🇧🇾
lns.bz
2026-09-06 06:23:20
(9 hours ago)
Too many 404 requests [BY]
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 03:54:47
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.95.18.92 (92.18.95.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.95.18.92 (92.18.95.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 23:54:38.985287 2026] [security2:error] [pid 24743:tid 24743] [client 34.95.18.92:34912] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.groz.net"] [uri "/.env"] [unique_id "apzj_v-_fUuUNXkekAKS6QAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 02:57:44
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.95.18.92 (92.18.95.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.95.18.92 (92.18.95.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 22:57:39.748381 2026] [security2:error] [pid 1733:tid 1733] [client 34.95.18.92:36286] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.district7vote.com"] [uri "/.env.backup"] [unique_id "apzWo8wTgN7ew7YIhxbbgAAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 02:39:01
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.95.18.92 (92.18.95.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.95.18.92 (92.18.95.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 22:38:55.631564 2026] [security2:error] [pid 1508:tid 1508] [client 34.95.18.92:58496] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "industrialgraphicdesign.com"] [uri "/.env.example"] [unique_id "apzSPxnOo31P7Z1mEOz43QAAAIA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-06 02:25:40
(13 hours ago)
(config_exploit_scan) Configuratie Scanner / Nep GPTBot 34.95.18.92 (CA/Canada/92.18.95.34.bc.google ...
show more
(config_exploit_scan) Configuratie Scanner / Nep GPTBot 34.95.18.92 (CA/Canada/92.18.95.34.bc.googleusercontent.com): 3 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 34.95.18.92 - - [06/Sep/2026:04:25:38 +0200] "GET /.env.backup HTTP/1.1" 406 4829 "-" "crusader-worker/1.0"
34.95.18.92 - - [06/Sep/2026:04:25:38 +0200] "GET /.env.example HTTP/1.1" 406 4830 "-" "crusader-worker/1.0"
34.95.18.92 - - [06/Sep/2026:04:25:38 +0200] "GET /.env.prod HTTP/1.1" 406 4830 "-" "crusader-worker/1.0"
show less
Port Scan
🇮🇹
clamehost.it
2026-09-06 01:45:11
(14 hours ago)
Automatic report - Brute Force attack using this IP address
Brute-Force
🇺🇸
TPI-Abuse
2026-09-06 01:44:20
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.95.18.92 (92.18.95.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.95.18.92 (92.18.95.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 21:44:14.904815 2026] [security2:error] [pid 20892:tid 20892] [client 34.95.18.92:51024] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ftp.domainexecs.com"] [uri "/.env.production"] [unique_id "apzFbhohHWM3y835CU3C3QAAAI4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
BlueWire Hosting
2026-09-06 01:37:11
(14 hours ago)
Probing websites for vulnerabilities
Web App Attack
Anonymous
2026-09-06 00:30:24
(15 hours ago)
[ssd1.kdns.gr] httpd-config-scan: logs=/var/log/httpd/access_log; samples=/.env.dev | /.env.prod | / ...
show more
[ssd1.kdns.gr] httpd-config-scan: logs=/var/log/httpd/access_log; samples=/.env.dev | /.env.prod | /actuator/configprops
show less
Hacking
Web App Attack
🇩🇪
Skyrider
2026-09-06 00:16:45
(15 hours ago)
crowdsecurity/http-sensitive-files
Web App Attack
🇺🇸
mw
2026-09-06 00:00:26
(16 hours ago)
GET /.env.production HTTP/1.1
Web App Attack
Anonymous
2026-09-05 23:59:03
(16 hours ago)
Bot / scanning and/or hacking attempts: GET /wp-config.php.swp HTTP/1.1, GET /.env.prod HTTP/1.1, GE ...
show more
Bot / scanning and/or hacking attempts: GET /wp-config.php.swp HTTP/1.1, GET /.env.prod HTTP/1.1, GET /crusader-404-probe HTTP/1.1, GET /env HTTP/1.1, GET /actuator/configprops HTTP/1.1, GET /.env.production HTTP/1.1, GET /_ignition/health-check HTTP/1.1, GET /storage/logs/laravel.log HTTP/1.1, GET /.env.local HTTP/1.1, GET /.env.bak HTTP/1.1, GET /wp-config.php.bak HTTP/1.1
show less
Hacking
Web App Attack
🇳🇱
WeCloudit-Anti-Abuse
2026-09-05 22:59:56
(17 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
🇳🇱
e.fierstra
2026-09-05 22:58:55
(17 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
🇬🇧
consul.to
2026-09-05 22:23:27
(17 hours ago)
Web attack/malicious scanning detected
Web App Attack