🇧🇪
cmbplf
2026-09-06 07:42:12
(6 hours ago)
168 requests with url.path */.git/config
Brute-Force
Bad Web Bot
Anonymous
2026-09-06 03:45:03
(10 hours ago)
Bot / scanning and/or hacking attempts: GET /html/.git/config HTTP/1.1, GET /.git/config HTTP/1.1
Hacking
Web App Attack
🇩🇪
raph
2026-09-06 02:45:23
(11 hours ago)
[DOT FILES] crawler *.env*, .git*, .config*, etc.
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 15:19:37
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.88.226.202 (202.226.88.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.88.226.202 (202.226.88.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 11:19:31.685078 2026] [security2:error] [pid 19801:tid 19801] [client 34.88.226.202:41046] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.holboxwhalesharktours.net"] [uri "/.env.local"] [unique_id "aprhg0b3E-PSbz0QkO8qsAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
pscriptos
2026-09-04 14:58:23
(1 day ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-04 14:05:33
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.88.226.202 (202.226.88.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.88.226.202 (202.226.88.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 10:05:26.619057 2026] [security2:error] [pid 27299:tid 27299] [client 34.88.226.202:45612] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.paintedoverwhite.com"] [uri "/.env.prod"] [unique_id "aprQJoaMj_z8TUVkoTCAlAAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
MatCat
2026-09-04 14:05:12
(2 days ago)
Banned by fail2ban: apache-webprobe
Port Scan
Bad Web Bot
🇺🇸
daveoctober
2026-09-04 13:44:30
(2 days ago)
October Sentinel: honeypot triggered
Bad Web Bot
Web App Attack
🇬🇧
Aetherweb Ark
2026-09-04 13:37:01
(2 days ago)
(mod_security) mod_security (id:949110) triggered by 34.88.226.202 (FI/Finland/202.226.88.34.bc.goog ...
show more
(mod_security) mod_security (id:949110) triggered by 34.88.226.202 (FI/Finland/202.226.88.34.bc.googleusercontent.com): N in the last X secs
show less
Web App Attack
🇳🇱
WeCloudit-Anti-Abuse
2026-09-04 13:25:10
(2 days ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
🇫🇷
COMAITE
2026-09-04 13:19:32
(2 days ago)
Suspicious URL access.
Web App Attack
🇩🇪
LRob
2026-09-04 13:17:58
(2 days ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /.env.production (+12 more) | 2026-09-04 13:17 UTC
show less
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 12:33:12
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.88.226.202 (202.226.88.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.88.226.202 (202.226.88.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 08:33:05.391348 2026] [security2:error] [pid 8638:tid 8638] [client 34.88.226.202:34670] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ftp.dunningtons.com"] [uri "/.env.prod"] [unique_id "apq6ge5KhX8Hs7BqeDxGngAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇨🇭
zynex
2026-09-04 12:20:01
(2 days ago)
URL Probing: /.env
Web App Attack
🇩🇪
Marc
2026-09-04 12:17:59
(2 days ago)
34.88.226.202 - - [04/Sep/2026:14:17:59 +0200] "GET /env HTTP/1.1" 404 4616 "-" "crusader-worker/1.0 ...
show more
34.88.226.202 - - [04/Sep/2026:14:17:59 +0200] "GET /env HTTP/1.1" 404 4616 "-" "crusader-worker/1.0" 34.88.226.202 - - [04/Sep/2026:14:17:59 +0200] "GET /.env.production HTTP/1.1" 404 4617 "-" "crusader-worker/1.0" 34.88.226.202 - - [04/Sep/2026:14:17:59 +0200] "GET /actuator/env HTTP/1.1" 404 4618 "-" "crusader-worker/1.0"
show less
Brute-Force