๐ณ๐ฑ
oisecnet
2026-09-22 21:03:10
(9 hours ago)
Automated report: Unauthorized vulnerability scanning detected on 2026-09-22. 828 requests from this ...
show more
Automated report: Unauthorized vulnerability scanning detected on 2026-09-22. 828 requests from this IP.
show less
Port Scan
Hacking
Web App Attack
Anonymous
2026-09-22 16:35:02
(14 hours ago)
suspicious request in access.log
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 16:31:00
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.89.115.46 (46.115.89.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.89.115.46 (46.115.89.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 12:30:54.591105 2026] [security2:error] [pid 3550:tid 3550] [client 34.89.115.46:36344] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "quintechcorp.com"] [uri "/.env.dev"] [unique_id "arKtPrxLBijbSmQhxj5o_gAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
GoodOldTOS
2026-09-22 16:25:13
(14 hours ago)
Bad keywords detected in request: /.env
Web App Attack
๐ฆ๐บ
aranguren.org
2026-09-22 15:50:15
(14 hours ago)
34.89.115.46 - - [23/Sep/2026:01:50:14 +1000] "GET /wp-config.php.bak HTTP/1.1" 404 996 "-" "crusade ...
show more
34.89.115.46 - - [23/Sep/2026:01:50:14 +1000] "GET /wp-config.php.bak HTTP/1.1" 404 996 "-" "crusader-worker/1.0"
34.89.115.46 - - [23/Sep/2026:01:50:14 +1000] "GET /.env.save HTTP/1.1" 404 996 "-" "crusader-worker/1.0"
34.89.115.46 - - [23/Sep/2026:01:50:14 +1000] "GET /actuator/configprops HTTP/1.1" 404 996 "-" "crusader-worker/1.0"
34.89.115.46 - - [23/Sep/2026:01:50:14 +1000] "GET /.env.bak HTTP/1.1" 404 996 "-" "crusader-worker/1.0"
34.89.115.46 - - [23/Sep/2026:01:50:14 +1000] "GET /.env.prod HTTP/1.1" 404 996 "-" "crusader-worker/1.0"
34.89.115.46 - - [23/Sep/2026:01:50:14 +1000] "GET /.env.local HTTP/1.1" 404 996 "-" "crusader-worker/1.0"
...
show less
Bad Web Bot
๐ณ๐ฑ
Alt255
2026-09-22 15:29:36
(15 hours ago)
[ti-07al] Web exploit scanning: 2 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-07al] Web exploit scanning: 2 suspicious requests detected by fail2ban jail apache-scanner. Example: 34.89.115.46 - - [22/Sep/2026:17:29:30 +0200] "GET /.env HTTP/1.1" 302 5750 "-" "crusader-worker/1.0"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 15:29:26
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.89.115.46 (46.115.89.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.89.115.46 (46.115.89.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 11:29:23.498284 2026] [security2:error] [pid 888222:tid 888222] [client 34.89.115.46:60780] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "nancyscafeandcatering.com"] [uri "/.env.prod"] [unique_id "arKe02FuO_bXkqOLnoZBNAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Dominik Lysiak
2026-09-22 15:27:53
(15 hours ago)
34.89.115.46 - - [22/Sep/2026:17:27:52 +0200] "GET /wp-config.php.bak HTTP/1.1" 200 51849 "-" "crusa ...
show more
34.89.115.46 - - [22/Sep/2026:17:27:52 +0200] "GET /wp-config.php.bak HTTP/1.1" 200 51849 "-" "crusader-worker/1.0"
34.89.115.46 - - [22/Sep/2026:17:27:52 +0200] "GET /wp-config.php~ HTTP/1.1" 200 51849 "-" "crusader-worker/1.0"
34.89.115.46 - - [22/Sep/2026:17:27:52 +0200] "GET /.env.example HTTP/1.1" 200 51849 "-" "crusader-worker/1.0"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 15:13:30
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.89.115.46 (46.115.89.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.89.115.46 (46.115.89.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 11:13:24.701480 2026] [security2:error] [pid 15435:tid 15435] [client 34.89.115.46:60376] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "milajarecords.com"] [uri "/.env.backup"] [unique_id "arKbFMmXHdSJKwBhsuogGQAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
SysAdmin Dylan
2026-09-22 14:57:28
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.89.115.46 (46.115.89.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.89.115.46 (46.115.89.34.bc.googleusercontent.com): 10 in the last 3600 secs
show less
Brute-Force
๐ฒ๐พ
Rizzy
2026-09-22 14:52:50
(15 hours ago)
Multiple WAF Violations
Brute-Force
Web App Attack
๐ท๐ด
clauss
2026-09-22 14:47:52
(15 hours ago)
34.89.115.46 - - [22/Sep/2026:17:47:51 +0300] "GET /_ignition/health-check HTTP/1.1" 403 146 "-" "cr ...
show more
34.89.115.46 - - [22/Sep/2026:17:47:51 +0300] "GET /_ignition/health-check HTTP/1.1" 403 146 "-" "crusader-worker/1.0"
34.89.115.46 - - [22/Sep/2026:17:47:51 +0300] "GET /.env.prod HTTP/1.1" 403 146 "-" "crusader-worker/1.0"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 14:33:06
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.89.115.46 (46.115.89.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.89.115.46 (46.115.89.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 10:33:03.846765 2026] [security2:error] [pid 31913:tid 31913] [client 34.89.115.46:37452] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "listitwithsteve.com"] [uri "/.env.dev"] [unique_id "arKRn6yOV_lGQrrvdeleYgAAAB8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ธ๐ช
vaia.cloud
2026-09-22 14:25:03
(16 hours ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
Anonymous
2026-09-22 14:07:04
(16 hours ago)
Automated web scanner. Requested suspicious paths: /.env.local | /.env.bak | /.env.old | /.env.save ...
show more
Automated web scanner. Requested suspicious paths: /.env.local | /.env.bak | /.env.old | /.env.save | /.env.prod | /.env.production. UTC: 2026-09-22 13:23:49.
show less
Web App Attack