π¨π
zynex
2026-08-27 14:28:47
(44 seconds ago)
URL Probing: /.env
Web App Attack
π©πͺ
big-cloud.nl
2026-08-27 14:25:56
(3 minutes ago)
Try to access /.env
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-27 14:24:15
(5 minutes ago)
(mod_security) mod_security (id:210492) triggered by 34.9.226.97 (97.226.9.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.9.226.97 (97.226.9.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 10:24:09.710856 2026] [security2:error] [pid 32551:tid 32551] [client 34.9.226.97:44398] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "professionalpianomoversinc.com.anthonyanimalclinic.net"] [uri "/.env.local"] [unique_id "apBIibiNSeUxhyKTxsQd0QAAAFo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
maxpower
2026-08-27 13:43:55
(45 minutes ago)
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 34.9.226.97 (US/United States/97.226.9.3 ...
show more
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 34.9.226.97 (US/United States/97.226.9.34.bc.googleusercontent.com): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 34.9.226.97 - - [27/Aug/2026:15:43:50 +0200] "GET /wp-config.php.bak HTTP/1.1" 200 11912 "-" "crusader-worker/1.0" "-" host=www.ticket.samitecnopetrol.it
show less
Port Scan
π©πͺ
LRob
2026-08-27 13:18:27
(1 hour ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /wp-config.php.swp (+12 more) | 2026-08-27 13:18 UTC
show less
Hacking
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-27 13:12:18
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.9.226.97 (97.226.9.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.9.226.97 (97.226.9.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 09:12:12.833067 2026] [security2:error] [pid 29039:tid 29039] [client 34.9.226.97:54210] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "arsndetx.com"] [uri "/.env.prod"] [unique_id "apA3rHE8ANP_nydWo6Jx-wAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
mnsf
2026-08-27 13:06:24
(1 hour ago)
Too many Status 40X (19)
Brute-Force
Web App Attack
Anonymous
2026-08-27 13:01:05
(1 hour ago)
Bot / scanning and/or hacking attempts: GET /.env.prod HTTP/1.1, GET /actuator/configprops HTTP/1.1, ...
show more
Bot / scanning and/or hacking attempts: GET /.env.prod HTTP/1.1, GET /actuator/configprops HTTP/1.1, GET /.env.production HTTP/1.1, GET /wp-config.php.swp HTTP/1.1, GET /.env HTTP/1.1, GET /wp-config.php.bak HTTP/1.1, GET /.env.backup HTTP/1.1, GET /.env.old HTTP/1.1, GET /_ignition/health-check HTTP/1.1, GET /.env.save HTTP/1.1, GET /crusader-404-probe HTTP/1.1, GET /wp-config.php~ HTTP/1.1, GET /env HTTP/1.1, GET /actuator/env HTTP/1.1
show less
Hacking
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-27 12:48:05
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.9.226.97 (97.226.9.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.9.226.97 (97.226.9.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 08:48:00.193731 2026] [security2:error] [pid 15692:tid 15692] [client 34.9.226.97:39480] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ds12bonn.de"] [uri "/wp-config.php.bak"] [unique_id "apAyAE7WuxyciPbeO3sHhAAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
bazter.pro
2026-08-27 12:29:45
(1 hour ago)
Fail2Ban: apache-ratelimit - 20 failures
Port Scan
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-27 11:48:27
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.9.226.97 (97.226.9.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.9.226.97 (97.226.9.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 07:48:22.636590 2026] [security2:error] [pid 25509:tid 25509] [client 34.9.226.97:44206] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.cloggersunlimited.com.joshuashands.org"] [uri "/wp-config.php.bak"] [unique_id "apAkBuqTfCDfaAXG8vZhGQAAACQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π·π΄
iulianh
2026-08-27 11:36:02
(2 hours ago)
80,443
Brute-Force
SSH
π©πͺ
ghostwarriors
2026-08-27 11:20:06
(3 hours ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack
π³π±
e.fierstra
2026-08-27 11:11:52
(3 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
π©πͺ
yitzhaq
2026-08-27 11:07:36
(3 hours ago)
34.9.226.97 - - [27/Aug/2026:13:07:33 +0200] "GET /wp-config.php.bak HTTP/1.1" 404 46273 "-" "crusad ...
show more
34.9.226.97 - - [27/Aug/2026:13:07:33 +0200] "GET /wp-config.php.bak HTTP/1.1" 404 46273 "-" "crusader-worker/1.0"
34.9.226.97 - - [27/Aug/2026:13:07:33 +0200] "GET /wp-config.php~ HTTP/1.1" 404 46273 "-" "crusader-worker/1.0"
34.9.226.97 - - [27/Aug/2026:13:07:33 +0200] "GET /.env.old HTTP/1.1" 404 46273 "-" "crusader-worker/1.0"
34.9.226.97 - - [27/Aug/2026:13:07:33 +0200] "GET /.env.example HTTP/1.1" 404 46274 "-" "crusader-worker/1.0"
34.9.226.97 - - [27/Aug/2026:13:07:33 +0200] "GET /.env HTTP/1.1" 404 46273 "-" "crusader-worker/1.0"
34.9.226.97 - - [27/Aug/2026:13:07:33 +0200] "GET /.env.dev HTTP/1.1" 404 46272 "-" "crusader-worker/1.0"
34.9.226.97 - - [27/Aug/2026:13:07:33 +0200] "GET /wp-config.php.swp HTTP/1.1" 404 46272 "-" "crusader-worker/1.0"
34.9.226.97 - - [27/Aug/2026:13:07:33 +0200] "GET /actuator/env HTTP/1.1" 404 46273 "-" "crusader-worker/1.0"
34.9.226.97 - - [27/Aug/2026:13:07:33 +0200] "GET /.env.production HTTP/1.1" 404 46274 "-" "crusader-worker/1.0"
34.9.226.97
show less
Web App Attack
Brute-Force