๐ฉ๐ช
raph
2026-09-01 05:15:15
(10 hours ago)
[Wordpress] crawler /wp-admin/*, /wp-content/*, etc.
Bad Web Bot
Web App Attack
Anonymous
2026-09-01 04:31:05
(10 hours ago)
Bot / scanning and/or hacking attempts: GET /.env.save HTTP/1.1, GET /.env.production HTTP/1.1, GET ...
show more
Bot / scanning and/or hacking attempts: GET /.env.save HTTP/1.1, GET /.env.production HTTP/1.1, GET /wp-config.php.swp HTTP/1.1, GET /crusader-404-probe HTTP/1.1, GET /_ignition/health-check HTTP/1.1, GET /actuator/env HTTP/1.1, GET /wp-config.php~ HTTP/1.1, GET /actuator/configprops HTTP/1.1, GET /wp-config.php.bak HTTP/1.1, GET /.env.local HTTP/1.1, GET /.env.old HTTP/1.1, GET /env HTTP/1.1, GET /.env.bak HTTP/1.1, GET /.env.prod HTTP/1.1, GET /.env.dev HTTP/1.1, GET /storage/logs/laravel.log HTTP/1.1, GET /.env HTTP/1.1, GET /.env.example HTTP/1.1, GET /.env.backup HTTP/1.1
show less
Hacking
Web App Attack
Anonymous
2026-09-01 03:48:38
(11 hours ago)
[ns31.kdns.gr] httpd-config-scan: sites=www.anart.dimitrisanousis.com; logs=/var/log/httpd/domains/d ...
show more
[ns31.kdns.gr] httpd-config-scan: sites=www.anart.dimitrisanousis.com; logs=/var/log/httpd/domains/dimitrisanousis.com.anart.log; samples=/.env | /.env.production | /.env.local
show less
Hacking
Web App Attack
๐ฌ๐ง
thetomtaylor.co.uk
2026-09-01 03:08:00
(12 hours ago)
Fail2Ban - [WEB]Custom exploit pattern detected on customexploits ... [ice01,ice02,wa01,wa02]
Hacking
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 02:44:28
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.85.56.243 (243.56.85.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.85.56.243 (243.56.85.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 22:44:20.371265 2026] [security2:error] [pid 14953:tid 14953] [client 34.85.56.243:43426] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.bestcountryclubs.com"] [uri "/.env"] [unique_id "apY8BFA66sTzKRgBR8_NgQAAAFo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-09-01 02:04:15
(13 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-09-01 01:13:55
(14 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 00:59:05
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.85.56.243 (243.56.85.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.85.56.243 (243.56.85.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 20:59:02.083834 2026] [security2:error] [pid 24905:tid 24905] [client 34.85.56.243:48598] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "dental.veneerdent.com"] [uri "/.env.production"] [unique_id "apYjVmnRgcE7baOPCSkfbwAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 00:16:15
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.85.56.243 (243.56.85.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.85.56.243 (243.56.85.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 20:16:12.541406 2026] [security2:error] [pid 3731785:tid 3731835] [client 34.85.56.243:45808] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.kwainet.com"] [uri "/wp-config.php.swp"] [unique_id "apYZTPczV_gUsgfH80PG6AAAAVQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
Charlesiv
2026-09-01 00:08:45
(15 hours ago)
Triggered Cloudflare WAF (firewallCustom) from JP.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Prot ...
show more
Triggered Cloudflare WAF (firewallCustom) from JP.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Protocol: HTTP/1.1 (GET method)
Endpoint: /.env/
Timestamp: 2026-08-31T23:46:46Z
Ray ID: a33feaa0a804c5bf
UA: crusader-worker/1.0
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-08-31 23:51:31
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.85.56.243 (243.56.85.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.85.56.243 (243.56.85.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 19:51:27.669959 2026] [security2:error] [pid 22601:tid 22601] [client 34.85.56.243:55006] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "colvani.com"] [uri "/.env.save"] [unique_id "apYTf9BkgImOMz_-Ns-vbgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-31 23:28:21
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.85.56.243 (243.56.85.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.85.56.243 (243.56.85.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 19:28:11.371532 2026] [security2:error] [pid 2173:tid 2173] [client 34.85.56.243:38692] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "casaluzislamujeres.com"] [uri "/.env.local"] [unique_id "apYOC0opYm30RCMzCGbSMQAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐ฉ
rvsdi
2026-08-31 22:57:17
(16 hours ago)
[OGWAF] path_traversal attack blocked | severity: high | GET /.env.example | UA: crusader-worker/1.0
Hacking
Web App Attack
๐ฎ๐ฉ
rvsdi
2026-08-31 22:57:17
(16 hours ago)
[OGWAF] bad_reputation attack blocked | severity: high | GET /storage/logs/laravel.log | UA: crusade ...
show more
[OGWAF] bad_reputation attack blocked | severity: high | GET /storage/logs/laravel.log | UA: crusader-worker/1.0
show less
Web App Attack
๐ฎ๐น
VHosting
2026-08-31 22:20:05
(17 hours ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack