๐จ๐ญ
zynex
2026-09-01 13:09:14
(18 minutes ago)
URL Probing: /wp-config.php.bak
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 12:15:24
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.10.24.185 (185.24.10.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.10.24.185 (185.24.10.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 08:15:19.284496 2026] [security2:error] [pid 8531:tid 8531] [client 34.10.24.185:33208] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "scottwithers.xyz"] [uri "/.env.local"] [unique_id "apbB13T_dRMpnU2QM7Ox1AAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 10:59:03
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.10.24.185 (185.24.10.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.10.24.185 (185.24.10.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 06:58:57.079607 2026] [security2:error] [pid 4966:tid 4966] [client 34.10.24.185:45814] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.mindheartbreath.com"] [uri "/.env.prod"] [unique_id "apav8f804m_G0VtwwC_jrQAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-09-01 10:47:46
(2 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-09-01 10:11:33
(3 hours ago)
Restricted File Access Attempt. Matched phrase ".env" at REQUEST_FILENAME. (930130-193)
Hacking
Web App Attack
๐ฉ๐ช
Gwyneth Llewelyn
2026-09-01 10:01:55
(3 hours ago)
2026/09/01 11:01:50 [error] 380595#380595: *2050017 access forbidden by rule, client: 34.10.24.185, ...
show more
2026/09/01 11:01:50 [error] 380595#380595: *2050017 access forbidden by rule, client: 34.10.24.185, server: [redacted], request: "GET /.env HTTP/2.0", host: "fashcon.betatechnologies.info"
34.10.24.185 - - [01/Sep/2026:11:01:50 +0100] "GET /.env HTTP/2.0" 403 1045 "-" "crusader-worker/1.0"
2026/09/01 11:01:53 [error] 380594#380594: *2050019 access forbidden by rule, client: 34.10.24.185, server: [redacted], request: "GET //.env HTTP/2.0", host: "fashcon.betatechnologies.info"
show less
Brute-Force
Web App Attack
๐ฉ๐ช
Nevermind
2026-09-01 09:59:14
(3 hours ago)
34.10.24.185 - - [01/Sep/2026:11:59:14 +0200] "GET /.env.backup HTTP/1.1" 403 5673 "-" "crusader-wor ...
show more
34.10.24.185 - - [01/Sep/2026:11:59:14 +0200] "GET /.env.backup HTTP/1.1" 403 5673 "-" "crusader-worker/1.0"
34.10.24.185 - - [01/Sep/2026:11:59:14 +0200] "GET /.env.prod HTTP/1.1" 403 5673 "-" "crusader-worker/1.0"
34.10.24.185 - - [01/Sep/2026:11:59:14 +0200] "GET /wp-config.php.bak HTTP/1.1" 403 5673 "-" "crusader-worker/1.0"
34.10.24.185 - - [01/Sep/2026:11:59:14 +0200] "GET /.env.dev HTTP/1.1" 403 5673 "-" "crusader-worker/1.0"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 09:51:03
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.10.24.185 (185.24.10.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.10.24.185 (185.24.10.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 05:50:58.804483 2026] [security2:error] [pid 226453:tid 226513] [client 34.10.24.185:48012] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "slingshotpro.com"] [uri "/.env.dev"] [unique_id "apagArXrnWkgbzFp5H75zgAAAFg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ญ๐ฐ
Mehmet_The_Script_Kiddie
2026-09-01 09:44:16
(3 hours ago)
AUTOMATED REPORT: Tried to access .env file/.env.backup
Bad Web Bot
Web App Attack
๐ฏ๐ต
warudora
2026-09-01 08:49:11
(4 hours ago)
Automated Honeypot Trap: Attempted to access sensitive path '/.env.dev' on a Flask server.
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 08:42:53
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.10.24.185 (185.24.10.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.10.24.185 (185.24.10.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 04:42:49.943306 2026] [security2:error] [pid 26563:tid 26563] [client 34.10.24.185:37112] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "server1.davisllp.com"] [uri "/.env.save"] [unique_id "apaQCTt6gs76NZqfSJJLpgAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-01 08:20:02
(5 hours ago)
suspicious request in access.log
Web App Attack
๐ฉ๐ช
4server
2026-09-01 08:17:00
(5 hours ago)
[TueSep0110:16:54.4631242026][security2:error][pid3893308:tid3893397][client34.10.24.185:0]ModSecuri ...
show more
[TueSep0110:16:54.4631242026][security2:error][pid3893308:tid3893397][client34.10.24.185:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Patternmatch\"\(\?i\)\(\?:/\(\?:\^\|/\)\\\\\\\\.\(env\|git\|svn\|hg\|DS_Store\)\|/\(\?:wp-config\|\\\\\\\\.htaccess\|\\\\\\\\.htpasswd\)\|\\\\\\\\.\(\?:sql\|bak\|old\|log\)\$\)\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"156\"][id\"960720\"][msg\"Forbiddenfileaccessattempt\"][severity\"CRITICAL\"][hostname\"atelier-lara.ch\"][uri\"/wp-config.php.bak\"][unique_id\"apaJ9hhpR4sTHkR5d1lRhwAAAJU\"]
show less
Port Scan
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 07:38:45
(5 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.10.24.185 (185.24.10.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.10.24.185 (185.24.10.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 03:38:41.785542 2026] [security2:error] [pid 611:tid 611] [client 34.10.24.185:34046] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||zeetec.nl|F|2"] [data ".log"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "zeetec.nl"] [uri "/storage/logs/laravel.log"] [unique_id "apaBAfkQhyh9oBU7j_-ySAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
masterguru
2026-09-01 07:16:45
(6 hours ago)
Inbound Anomaly Score Exceeded (Total Score: 10). Operator GE matched 5 at TX:anomaly_score. (949110 ...
show more
Inbound Anomaly Score Exceeded (Total Score: 10). Operator GE matched 5 at TX:anomaly_score. (949110-122)
show less
Hacking