๐ณ๐ฑ
homeshowdomain.nl
2026-09-02 21:59:17
(5 hours ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-09-01.
show less
Web App Attack
SSH
Hacking
๐ฌ๐ง
openstrike.co.uk
2026-09-02 05:13:30
(21 hours ago)
13 attacks on PHP URLs, env grabbing URLs:
GET /wp-config.php~ HTTP/1.1
GET /.env.old HTTP/1.1
Web App Attack
Hacking
Anonymous
2026-09-01 13:40:08
(1 day ago)
"GET /.env HTTP/1.1"
Hacking
Web App Attack
Anonymous
2026-09-01 09:36:40
(1 day ago)
Web App Attack
Brute-Force
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 09:26:01
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.47.14.26 (26.14.47.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.47.14.26 (26.14.47.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 05:25:54.678887 2026] [security2:error] [pid 2159:tid 2159] [client 34.47.14.26:35554] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "clip24.net"] [uri "/.env.dev"] [unique_id "apaaIgjzw2qC4v_RtVTE3gAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 07:45:33
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.47.14.26 (26.14.47.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.47.14.26 (26.14.47.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 03:45:28.151114 2026] [security2:error] [pid 2527:tid 2527] [client 34.47.14.26:52122] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "gestiofiscal.com"] [uri "/.env.prod"] [unique_id "apaCmFGqL2iMjjL2BvvS6QAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
edena
2026-09-01 06:14:39
(1 day ago)
34.47.14.26 - - [01/Sep/2026:08:14:38 +0200] "GET /.env.example HTTP/1.1" 403 1842 "-" "crusader-wor ...
show more
34.47.14.26 - - [01/Sep/2026:08:14:38 +0200] "GET /.env.example HTTP/1.1" 403 1842 "-" "crusader-worker/1.0"
34.47.14.26 - - [01/Sep/2026:08:14:38 +0200] "GET /wp-config.php~ HTTP/1.1" 403 1842 "-" "crusader-worker/1.0"
34.47.14.26 - - [01/Sep/2026:08:14:38 +0200] "GET /wp-config.php.swp HTTP/1.1" 403 1842 "-" "crusader-worker/1.0"
...
show less
Web App Attack
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-01 06:06:31
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.47.14.26 (26.14.47.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.47.14.26 (26.14.47.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 02:06:22.940459 2026] [security2:error] [pid 21732:tid 21732] [client 34.47.14.26:51418] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.fortwaynepartybuses.com"] [uri "/wp-config.php.swp"] [unique_id "apZrXt1EiHvz4qAyfBNFuQAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-01 05:20:29
(1 day ago)
34.47.14.26 - - [01/Sep/2026:05:20:28 +0000] "GET /.env.bak HTTP/1.1" 302 443 "-" "crusader-worker/1 ...
show more
34.47.14.26 - - [01/Sep/2026:05:20:28 +0000] "GET /.env.bak HTTP/1.1" 302 443 "-" "crusader-worker/1.0"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 05:04:24
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.47.14.26 (26.14.47.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.47.14.26 (26.14.47.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 01:04:17.036703 2026] [security2:error] [pid 25838:tid 25854] [client 34.47.14.26:51690] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "abney.info"] [uri "/.env.dev"] [unique_id "apZc0TiAK0m6ICQJU9O4CgAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
4server
2026-09-01 04:47:28
(1 day ago)
[TueSep0106:47:23.7075512026][security2:error][pid1796811:tid1796849][client34.47.14.26:0]ModSecurit ...
show more
[TueSep0106:47:23.7075512026][security2:error][pid1796811:tid1796849][client34.47.14.26:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\".env\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"610\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"hostingedominio.net\"][uri\"/.env.production\"][unique_id\"apZY28o2XC-wo6QnmY5uWAAAAEw\"]
show less
Hacking
Web App Attack
Anonymous
2026-09-01 04:38:30
(1 day ago)
Web scanner: GET /.env.local
Web App Attack
Hacking
๐บ๐ธ
antlac1
2026-09-01 04:28:51
(1 day ago)
crowdsecurity/http-probing
Brute-Force
Web App Attack
๐ฉ๐ช
raph
2026-09-01 04:13:58
(1 day ago)
[DOT FILES] crawler *.env*, .git*, .config*, etc.
Bad Web Bot
Web App Attack
Anonymous
2026-09-01 04:13:38
(1 day ago)
Detected by CrowdSec: crowdsecurity/http-sensitive-files
Web App Attack