🇩🇪
FeG Deutschland
2026-09-06 04:38:14
(2 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 03:54:21
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.65.210.105 (105.210.65.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.65.210.105 (105.210.65.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 23:54:16.761349 2026] [security2:error] [pid 4807:tid 4807] [client 34.65.210.105:47326] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.ictsl.net"] [uri "/.env.local"] [unique_id "apzj6O0G0gDmBijD2ddlCAAAAD8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
TheDjRider
2026-09-06 03:36:28
(3 hours ago)
CrowdSec detected Web application reconnaissance. Scenario: local/framework-recon. Automatic ban tri ...
show more
CrowdSec detected Web application reconnaissance. Scenario: local/framework-recon. Automatic ban triggered. Detection time (UTC): 2026-09-06T03:36:24.446824718Z. Context: http_status=200
show less
Web App Attack
🇳🇱
e.fierstra
2026-09-06 03:32:47
(3 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 02:58:18
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.65.210.105 (105.210.65.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.65.210.105 (105.210.65.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 22:58:14.949650 2026] [security2:error] [pid 11934:tid 11960] [client 34.65.210.105:52018] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.whitecrosslibrary.com"] [uri "/.env.example"] [unique_id "apzWxikz-efFYVN710PfiQAAAJg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
LRob
2026-09-06 02:54:14
(4 hours ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /.env.local (+12 more) | 2026-09-06 02:54 UTC
show less
Hacking
Web App Attack
Anonymous
2026-09-06 01:59:48
(5 hours ago)
Web scanner: GET /actuator/env
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-06 01:48:54
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.65.210.105 (105.210.65.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.65.210.105 (105.210.65.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 21:48:48.855271 2026] [security2:error] [pid 3505780:tid 3505914] [client 34.65.210.105:34060] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sailcleaner.com"] [uri "/.env.dev"] [unique_id "apzGgKeVUu6W99IeSwEbXAAAAg4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇷🇺
DZBOT
2026-09-06 01:47:49
(5 hours ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
Anonymous
2026-09-06 01:36:03
(5 hours ago)
Unauthorized SSH login attempts
Brute-Force
SSH
🇨🇭
zynex
2026-09-06 00:57:33
(6 hours ago)
URL Probing: /.env
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 00:47:31
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.65.210.105 (105.210.65.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.65.210.105 (105.210.65.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 20:47:24.093790 2026] [security2:error] [pid 12378:tid 12378] [client 34.65.210.105:41018] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.kathleenhazlett.com"] [uri "/wp-config.php.bak"] [unique_id "apy4HG4SM5RfiZTLhWF_2gAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇪🇸
alferez
2026-09-05 23:33:19
(7 hours ago)
Searching .(env|sql|zip|tar|rar) files
Hacking
Exploited Host
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 23:26:12
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.65.210.105 (105.210.65.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.65.210.105 (105.210.65.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 19:26:04.872748 2026] [security2:error] [pid 20033:tid 20033] [client 34.65.210.105:51346] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "keeftone.tech-servusa.com"] [uri "/.env.backup"] [unique_id "apylDKkDipr8aPxzR5ZB9wAAAF8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 22:56:15
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.65.210.105 (105.210.65.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.65.210.105 (105.210.65.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 18:56:12.252197 2026] [security2:error] [pid 25356:tid 25356] [client 34.65.210.105:51008] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.josephalosi.com"] [uri "/.env.backup"] [unique_id "apyeDBoJ4FNEkj_sikH6cgAAAIA"]
show less
Brute-Force
Bad Web Bot
Web App Attack