๐ง๐พ
lns.bz
2026-08-27 20:56:58
(2 hours ago)
.env scanning [BY]
Web App Attack
๐ฉ๐ช
sdos.es
2026-08-27 20:12:56
(3 hours ago)
"URL file extension is restricted by policy - .backup"
Web App Attack
๐ฉ๐ช
LRob
2026-08-27 19:12:52
(4 hours ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /wp-config.php~ (+12 more) | 2026-08-27 19:12 UTC
show less
Hacking
Web App Attack
๐ธ๐ช
vaia.cloud
2026-08-27 18:50:03
(4 hours ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
Anonymous
2026-08-27 18:41:41
(4 hours ago)
Auto-reported by Fail2Ban (NPM-Auth)
Web App Attack
๐จ๐ญ
zynex
2026-08-27 18:35:46
(4 hours ago)
URL Probing: /wp-config.php.bak
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 18:07:59
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.63.154.64 (64.154.63.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.63.154.64 (64.154.63.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 14:07:54.579828 2026] [security2:error] [pid 30863:tid 30863] [client 34.63.154.64:46724] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "davisound.com"] [uri "/.env.save"] [unique_id "apB8-pHIePCM4L4wYh-bogAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-08-27 18:05:19
(5 hours ago)
Abuse Detected (9)
Brute-Force
Web App Attack
๐ฉ๐ช
seal
2026-08-27 17:25:43
(5 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
SSH
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-08-27 17:18:56
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.63.154.64 (64.154.63.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.63.154.64 (64.154.63.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 13:18:48.781626 2026] [security2:error] [pid 26208:tid 26208] [client 34.63.154.64:44240] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "leositalianice.royal-barbershop.com"] [uri "/.env.save"] [unique_id "apBxeGVLP0C4G2ZJGW6WYAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-27 16:47:10
(6 hours ago)
CrowdSec ban: crowdsecurity/http-sensitive-files
Port Scan
๐ณ๐ฑ
e.fierstra
2026-08-27 16:03:36
(7 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐ซ๐ท
GoodOldTOS
2026-08-27 15:52:25
(7 hours ago)
Bad keywords detected in request: /.env
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 15:35:30
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.63.154.64 (64.154.63.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.63.154.64 (64.154.63.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 11:35:14.783600 2026] [security2:error] [pid 10593:tid 10593] [client 34.63.154.64:54580] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "instituteofscience.com"] [uri "/.env.bak"] [unique_id "apBZMrHOvDn_zQHEewFw0wAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
maxpower
2026-08-27 15:25:50
(7 hours ago)
(nginx_hardened) REGOLA 3 - Nginx Hardening Triggered 34.63.154.64 (US/United States/64.154.63.34.bc ...
show more
(nginx_hardened) REGOLA 3 - Nginx Hardening Triggered 34.63.154.64 (US/United States/64.154.63.34.bc.googleusercontent.com): 3 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 2026/08/27 17:25:44 [error] 3986384#3986384: *492870 access forbidden by rule, client: 34.63.154.64, server: albavisual.mlocale.com, request: "GET /wp-config.php.bak HTTP/1.1", host: "www.albavisual.mlocale.com"
2026/08/27 17:25:44 [error] 3986382#3986382: *492871 access forbidden by rule, client: 34.63.154.64, server: albavisual.mlocale.com, request: "GET /wp-config.php~ HTTP/1.1", host: "www.albavisual.mlocale.com"
2026/08/27 17:25:44 [error] 3986380#3986380: *492869 access forbidden by rule, client: 34.63.154.64, server: albavisual.mlocale.com, request: "GET /wp-config.php.swp HTTP/1.1", host: "www.albavisual.mlocale.com"
show less
Port Scan