๐บ๐ธ
TPI-Abuse
2026-08-01 17:33:02
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.102.30.137 (137.30.102.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.102.30.137 (137.30.102.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 13:32:54.350074 2026] [security2:error] [pid 917869:tid 917869] [client 34.102.30.137:32962] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "yogawithbubba.com"] [uri "/.env.save"] [unique_id "am4txhcipSnCxA_O3BbTKgAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
4server
2026-08-01 17:31:16
(14 hours ago)
[SatAug0119:31:11.2290012026][security2:error][pid237922:tid238149][client34.102.30.137:0]ModSecurit ...
show more
[SatAug0119:31:11.2290012026][security2:error][pid237922:tid238149][client34.102.30.137:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\".env\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"365\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"mail.cacciatorichiasso.ch\"][uri\"/.env.bak\"][unique_id\"am4tX0iA1BwsA8M985dZGwAAAEU\"]
show less
Hacking
Web App Attack
๐ฉ๐ช
LRob
2026-08-01 16:36:20
(15 hours ago)
CrowdSec: crowdsecurity/http-sensitive-files | req: /.env.backup | 5 distinct paths | UA: crusader-w ...
show more
CrowdSec: crowdsecurity/http-sensitive-files | req: /.env.backup | 5 distinct paths | UA: crusader-worker/1.0
show less
Hacking
๐บ๐ธ
TPI-Abuse
2026-08-01 16:35:29
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.102.30.137 (137.30.102.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.102.30.137 (137.30.102.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 12:35:23.050514 2026] [security2:error] [pid 27006:tid 27006] [client 34.102.30.137:44814] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.abilityimprinting.abilityengraving.com"] [uri "/.env.backup"] [unique_id "am4gS2JDxA-qX1GOjFo-wQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
zynex
2026-08-01 16:32:47
(15 hours ago)
URL Probing: /.env
Web App Attack
๐บ๐ธ
Matthew Ping
2026-08-01 16:15:04
(16 hours ago)
ModSecurity rule 949110 triggered on d865. Web application attack blocked by CSF/LFD.
Web App Attack
Hacking
๐ซ๐ท
LRNP
2026-08-01 16:04:56
(16 hours ago)
_:443 34.102.30.137 - - [01/Aug/2026:16:04:47 +0000] "GET /.env HTTP/1.1" 404 146 "-" "crusader-work ...
show more
_:443 34.102.30.137 - - [01/Aug/2026:16:04:47 +0000] "GET /.env HTTP/1.1" 404 146 "-" "crusader-worker/1.0"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
johnkarlhill
2026-08-01 15:45:01
(16 hours ago)
WebKnight blocked malicious web request on johnkarlhill.com
Brute-Force
SSH
๐ณ๐ฑ
e.fierstra
2026-08-01 15:43:00
(16 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐ณ๐ด
jad-abuse
2026-08-01 15:42:06
(16 hours ago)
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: env_probe ...
show more
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: env_probe, source_backup. Observed by 1 sensor(s); 10 hits.
show less
Web App Attack
๐ฉ๐ช
4server
2026-08-01 15:40:22
(16 hours ago)
[SatAug0117:40:18.1987482026][security2:error][pid1698925:tid1699016][client34.102.30.137:0]ModSecur ...
show more
[SatAug0117:40:18.1987482026][security2:error][pid1698925:tid1699016][client34.102.30.137:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:5\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.10\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"www.akastudio.ch.136-243-54-122.cpanel.site\"][uri\"/.env.example\"][unique_id\"am4TYrcSgRfDptQn6SNmAgAAAMc\"]
show less
Port Scan
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-01 15:34:18
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.102.30.137 (137.30.102.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.102.30.137 (137.30.102.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 11:34:12.651497 2026] [security2:error] [pid 10158:tid 10158] [client 34.102.30.137:33556] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.jessemeyersconsulting.jessemeyers.com"] [uri "/.env.local"] [unique_id "am4R9O1EGFd9VQA8QTL-sgAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-08-01 15:33:17
(16 hours ago)
URL file extension is restricted by policy. String match within ".ani/ .asa/ .asax/ .ascx/ .backup/ ...
show more
URL file extension is restricted by policy. String match within ".ani/ .asa/ .asax/ .ascx/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .compositefont/ .config/ .conf/ .crt/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dist/ .dll/ .dos/ .dpkg-dist/ .drv/ .gadget/ .hta/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .inf/ .ini/ .jse/ .key/ .licx/ .lnk/ .log/ .mdb/ .msc/ .ocx/ .old/ .pass/ .pdb/ .pfx/ .pif/ .pem/ .pol/ .prf/ .printer/ .pwd/ .rdb/ .rdp/ .reg/ .resources/ .resx/ .scr/ .sct/ .shs/ .sql/ .swp/ .sys/ .tlb/ .tmp/ .url/ .vb/ .vbe/ .vbs/ .vbproj/ .vsdisco/ .vxd/ .webinfo/ .ws/ .wsc/ .wsf/ .wsh/ .xsd/ .xsx/" at TX:extension. (920440-195)
show less
Hacking
๐บ๐ธ
TPI-Abuse
2026-08-01 14:33:43
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.102.30.137 (137.30.102.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.102.30.137 (137.30.102.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 10:33:37.966564 2026] [security2:error] [pid 708458:tid 708490] [client 34.102.30.137:38018] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cynosureirrigation.com.cynosureinternetservices.com"] [uri "/.env.local"] [unique_id "am4DwR3PurNDA53-AL7YPQAAAdE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
SCHAPPY
2026-08-01 14:19:12
(17 hours ago)
Brute-force attack to non-existent web resources, HTTP code 404.
Brute-Force
Web App Attack