๐บ๐ธ
TPI-Abuse
2026-10-09 10:05:28
(2 minutes ago)
(mod_security) mod_security (id:210492) triggered by 18.220.254.34 (ec2-18-220-254-34.us-east-2.comp ...
show more
(mod_security) mod_security (id:210492) triggered by 18.220.254.34 (ec2-18-220-254-34.us-east-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 06:05:21.451956 2026] [security2:error] [pid 29055:tid 29055] [client 18.220.254.34:63885] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "creartest.com"] [uri "/.env"] [unique_id "asi8YVz_vawP7HfMLCnc3gAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-09 05:43:04
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 18.220.254.34 (ec2-18-220-254-34.us-east-2.comp ...
show more
(mod_security) mod_security (id:210492) triggered by 18.220.254.34 (ec2-18-220-254-34.us-east-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 01:42:57.505467 2026] [security2:error] [pid 9553:tid 9553] [client 18.220.254.34:56370] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "fundaciondamashcc.org.ec"] [uri "/.env"] [unique_id "ash-4URHK5_xCqrlAewD_wAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
netclix.gr
2026-10-09 00:17:57
(9 hours ago)
(security_scan) Sensitive File Scan Blocked 18.220.254.34 (US/United States/ec2-18-220-254-34.us-eas ...
show more
(security_scan) Sensitive File Scan Blocked 18.220.254.34 (US/United States/ec2-18-220-254-34.us-east-2.compute.amazonaws.com)
show less
Hacking
๐บ๐ธ
TPI-Abuse
2026-10-08 23:33:45
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 18.220.254.34 (ec2-18-220-254-34.us-east-2.comp ...
show more
(mod_security) mod_security (id:210492) triggered by 18.220.254.34 (ec2-18-220-254-34.us-east-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 19:33:40.783535 2026] [security2:error] [pid 29962:tid 29962] [client 18.220.254.34:50173] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "apsni.net"] [uri "/.env"] [unique_id "asgoVDOOVuFw34pjKo-_MwAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
abivia
2026-10-08 23:13:57
(10 hours ago)
Abivia WAF trigger: Rule scriptKiddies: Dot file access. uri: /.env
Hacking
๐บ๐ธ
TPI-Abuse
2026-10-08 22:17:38
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 18.220.254.34 (ec2-18-220-254-34.us-east-2.comp ...
show more
(mod_security) mod_security (id:210492) triggered by 18.220.254.34 (ec2-18-220-254-34.us-east-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 18:17:32.514943 2026] [security2:error] [pid 28333:tid 28333] [client 18.220.254.34:50424] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cruisingforsex.com"] [uri "/.env"] [unique_id "asgWfP2E8rUe8qxDR1oLwQAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 21:40:39
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 18.220.254.34 (ec2-18-220-254-34.us-east-2.comp ...
show more
(mod_security) mod_security (id:210492) triggered by 18.220.254.34 (ec2-18-220-254-34.us-east-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 17:40:34.230345 2026] [security2:error] [pid 10203:tid 10203] [client 18.220.254.34:56831] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "frame-sa.com"] [uri "/.env"] [unique_id "asgN0mEwaGaNlsTYT8tbFwAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
london2038.com
2026-10-08 21:33:20
(12 hours ago)
Probing for exploits
18.220.254.34 - - [08/Oct/2026:23:33:16 +0200] "GET /.env HTTP/1.1" 422 0 "-" " ...
show more
Probing for exploits
18.220.254.34 - - [08/Oct/2026:23:33:16 +0200] "GET /.env HTTP/1.1" 422 0 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36"
18.220.254.34 - - [08/Oct/2026:23:33:18 +0200] "GET /sendgrid/.env HTTP/1.1" 422 0 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36"
show less
Hacking
Web App Attack
Anonymous
2026-10-08 17:25:02
(16 hours ago)
suspicious request in access.log
Web App Attack
๐ท๐ธ
pexodelic
2026-10-08 16:43:58
(17 hours ago)
Automated report from web, SSH and FTP server logs: 6 requests probing for exposed secrets (.env, .g ...
show more
Automated report from web, SSH and FTP server logs: 6 requests probing for exposed secrets (.env, .git, config files). First reported 2026-10-08 15:05 UTC, last reported 2026-10-08 16:05 UTC; counts cover the current log rotation window.
show less
Web App Attack
๐จ๐ญ
lufi
2026-10-08 16:06:45
(18 hours ago)
2026-10-08 18:06:44 18.220.254.34: blacklistedPath: /.env
...
Web Spam
Brute-Force
Hacking
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-10-08 15:44:31
(18 hours ago)
[08/Oct/2026:18:44:31 +0300] -- 18.220.254.34 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET / ...
show more
[08/Oct/2026:18:44:31 +0300] -- 18.220.254.34 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET /.env HTTP/1.1
show less
Bad Web Bot
Web App Attack
๐ฎ๐น
Inartis
2026-10-08 15:10:09
(18 hours ago)
18.220.254.34 - - [08/Oct/2026:17:10:08 +0200] "GET /.env HTTP/1.1" 302 487 "-" "Mozilla/5.0 (X11; L ...
show more
18.220.254.34 - - [08/Oct/2026:17:10:08 +0200] "GET /.env HTTP/1.1" 302 487 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36"
...
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 14:48:10
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 18.220.254.34 (ec2-18-220-254-34.us-east-2.comp ...
show more
(mod_security) mod_security (id:210492) triggered by 18.220.254.34 (ec2-18-220-254-34.us-east-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 10:48:03.162480 2026] [security2:error] [pid 13545:tid 13545] [client 18.220.254.34:64796] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cephedanisman.com"] [uri "/.env"] [unique_id "asetIwLmD7cAi_6ydEibIgAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-10-08 14:47:03
(19 hours ago)
Web App Attack
Brute-Force
Exploited Host
Web App Attack