🇫🇮
JLKnoch Software GmbH
2026-09-04 10:58:53
(2 minutes ago)
CrowdSec crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
🇩🇪
FD-IX
2026-09-04 10:56:25
(4 minutes ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
🇩🇪
conseilgouz
2026-09-04 10:50:08
(11 minutes ago)
vee-17 : Block hidden directories=>/.env.production(/)
Hacking
🇺🇸
lavnet.net
2026-09-04 10:44:37
(16 minutes ago)
34.86.36.169 - - [04/Sep/2026:10:44:36 +0000] "GET /.env.save HTTP/1.1" 404 6087 "-" "crusader-worke ...
show more
34.86.36.169 - - [04/Sep/2026:10:44:36 +0000] "GET /.env.save HTTP/1.1" 404 6087 "-" "crusader-worker/1.0"
34.86.36.169 - - [04/Sep/2026:10:44:36 +0000] "GET /actuator/env HTTP/1.1" 404 6089 "-" "crusader-worker/1.0"
34.86.36.169 - - [04/Sep/2026:10:44:36 +0000] "GET /.env.local HTTP/1.1" 404 6088 "-" "crusader-worker/1.0"
34.86.36.169 - - [04/Sep/2026:10:44:36 +0000] "GET /.env.production HTTP/1.1" 404 6088 "-" "crusader-worker/1.0"
34.86.36.169 - - [04/Sep/2026:10:44:36 +0000] "GET /.env.bak HTTP/1.1" 404 6087 "-" "crusader-worker/1.0"
34.86.36.169 - - [04/Sep/2026:10:44:36 +0000] "GET /wp-config.php~ HTTP/1.1" 404 6088 "-" "crusader-worker/1.0"
...
show less
Brute-Force
Anonymous
2026-09-04 09:52:11
(1 hour ago)
Web scanner: GET /actuator/configprops
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-04 09:49:55
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.86.36.169 (169.36.86.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.86.36.169 (169.36.86.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 05:49:50.945687 2026] [security2:error] [pid 21724:tid 21724] [client 34.86.36.169:52514] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "h1920.suretrap.com"] [uri "/wp-config.php.swp"] [unique_id "apqUPgkSdrzplza8K1O5fwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
Aetherweb Ark
2026-09-04 08:30:15
(2 hours ago)
(mod_security) mod_security (id:949110) triggered by 34.86.36.169 (US/United States/169.36.86.34.bc. ...
show more
(mod_security) mod_security (id:949110) triggered by 34.86.36.169 (US/United States/169.36.86.34.bc.googleusercontent.com): N in the last X secs
show less
Web App Attack
🇫🇷
dynamix
2026-09-04 08:27:37
(2 hours ago)
Multiple WAF Violations
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 08:25:26
(2 hours ago)
(mod_security) mod_security (id:949110) triggered by 34.86.36.169 (169.36.86.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:949110) triggered by 34.86.36.169 (169.36.86.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 04:25:20.853418 2026] [security2:error] [pid 28970:tid 28970] [client 34.86.36.169:42774] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "mail.euro-theatre.com"] [uri "/.env.dev"] [unique_id "apqAcMB8hLqj_ptD0mYppgAAAFY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 07:42:52
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.86.36.169 (169.36.86.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.86.36.169 (169.36.86.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 03:42:48.022599 2026] [security2:error] [pid 24300:tid 24314] [client 34.86.36.169:41690] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "geegeefive.com"] [uri "/.env.old"] [unique_id "app2eFzCvmJmYnXvhhNAKAAAAIs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-04 07:40:04
(3 hours ago)
suspicious request in access.log
Web App Attack
🇩🇪
schuerholz
2026-09-04 06:30:10
(4 hours ago)
Confirmed intrusion/exploit attempt detected and blocked by IPS (automated detection).
Hacking
Web App Attack
🇳🇱
WeCloudit-Anti-Abuse
2026-09-04 06:27:22
(4 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
Anonymous
2026-09-04 06:06:05
(4 hours ago)
Trying to access config files
Web App Attack
🇬🇧
consul.to
2026-09-04 06:00:00
(5 hours ago)
Web attack/malicious scanning detected
Web App Attack