๐บ๐ธ
Gabriel Camargo
2026-08-01 17:24:04
(13 hours ago)
34.47.152.97 - - [01/Aug/2026:12:24:04 -0500] "GET /.env.old HTTP/1.1" 301 178 "-" "crusader-worker/ ...
show more
34.47.152.97 - - [01/Aug/2026:12:24:04 -0500] "GET /.env.old HTTP/1.1" 301 178 "-" "crusader-worker/1.0"
34.47.152.97 - - [01/Aug/2026:12:24:04 -0500] "GET /.env.dev HTTP/1.1" 301 178 "-" "crusader-worker/1.0"
34.47.152.97 - - [01/Aug/2026:12:24:04 -0500] "GET /.env.local HTTP/1.1" 301 178 "-" "crusader-worker/1.0"
...
show less
Brute-Force
SSH
๐จ๐ญ
4server
2026-08-01 17:18:52
(13 hours ago)
[SatAug0119:18:46.0202122026][security2:error][pid190964:tid191237][client34.47.152.97:0]ModSecurity ...
show more
[SatAug0119:18:46.0202122026][security2:error][pid190964:tid191237][client34.47.152.97:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\".env\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"365\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"executivekotech.com.81-17-25-250.cpanel.site\"][uri\"/.env.backup\"][unique_id\"am4qduhU5pgcqI9UHxHJ3wAAAQE\"]
show less
Hacking
Web App Attack
๐บ๐ธ
rdpguard.com
2026-08-01 16:51:12
(13 hours ago)
RdpGuard detected brute-force attempt on HTTP
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-08-01 16:25:54
(14 hours ago)
(mod_security) mod_security (id:949110) triggered by 34.47.152.97 (97.152.47.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:949110) triggered by 34.47.152.97 (97.152.47.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 12:25:50.965010 2026] [security2:error] [pid 2140386:tid 2140386] [client 34.47.152.97:54460] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "joycepelham.com"] [uri "/.env.old"] [unique_id "am4eDrxlQvfY020vzoeDkAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-01 16:14:34
(14 hours ago)
34.47.152.97 - - [01/Aug/2026:16:14:32 +0000] "GET /.env.example HTTP/1.1" 404 153 "-" "crusader-wor ...
show more
34.47.152.97 - - [01/Aug/2026:16:14:32 +0000] "GET /.env.example HTTP/1.1" 404 153 "-" "crusader-worker/1.0" "-" "opt-out.schmittel-it.de"
...
show less
Hacking
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-01 15:52:29
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.47.152.97 (97.152.47.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.47.152.97 (97.152.47.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 11:52:23.359029 2026] [security2:error] [pid 2298532:tid 2298550] [client 34.47.152.97:46006] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.ucamp.appraisalteam.net"] [uri "/.env.old"] [unique_id "am4WN0FRTfSvsx8WqZAsSAAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-08-01 15:50:06
(14 hours ago)
Restricted File Access Attempt. Matched phrase ".env" at REQUEST_FILENAME. (930130-196)
Hacking
Web App Attack
Anonymous
2026-08-01 15:44:57
(14 hours ago)
[ns31.kdns.gr] httpd-config-scan: sites=www.example.com; logs=/var/log/httpd/access_log; samples=/.e ...
show more
[ns31.kdns.gr] httpd-config-scan: sites=www.example.com; logs=/var/log/httpd/access_log; samples=/.env.backup | /.env.bak | /.env.old
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-01 15:15:17
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.47.152.97 (97.152.47.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.47.152.97 (97.152.47.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 11:15:08.848466 2026] [security2:error] [pid 904088:tid 904088] [client 34.47.152.97:55252] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.avaliantlife.com"] [uri "/.env.local"] [unique_id "am4NfAyzu2ekF3i3gi16VwAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-01 14:26:01
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.47.152.97 (97.152.47.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.47.152.97 (97.152.47.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 10:25:56.572443 2026] [security2:error] [pid 5756:tid 5756] [client 34.47.152.97:53262] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jimmyshakes.org"] [uri "/.env.save"] [unique_id "am4B9IFHMB2v_hIG9jmLQQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-08-01 14:18:31
(16 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
๐ฉ๐ช
23p02732
2026-08-01 14:12:26
(16 hours ago)
Automated web scanning and malicious probing
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-01 14:04:51
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.47.152.97 (97.152.47.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.47.152.97 (97.152.47.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 10:04:47.463986 2026] [security2:error] [pid 2584906:tid 2584906] [client 34.47.152.97:59336] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "alkymera.es"] [uri "/.env.save"] [unique_id "am38_0Nn73AFuVIijcqG3wAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐พ
lns.bz
2026-08-01 13:54:00
(16 hours ago)
Too many 404 requests [BY]
Web App Attack
๐ฉ๐ช
4server
2026-08-01 13:52:12
(16 hours ago)
[SatAug0115:52:08.8958522026][security2:error][pid1580537:tid1580571][client34.47.152.97:0]ModSecuri ...
show more
[SatAug0115:52:08.8958522026][security2:error][pid1580537:tid1580571][client34.47.152.97:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:5\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.10\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"glass-container.com.136-243-54-122.cpanel.site\"][uri\"/.env.example\"][unique_id\"am36CA44IrGxkBFJENt-hAAAAAw\"]
show less
Port Scan
Brute-Force
Web App Attack