Anonymous
2026-08-28 15:24:45
(3 hours ago)
34.9.46.255 - - [28/Aug/2026:10:24:44 -0500] "GET /.env.example HTTP/1.1" 403 199 "-" "crusader-work ...
show more
34.9.46.255 - - [28/Aug/2026:10:24:44 -0500] "GET /.env.example HTTP/1.1" 403 199 "-" "crusader-worker/1.0" 34.9.46.255
34.9.46.255 - - [28/Aug/2026:10:24:44 -0500] "GET /.env.bak HTTP/1.1" 403 199 "-" "crusader-worker/1.0" 34.9.46.255
34.9.46.255 - - [28/Aug/2026:10:24:44 -0500] "GET /.env.production HTTP/1.1" 403 199 "-" "crusader-worker/1.0" 34.9.46.255
34.9.46.255 - - [28/Aug/2026:10:24:44 -0500] "GET /.env.old HTTP/1.1" 403 199 "-" "crusader-worker/1.0" 34.9.46.255
34.9.46.255 - - [28/Aug/2026:10:24:44 -0500] "GET /.env.dev HTTP/1.1" 403 199 "-" "crusader-worker/1.0" 34.9.46.255
34.9.46.255 - - [28/Aug/2026:10:24:44 -0500] "GET /.env.backup HTTP/1.1" 403 199 "-" "crusader-worker/1.0" 34.9.46.255
34.9.46.255 - - [28/Aug/2026:10:24:44 -0500] "GET /.env HTTP/1.1" 403 199 "-" "crusader-worker/1.0" 34.9.46.255
34.9.46.255 - - [28/Aug/2026:10:24:44 -0500] "GET /.env.prod HTTP/1.1" 403 199 "-" "crusader-worker/1.0" 34.9.46.255
34.9.46.255 - - [28/Aug/2026:10:24:44 -0500] "GET /.env.local
...
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Hazzard
2026-08-28 15:03:36
(3 hours ago)
(mod_security) mod_security triggered on hostname [redacted]): (CF_ENABLE)
SQL Injection
๐บ๐ธ
TPI-Abuse
2026-08-28 14:57:31
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.9.46.255 (255.46.9.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.9.46.255 (255.46.9.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 10:57:26.355124 2026] [security2:error] [pid 19475:tid 19493] [client 34.9.46.255:55716] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.maroontribe.philacentric.com"] [uri "/.env.backup"] [unique_id "apGh1kUIXH7KfbeUV-nFoQAAAUw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
mnazibo
2026-08-28 14:00:11
(4 hours ago)
Date: 28/Aug/2026 16:21:24 | Reported IP: 34.9.46.255 mod_security | id: 930130 | US/group.my_domain ...
show more
Date: 28/Aug/2026 16:21:24 | Reported IP: 34.9.46.255 mod_security | id: 930130 | US/group.my_domain/- | Connections: 19 | Blocked: Permanent Block: [LF_MODSEC] | URIs: /%2eenv; /.env; /.env.; /.env/; //.env; /.ENV; /.env.backup; /.env.bak; /.env.dev; /.env.example; /.env.local; /.env.old; /.env;.png; /.env.prod; /.env.production; /.env.save; /wp-config.php~; /wp-config.php.bak; /wp-config.php.swp | Logs: Restricted File Access Attempt
show less
SQL Injection
Brute-Force
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-08-28 13:44:53
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.9.46.255 (255.46.9.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.9.46.255 (255.46.9.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 09:44:48.567071 2026] [security2:error] [pid 8408:tid 8408] [client 34.9.46.255:42804] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.radtraininginc.radtraininginc.net"] [uri "/.env.dev"] [unique_id "apGQ0Mfxj8WPbYJEKR4bngAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 12:48:09
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.9.46.255 (255.46.9.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.9.46.255 (255.46.9.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 08:48:01.518098 2026] [security2:error] [pid 23612:tid 23612] [client 34.9.46.255:58292] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.title45.com.itaxcenter.com"] [uri "/.env.old"] [unique_id "apGDgR7kceD8sxPRxt7eUAAAAB8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
4server
2026-08-28 11:44:45
(6 hours ago)
[FriAug2813:44:42.5714522026][security2:error][pid2588348:tid2588479][client34.9.46.255:0]ModSecurit ...
show more
[FriAug2813:44:42.5714522026][security2:error][pid2588348:tid2588479][client34.9.46.255:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Patternmatch\"\(\?i\)\(\?:/\(\?:\^\|/\)\\\\\\\\.\(env\|git\|svn\|hg\|DS_Store\)\|/\(\?:wp-config\|\\\\\\\\.htaccess\|\\\\\\\\.htpasswd\)\|\\\\\\\\.\(\?:sql\|bak\|old\|log\)\$\)\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"156\"][id\"960720\"][msg\"Forbiddenfileaccessattempt\"][severity\"CRITICAL\"][hostname\"www.lastminuteweb.ch.136-243-54-122.cpanel.site\"][uri\"/wp-config.php.swp\"][unique_id\"apF0qiUop2XrsbLIowf1ggAAAJY\"]
show less
Port Scan
Brute-Force
Web App Attack
๐ฉ๐ช
mravb
2026-08-28 10:54:47
(7 hours ago)
34.9.46.255 - - [28/Aug/2026:13:54:47 +0300] "GET /.env.local HTTP/1.1" 404 149 "-" "crusader-worker ...
show more
34.9.46.255 - - [28/Aug/2026:13:54:47 +0300] "GET /.env.local HTTP/1.1" 404 149 "-" "crusader-worker/1.0"
...
show less
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-08-28 10:47:09
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.9.46.255 (255.46.9.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.9.46.255 (255.46.9.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 06:47:01.876535 2026] [security2:error] [pid 3319:tid 3319] [client 34.9.46.255:47094] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.aares2026.net"] [uri "/.env.dev"] [unique_id "apFnJXS2KGKBpS0NlVg2rQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ท๐บ
DZBOT
2026-08-28 10:47:01
(7 hours ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
๐ฌ๐ง
consul.to
2026-08-28 10:43:22
(7 hours ago)
Web attack/malicious scanning detected
Web App Attack
๐ซ๐ฎ
paissangroup
2026-08-28 10:27:41
(8 hours ago)
Multiple WAF Violations
Web App Attack
๐ฉ๐ช
ger-stg-sifi1
2026-08-28 10:09:59
(8 hours ago)
(wordpress) Failed wordpress login using wp-login.php or xmlrpc.php
Web App Attack
Anonymous
2026-08-27 22:04:25
(20 hours ago)
WordPress Enforcement Protection.
Web App Attack
๐ง๐พ
lns.bz
2026-08-27 20:21:18
(22 hours ago)
.env scanning [BY]
Web App Attack