🇬🇧
consul.to
2026-09-06 04:43:57
(3 hours ago)
Web attack/malicious scanning detected
Web App Attack
Anonymous
2026-09-06 03:33:01
(4 hours ago)
Aggressive web scan
Web App Attack
🇫🇷
✨
2026-09-06 03:08:18
(4 hours ago)
Domain : woodyroad.church
Rule : hack
2026-09-06 03:06:27 ***hidden-privacy*** GET /.env.bak - 443 - ...
show more
Domain : woodyroad.church
Rule : hack
2026-09-06 03:06:27 ***hidden-privacy*** GET /.env.bak - 443 - 172.69.6.187 HTTP/2 crusader-worker/1.0 - woodyroad.church 404 0 0 44078 340 11995 - 34.9.135.97
show less
Hacking
SQL Injection
Brute-Force
🇺🇸
TPI-Abuse
2026-09-06 02:58:18
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.9.135.97 (97.135.9.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.9.135.97 (97.135.9.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 22:58:10.583106 2026] [security2:error] [pid 3813:tid 3813] [client 34.9.135.97:50384] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.mrbss.com"] [uri "/.env.backup"] [unique_id "apzWwhebh5e_e05KjoZH1wAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
kkw
2026-09-06 02:56:55
(4 hours ago)
[REDACTED] 34.9.135.97 - - [06/Sep/2026:04:56:54 +0200] "GET /.env.bak HTTP/1.1" 401 4706 "-" "crusa ...
show more
[REDACTED] 34.9.135.97 - - [06/Sep/2026:04:56:54 +0200] "GET /.env.bak HTTP/1.1" 401 4706 "-" "crusader-worker/1.0"
... (mode: searching http-sensitive-files)
show less
Bad Web Bot
Web App Attack
🇩🇪
AetherFox
2026-09-06 02:39:44
(5 hours ago)
AetherFox VoidGuard detected: [Sun Sep 06 02:39:44.256873 2026] [authz_core:error] [pid 898373:tid 8 ...
show more
AetherFox VoidGuard detected: [Sun Sep 06 02:39:44.256873 2026] [authz_core:error] [pid 898373:tid 898400] [client 34.9.135.97:54658] AH01630: client denied by server configuration: proxy:https://freebeegee.draconigen.de/.env.save
[Sun Sep 06 02:39:44.256980 2026] [authz_core:error] [pid 898373:tid 898400] [client 34.9.135.97:54658] AH01630: client denied by server configuration: /var/www/html/ERRORpages/403.html
[Sun Sep 06 02:39:44.257480 2026] [authz_core:error] [pid 898374:tid 898425] [client 34.9.135.97:54778] AH01630: client denied by server configuration: proxy:https://freebeegee.draconigen.de/.env.old
[Sun Sep 06 02:39:44.257601 2026] [authz_core:error] [pid 898374:tid 898425] [client 34.9.135.97:54778] AH01630: client denied by server configuration: /var/www/html/ERRORpages/403.html
[Sun Sep 06 02:39:44.257779 2026] [authz_core:error] [pid 898374:tid 898424] [client 34.9.135.97:54732] AH01630: client denied by server configuration: proxy:https://freebeegee.
...
show less
Bad Web Bot
Web App Attack
🇫🇷
masterguru
2026-09-06 02:29:45
(5 hours ago)
Attempt to access a backup or working file. Pattern match "\\\\. (920500-193)
Hacking
🇺🇸
TPI-Abuse
2026-09-06 02:19:19
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.9.135.97 (97.135.9.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.9.135.97 (97.135.9.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 22:19:14.707792 2026] [security2:error] [pid 1511:tid 1511] [client 34.9.135.97:47106] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "stonesandbones.net"] [uri "/wp-config.php.swp"] [unique_id "apzNonHI-hI-RHRWZIWaogAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
mnsf
2026-09-06 02:05:31
(5 hours ago)
Scanning/Probing (18)
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 02:01:47
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.9.135.97 (97.135.9.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.9.135.97 (97.135.9.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 22:01:42.970775 2026] [security2:error] [pid 30727:tid 30746] [client 34.9.135.97:44442] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mailsrv.absurdotron.com"] [uri "/.env.bak"] [unique_id "apzJhlyjTaewCShlwzfHkAAAAEk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-06 00:08:11
(7 hours ago)
[ns3.backorder.gr] httpd-config-scan: logs=/var/log/httpd/access_log; samples=/actuator/configprops ...
show more
[ns3.backorder.gr] httpd-config-scan: logs=/var/log/httpd/access_log; samples=/actuator/configprops | /.env.local | /wp-config.php.bak
show less
Hacking
Web App Attack
🇬🇧
Aetherweb Ark
2026-09-06 00:03:46
(7 hours ago)
(mod_security) mod_security (id:949110) triggered by 34.9.135.97 (US/United States/97.135.9.34.bc.go ...
show more
(mod_security) mod_security (id:949110) triggered by 34.9.135.97 (US/United States/97.135.9.34.bc.googleusercontent.com): N in the last X secs
show less
Web App Attack
🇮🇩
penjaga BRIN
2026-09-06 00:02:54
(7 hours ago)
Suspicious malicious activity
Hacking
🇩🇪
big-cloud.nl
2026-09-05 23:57:08
(7 hours ago)
Try to access /.env
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 23:55:06
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.9.135.97 (97.135.9.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.9.135.97 (97.135.9.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 19:54:58.817212 2026] [security2:error] [pid 6905:tid 6905] [client 34.9.135.97:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.dentguyvt.com"] [uri "/.env.dev"] [unique_id "apyr0kcdJVJVvJ0-hInrNwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack