🇫🇷
Octopuce
2026-09-06 04:15:53
(17 hours ago)
Aggressive web search of vulnerable pages: /backup.tar.gz /api/phpinfo.php /backup.rar /mysql.sql /b ...
show more
Aggressive web search of vulnerable pages: /backup.tar.gz /api/phpinfo.php /backup.rar /mysql.sql /backup.tgz ...
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 03:52:23
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.92.18.155 (155.18.92.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.92.18.155 (155.18.92.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 23:52:17.705578 2026] [security2:error] [pid 17118:tid 17118] [client 34.92.18.155:40426] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.holdingfamily.com"] [uri "/.env"] [unique_id "apzjcUW3_T-UOq93XSyosQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 02:56:36
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.92.18.155 (155.18.92.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.92.18.155 (155.18.92.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 22:56:33.023763 2026] [security2:error] [pid 24467:tid 24467] [client 34.92.18.155:40982] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.lajoze.com"] [uri "/wp-config.php.swp"] [unique_id "apzWYekjkxRuJHcmXg93LgAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
e.fierstra
2026-09-06 02:32:00
(19 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
🇺🇸
OceanTreasure
2026-09-06 02:30:10
(19 hours ago)
tcp/80; /.env* dotfile probe: "GET /.env.local" @ 2026-09-06T02:28:14Z
Web App Attack
🇫🇷
✨
2026-09-06 02:07:09
(20 hours ago)
Domain : merrionpark.com
Rule : env
2026-09-06 02:04:35 W3SVC55 PLESK76 217.194.212.5 GET /.env.back ...
show more
Domain : merrionpark.com
Rule : env
2026-09-06 02:04:35 W3SVC55 PLESK76 217.194.212.5 GET /.env.backup - 443 - 34.92.18.155 HTTP/1.1 crusader-worker/1.0 - - merrionpark.com 404 0 2 1500 98 189 - -
show less
Hacking
SQL Injection
🇺🇸
TPI-Abuse
2026-09-06 01:47:43
(20 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.92.18.155 (155.18.92.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.92.18.155 (155.18.92.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 21:47:38.363239 2026] [security2:error] [pid 4207:tid 4207] [client 34.92.18.155:37728] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ganeki.com"] [uri "/wp-config.php~"] [unique_id "apzGOvSsR24KVQJ4twR5OQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-06 01:10:19
(21 hours ago)
(config_exploit_scan) Configuratie Scanner / Nep GPTBot 34.92.18.155 (155.18.92.34.bc.googleusercont ...
show more
(config_exploit_scan) Configuratie Scanner / Nep GPTBot 34.92.18.155 (155.18.92.34.bc.googleusercontent.com): 3 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 34.92.18.155 - - [06/Sep/2026:03:10:18 +0200] "GET /.env.dev HTTP/1.1" 406 4831 "-" "crusader-worker/1.0"
34.92.18.155 - - [06/Sep/2026:03:10:18 +0200] "GET /.env.bak HTTP/1.1" 406 4829 "-" "crusader-worker/1.0"
34.92.18.155 - - [06/Sep/2026:03:10:18 +0200] "GET /.env HTTP/1.1" 406 4830 "-" "crusader-worker/1.0"
show less
Port Scan
🇺🇸
TPI-Abuse
2026-09-06 00:53:02
(21 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.92.18.155 (155.18.92.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.92.18.155 (155.18.92.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 20:52:57.636158 2026] [security2:error] [pid 26396:tid 26396] [client 34.92.18.155:40274] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "estatemartinc.com"] [uri "/.env.prod"] [unique_id "apy5ackLsv9qFWYilLVikgAAACs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
Hazzard
2026-09-06 00:07:06
(22 hours ago)
(mod_security) mod_security triggered on hostname [redacted]): (CF_ENABLE)
SQL Injection
🇳🇱
WeCloudit-Anti-Abuse
2026-09-06 00:06:09
(22 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-06 00:01:47
(22 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.92.18.155 (155.18.92.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.92.18.155 (155.18.92.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 20:01:40.922814 2026] [security2:error] [pid 21950:tid 21955] [client 34.92.18.155:59078] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "joeandlane.com"] [uri "/wp-config.php~"] [unique_id "apytZD8MvCyKEZGrI2RkhQAAAQI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
debestelapp
2026-09-05 23:55:14
(22 hours ago)
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 23:38:19
(22 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.92.18.155 (155.18.92.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.92.18.155 (155.18.92.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 19:38:12.546175 2026] [security2:error] [pid 17756:tid 17756] [client 34.92.18.155:33392] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "haisten.net"] [uri "/.env"] [unique_id "apyn5FjA1xKr0gVAV39M3QAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
consul.to
2026-09-05 23:06:28
(23 hours ago)
Web attack/malicious scanning detected
Web App Attack