago)
Bot / scanning and/or hacking attempts: GET /.env.save HTTP/1.1, GET /.env.prod HTTP/1.1, GET /.env. ...
show more
Bot / scanning and/or hacking attempts: GET /.env.save HTTP/1.1, GET /.env.prod HTTP/1.1, GET /.env.bak HTTP/1.1, GET /env HTTP/1.1, GET /.env.local HTTP/1.1, GET /storage/logs/laravel.log HTTP/1.1, GET /_ignition/health-check HTTP/1.1, GET /.env.example HTTP/1.1, GET /.env HTTP/1.1, GET /.env.old HTTP/1.1, GET /crusader-404-probe HTTP/1.1, GET /.env.dev HTTP/1.1, GET /.env.production HTTP/1.1, GET /wp-config.php~ HTTP/1.1, GET /actuator/configprops HTTP/1.1, GET /.env.backup HTTP/1.1, GET /wp-config.php.bak HTTP/1.1, GET /actuator/env HTTP/1.1, GET /wp-config.php.swp HTTP/1.1
show less
Hacking
Web App Attack
๐ท๐บ
DZBOT
2026-08-28 10:27:01
(9 hours ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
Anonymous
2026-08-28 10:22:03
(9 hours ago)
[da.kdns.gr] httpd-config-scan: sites=www.panetsos.gr; logs=/var/log/httpd/domains/panetsos.gr.log; ...
show more
[da.kdns.gr] httpd-config-scan: sites=www.panetsos.gr; logs=/var/log/httpd/domains/panetsos.gr.log; samples=/.env.local | /.env.prod | /.env
show less
Hacking
Web App Attack
๐ซ๐ท
service Informatique
2026-08-28 04:00:37
(15 hours ago)
GET /wp-config
Web App Attack
๐ฎ๐น
mediarama.com
2026-08-27 22:02:20
(21 hours ago)
Banned by Fail2Ban
Web App Attack
๐บ๐ธ
cwytech
2026-08-27 21:43:59
(21 hours ago)
Fleet-wide ban from the Ghostfleet ๐ป. Triggered by scenario: crowdsecurity/http-sensitive-files.
Bad Web Bot
Web App Attack
๐ง๐พ
lns.bz
2026-08-27 21:39:45
(21 hours ago)
.env scanning [BY]
Web App Attack
๐บ๐ธ
lnklnx
2026-08-27 19:18:34
(1 day ago)
www.lincolnclan.com:443 34.42.113.125 - - [27/Aug/2026:14:18:32 -0500] "GET /wp-config.php.bak HTTP/ ...
show more
www.lincolnclan.com:443 34.42.113.125 - - [27/Aug/2026:14:18:32 -0500] "GET /wp-config.php.bak HTTP/1.1" 401 5576 "-" "crusader-worker/1.0"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 19:12:06
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.42.113.125 (125.113.42.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.42.113.125 (125.113.42.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 15:12:00.854201 2026] [security2:error] [pid 19393:tid 19393] [client 34.42.113.125:34778] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "businessvaluationapp.com"] [uri "/.env"] [unique_id "apCMABqVxt86mzMe8NIM0AAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack