๐ณ๐ฑ
homeshowdomain.nl
2026-08-02 22:00:22
(4 weeks ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-08-01.
show less
Web App Attack
SSH
Hacking
๐จ๐ญ
zynex
2026-08-01 17:23:11
(1 month ago)
URL Probing: /.env
Web App Attack
๐ซ๐ท
COMAITE
2026-08-01 17:12:40
(1 month ago)
Suspicious URL access.
Web App Attack
๐ง๐ช
boxed-it
2026-08-01 17:03:42
(1 month ago)
GET /.env (Tarpitted for 2m10s, wasted 7.73kB)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-01 16:53:54
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 34.64.46.30 (30.46.64.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.64.46.30 (30.46.64.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 12:53:47.584323 2026] [security2:error] [pid 2118158:tid 2118158] [client 34.64.46.30:40722] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.emailaegis.axiomemail.net"] [uri "/.env.dev"] [unique_id "am4km2EJ70xzchh4fsGrBwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-08-01 15:41:30
(1 month ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-01 15:35:47
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 34.64.46.30 (30.46.64.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.64.46.30 (30.46.64.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 11:35:41.729228 2026] [security2:error] [pid 94526:tid 94526] [client 34.64.46.30:60476] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.juca.imerka.com.mx"] [uri "/.env.prod"] [unique_id "am4STd7YdaIG9QsvD81ZaAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-01 14:52:16
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 34.64.46.30 (30.46.64.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.64.46.30 (30.46.64.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 10:52:08.053293 2026] [security2:error] [pid 2833349:tid 2833349] [client 34.64.46.30:54646] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.srtgloballogistics.srtmanagementservices.com"] [uri "/.env.backup"] [unique_id "am4IGNMu4YSnszWP0RoiTQAAACM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-01 14:24:54
(1 month ago)
[ssd5.kdns.gr] httpd-config-scan: sites=www.electromecanica.gr; logs=/var/log/httpd/domains/electrom ...
show more
[ssd5.kdns.gr] httpd-config-scan: sites=www.electromecanica.gr; logs=/var/log/httpd/domains/electromecanica.gr.log; samples=/.env.save | /.env.example | /.env
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-01 13:43:07
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 34.64.46.30 (30.46.64.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.64.46.30 (30.46.64.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 09:43:03.343382 2026] [security2:error] [pid 1157360:tid 1157360] [client 34.64.46.30:35132] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sympalais.com"] [uri "/.env.dev"] [unique_id "am335_VQHRAyMW80RmDJSAAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
enchiriadis
2026-08-01 13:33:47
(1 month ago)
Fail2Ban caddy-wp-404scan on Tuxi
Port Scan
๐ฌ๐ง
consul.to
2026-08-01 13:28:15
(1 month ago)
Web attack/malicious scanning detected
Web App Attack
๐ซ๐ท
masterguru
2026-08-01 13:03:45
(1 month ago)
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 34.64.46.30 (KR/South Korea/30.46.64. ...
show more
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 34.64.46.30 (KR/South Korea/30.46.64.34.bc.googleusercontent.com): 2 in the last 3600 secs (0-196)
show less
Hacking
๐บ๐ธ
TPI-Abuse
2026-08-01 12:56:55
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 34.64.46.30 (30.46.64.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.64.46.30 (30.46.64.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 08:56:51.453824 2026] [security2:error] [pid 2767760:tid 2767776] [client 34.64.46.30:58088] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.danbressler.pwrcoupling.com"] [uri "/.env.old"] [unique_id "am3tE7xOVQn5Dm_6iuWueAAAAMw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-08-01 12:55:25
(1 month ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking