Anonymous
2026-09-06 06:35:57
(5 hours ago)
Suspicious URL access.
Hacking
🇩🇪
Vegascosmetics
2026-09-06 03:34:37
(8 hours ago)
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after sensitive config/credentials exposure ...
show more
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after sensitive config/credentials exposure probe. Evidence: AttackPattern: /\.env (Match: /.env)
show less
Hacking
Brute-Force
Web App Attack
🇮🇹
VHosting
2026-09-06 03:05:02
(9 hours ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
Anonymous
2026-09-06 03:01:15
(9 hours ago)
34.88.229.244 - - [05/Sep/2026:22:01:14 -0500] "GET /.env.bak HTTP/1.1" 403 199 "-" "crusader-worker ...
show more
34.88.229.244 - - [05/Sep/2026:22:01:14 -0500] "GET /.env.bak HTTP/1.1" 403 199 "-" "crusader-worker/1.0" 34.88.229.244
34.88.229.244 - - [05/Sep/2026:22:01:14 -0500] "GET /.env.save HTTP/1.1" 403 199 "-" "crusader-worker/1.0" 34.88.229.244
34.88.229.244 - - [05/Sep/2026:22:01:14 -0500] "GET /.env HTTP/1.1" 403 199 "-" "crusader-worker/1.0" 34.88.229.244
34.88.229.244 - - [05/Sep/2026:22:01:14 -0500] "GET /.env.prod HTTP/1.1" 403 199 "-" "crusader-worker/1.0" 34.88.229.244
34.88.229.244 - - [05/Sep/2026:22:01:14 -0500] "GET /.env.backup HTTP/1.1" 403 199 "-" "crusader-worker/1.0" 34.88.229.244
34.88.229.244 - - [05/Sep/2026:22:01:14 -0500] "GET /.env.local HTTP/1.1" 403 199 "-" "crusader-worker/1.0" 34.88.229.244
34.88.229.244 - - [05/Sep/2026:22:01:14 -0500] "GET /.env.example HTTP/1.1" 403 199 "-" "crusader-worker/1.0" 34.88.229.244
34.88.229.244 - - [05/Sep/2026:22:01:14 -0500] "GET /.env.production HTTP/1.1" 403 199 "-" "crusader-worker/1.0" 34.88.229.244
34.88.229.244 - - [05/Sep/
...
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 02:57:48
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.88.229.244 (244.229.88.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.88.229.244 (244.229.88.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 22:57:42.226286 2026] [security2:error] [pid 22627:tid 22627] [client 34.88.229.244:56116] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.outsourceitinc.com"] [uri "/.env.backup"] [unique_id "apzWpimZpBXg6TbtjlE5UQAAAHc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 02:30:42
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.88.229.244 (244.229.88.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.88.229.244 (244.229.88.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 22:30:39.041184 2026] [security2:error] [pid 28990:tid 28997] [client 34.88.229.244:37336] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "siraceservices.com"] [uri "/wp-config.php~"] [unique_id "apzQT4nbmbWWpEL5qYYTNQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
ger-stg-sifi1
2026-09-06 02:25:20
(9 hours ago)
(wordpress) Failed wordpress login using wp-login.php or xmlrpc.php
Web App Attack
🇵🇱
Budyn
2026-09-06 02:17:57
(9 hours ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scan ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scanner. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: teddypot.store | URI: /actuator/configprops | UA: crusader-worker/1.0 | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
🇩🇪
0x44
2026-09-06 01:37:00
(10 hours ago)
TCP SYN Discovery - Flooding
DDoS Attack
🇳🇱
e.fierstra
2026-09-06 01:36:03
(10 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
🇩🇪
FD-IX
2026-09-06 00:34:18
(11 hours ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
🇬🇧
Aetherweb Ark
2026-09-06 00:30:58
(11 hours ago)
(mod_security) mod_security (id:949110) triggered by 34.88.229.244 (FI/Finland/244.229.88.34.bc.goog ...
show more
(mod_security) mod_security (id:949110) triggered by 34.88.229.244 (FI/Finland/244.229.88.34.bc.googleusercontent.com): N in the last X secs
show less
Web App Attack
🇬🇧
consul.to
2026-09-06 00:05:38
(12 hours ago)
Web attack/malicious scanning detected
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 23:54:15
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.88.229.244 (244.229.88.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.88.229.244 (244.229.88.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 19:54:11.457218 2026] [security2:error] [pid 29839:tid 29839] [client 34.88.229.244:35862] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.kentsmithfamily.com"] [uri "/.env"] [unique_id "apyroxCfZjAR75ZLHp8aZwAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇧🇪
voormedia
2026-09-05 23:52:29
(12 hours ago)
Accessed trap at '/actuator/env'
Web App Attack