🇺🇸
mnsf
2026-09-04 07:06:11
(16 minutes ago)
Scanning/Probing (20)
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 06:35:22
(47 minutes ago)
(mod_security) mod_security (id:210492) triggered by 34.74.58.72 (72.58.74.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.74.58.72 (72.58.74.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 02:35:16.643623 2026] [security2:error] [pid 6779:tid 6779] [client 34.74.58.72:38686] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "xalais.com"] [uri "/.env.dev"] [unique_id "appmpEtn-ZrGl_pBE8993wAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇸🇪
vaia.cloud
2026-09-04 06:35:01
(47 minutes ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
🇺🇦
URAN Publishing Service
2026-09-04 06:31:20
(51 minutes ago)
[04/Sep/2026:09:31:20 +0300] -- 34.74.58.72 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.env.s ...
show more
[04/Sep/2026:09:31:20 +0300] -- 34.74.58.72 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.env.save HTTP/1.1
show less
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 06:17:47
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.74.58.72 (72.58.74.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.74.58.72 (72.58.74.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 02:17:39.194991 2026] [security2:error] [pid 97316:tid 97316] [client 34.74.58.72:41898] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "hotelausland.com"] [uri "/.env.backup"] [unique_id "appig_zZFBlnpoebzh5a5gAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
IndigoRidge
2026-09-04 05:54:54
(1 hour ago)
[04/Sep/2026:01:54:54.150455 --0400] appdLo6vNRRsFbjg@6UtnwAAAhg 34.74.58.72 43908 205.233.18.17 708 ...
show more
[04/Sep/2026:01:54:54.150455 --0400] appdLo6vNRRsFbjg@6UtnwAAAhg 34.74.58.72 43908 205.233.18.17 7081
[04/Sep/2026:01:54:54.182086 --0400] appdLv@UcscHgrgVvMqHiQAAAAs 34.74.58.72 43918 205.233.18.17 7081
[04/Sep/2026:01:54:54.213042 --0400] appdLsD47DFdQnnNY1CwKgAAAVU 34.74.58.72 43930 205.233.18.17 7081
[04/Sep/2026:01:54:54.245019 --0400] appdLu2LUNsX7oZ@-ms61gAAAZY 34.74.58.72 43934 205.233.18.17 7081
[04/Sep/2026:01:54:54.276520 --0400] appdLnPdRWsohBr@J2-N0gAAAcM 34.74.58.72 43940 205.233.18.17 7081
...
show less
Hacking
🇫🇷
masterguru
2026-09-04 04:48:08
(2 hours ago)
Attempt to access a backup or working file. Pattern match "\\\\. (920500-193)
Hacking
🇵🇱
Budyn
2026-09-04 04:04:53
(3 hours ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scan ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scanner. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: p.budyn.wtf | URI: /.env.dev | UA: crusader-worker/1.0 | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 03:59:40
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.74.58.72 (72.58.74.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.74.58.72 (72.58.74.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 23:59:35.255699 2026] [security2:error] [pid 17113:tid 17151] [client 34.74.58.72:59954] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.illianapartyrentals.com"] [uri "/.env.example"] [unique_id "appCJzdYFeaht6mQMIkYxwAAAVg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇮🇹
VHosting
2026-09-04 03:50:05
(3 hours ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
Anonymous
2026-09-04 03:43:14
(3 hours ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack
🇩🇪
Fusl
2023-08-03 06:43:19
(3 years ago)
received unsolicited smtp data stream:
Message-ID: <[email protected] >
Date: Wed, 2 Aug 20 ...
show more
received unsolicited smtp data stream:
Message-ID: <[email protected] >
Date: Wed, 2 Aug 2023 23:43:04 -0700
From: "noreply" <[email protected] >
Subject: ===smtp444xubbcaj nqfae vjw MID:c0108f4d46d0c1a25966ef0735d2dce5
To: [email protected]
Content-Transfer-Encoding: 7bit
Content-Type: text/html; charset=UTF-8
===185.242.215.186:587:::"noreply"<#RANDOM(10)#@{gmail.com|yahoo.com|hotmail.com}>:nossl::::0 ===
show less
Email Spam