๐ฉ๐ช
BlueWire Hosting
2026-09-02 07:33:01
(18 hours ago)
Aggressive scanning resulting into 404
Bad Web Bot
๐ณ๐ฑ
middelkoopcc
2026-09-02 06:05:01
(20 hours ago)
2026-09-02 08:03:27 GET /app/config/database.php [301] && 2026-09-02 08:03:27 GET /api/phpinfo.php [ ...
show more
2026-09-02 08:03:27 GET /app/config/database.php [301] && 2026-09-02 08:03:27 GET /api/phpinfo.php [301] && 2026-09-02 08:03:27 GET /application/config/database.php [301] && 633 more within 20 minutes
show less
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-09-01 22:00:11
(1 day ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-08-31.
show less
Web App Attack
SSH
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-01 14:01:37
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.47.143.56 (56.143.47.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.47.143.56 (56.143.47.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 10:01:31.322763 2026] [security2:error] [pid 20099:tid 20099] [client 34.47.143.56:57782] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.montgomeryhistoricalsociety.org"] [uri "/.env.backup"] [unique_id "apbau9hwTwMneCjy1fbsgAAAACE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
4server
2026-09-01 13:58:28
(1 day ago)
[TueSep0115:58:24.1376722026][security2:error][pid3541454:tid3541683][client34.47.143.56:0]ModSecuri ...
show more
[TueSep0115:58:24.1376722026][security2:error][pid3541454:tid3541683][client34.47.143.56:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\".env\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"610\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"cpcontacts.verticalti.ch\"][uri\"/.env.prod\"][unique_id\"apbaAMs9wbYeR1DMzZyAuQAAAQ4\"]
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 13:46:21
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.47.143.56 (56.143.47.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.47.143.56 (56.143.47.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 09:46:17.340921 2026] [security2:error] [pid 16351:tid 16351] [client 34.47.143.56:40092] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.jacobunderwoodmusic.com"] [uri "/.env"] [unique_id "apbXKUFCOyUMpC9TmWrxxgAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FD-IX
2026-09-01 13:03:29
(1 day ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-09-01 12:40:50
(1 day ago)
Attempt to access a backup or working file. Pattern match "\\\\. (920500-193)
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-01 12:32:10
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.47.143.56 (56.143.47.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.47.143.56 (56.143.47.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 08:32:03.333064 2026] [security2:error] [pid 28778:tid 28778] [client 34.47.143.56:42980] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "chitsey.com"] [uri "/.env.local"] [unique_id "apbFw23zEXTBfaWnxJJwbgAAADY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 12:03:27
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.47.143.56 (56.143.47.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.47.143.56 (56.143.47.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 08:03:19.137549 2026] [security2:error] [pid 16241:tid 16248] [client 34.47.143.56:53988] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "deathconfusion.mylordsday.com"] [uri "/.env.backup"] [unique_id "apa_BwPfUQIhse-a9urE1AAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 11:19:49
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.47.143.56 (56.143.47.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.47.143.56 (56.143.47.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 07:19:45.893222 2026] [security2:error] [pid 20374:tid 20374] [client 34.47.143.56:52860] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "westernweddingnapkins.com"] [uri "/.env.bak"] [unique_id "apa00bth5wDLYrhcNUj4bQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
consul.to
2026-09-01 11:13:07
(1 day ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 10:58:04
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.47.143.56 (56.143.47.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.47.143.56 (56.143.47.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 06:57:59.421165 2026] [security2:error] [pid 24096:tid 24096] [client 34.47.143.56:41966] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.guavaroad.com"] [uri "/wp-config.php.bak"] [unique_id "apavtxqZ6Gh3NLQWa611vQAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-01 09:48:39
(1 day ago)
[ssd5.kdns.gr] httpd-config-scan: logs=/var/log/httpd/access_log; samples=/.env.production | /.env.o ...
show more
[ssd5.kdns.gr] httpd-config-scan: logs=/var/log/httpd/access_log; samples=/.env.production | /.env.old | /.env.example
show less
Hacking
Web App Attack
๐ฉ๐ช
Stefan Dreher
2026-09-01 09:39:48
(1 day ago)
34.47.143.56 - - [01/Sep/2026:11:39:47 +0200] "GET /.env.old HTTP/1.1" 404 153 "-" "crusader-worker/ ...
show more
34.47.143.56 - - [01/Sep/2026:11:39:47 +0200] "GET /.env.old HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
34.47.143.56 - - [01/Sep/2026:11:39:47 +0200] "GET /.env.backup HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
34.47.143.56 - - [01/Sep/2026:11:39:47 +0200] "GET /storage/logs/laravel.log HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
34.47.143.56 - - [01/Sep/2026:11:39:47 +0200] "GET /crusader-404-probe HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
34.47.143.56 - - [01/Sep/2026:11:39:47 +0200] "GET /.env.bak HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
...
show less
Hacking
Brute-Force