🇫🇷
✨
2026-09-06 02:29:10
(24 minutes ago)
Domain : srv.hellfiremoves.co.uk
Rule : env
2026-09-06 02:28:10 ***hidden-privacy*** GET /.env.bak - ...
show more
Domain : srv.hellfiremoves.co.uk
Rule : env
2026-09-06 02:28:10 ***hidden-privacy*** GET /.env.bak - 80 - 34.104.232.23 HTTP/1.1 crusader-worker/1.0 - srv.hellfiremoves.co.uk 404 0 2 1535 103 247 - -
show less
Hacking
SQL Injection
🇺🇸
TPI-Abuse
2026-09-06 02:11:25
(42 minutes ago)
(mod_security) mod_security (id:210492) triggered by 34.104.232.23 (23.232.104.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.104.232.23 (23.232.104.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 22:11:20.807947 2026] [security2:error] [pid 5286:tid 5286] [client 34.104.232.23:36052] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "shannonraevocalstudio.com"] [uri "/.env.backup"] [unique_id "apzLyBlR2njW3hyn01VChwAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 01:44:50
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.104.232.23 (23.232.104.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.104.232.23 (23.232.104.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 21:44:44.943214 2026] [security2:error] [pid 30431:tid 30431] [client 34.104.232.23:32932] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "fantabulousburgersandpies.jbaydeliveries.com"] [uri "/.env.old"] [unique_id "apzFjDYctIgFHGZb1DMx_AAAACU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 01:11:59
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.104.232.23 (23.232.104.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.104.232.23 (23.232.104.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 21:11:50.848316 2026] [security2:error] [pid 11498:tid 11521] [client 34.104.232.23:36178] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.ahsdistance.org"] [uri "/wp-config.php.swp"] [unique_id "apy91j1yipf3j8T44v8auwAAAIw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 23:55:13
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.104.232.23 (23.232.104.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.104.232.23 (23.232.104.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 19:55:08.758291 2026] [security2:error] [pid 11223:tid 11223] [client 34.104.232.23:57986] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.jalenbattle.com"] [uri "/.env.production"] [unique_id "apyr3IJ2O55aqXzUioNcIgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇴
jad-abuse
2026-09-05 22:51:30
(4 hours ago)
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: env_probe ...
show more
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: env_probe, source_backup, scanner_ua, actuator, config_backup, ignition_debug. Observed by 1 sensor(s); 19 hits.
show less
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 22:43:11
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.104.232.23 (23.232.104.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.104.232.23 (23.232.104.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 18:43:08.196191 2026] [security2:error] [pid 29803:tid 29803] [client 34.104.232.23:60466] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "itsupitsdown.com"] [uri "/.env"] [unique_id "apya_Kh4g2aJPjyuXXP-gwAAAJU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇦
URAN Publishing Service
2026-09-05 22:00:13
(4 hours ago)
[06/Sep/2026:01:00:13 +0300] -- 34.104.232.23 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET / ...
show more
[06/Sep/2026:01:00:13 +0300] -- 34.104.232.23 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET /storage/logs/laravel.log HTTP/1.1
show less
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 21:47:23
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.104.232.23 (23.232.104.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.104.232.23 (23.232.104.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 17:47:15.215885 2026] [security2:error] [pid 1767:tid 1767] [client 34.104.232.23:60252] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htaccess" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.itony.com"] [uri "/.htaccess"] [unique_id "apyN41ITGMJusTfTRHVltAAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
dynamix
2026-09-05 21:02:19
(5 hours ago)
Multiple WAF Violations
Web App Attack
🇬🇧
consul.to
2026-09-05 20:35:40
(6 hours ago)
Web attack/malicious scanning detected
Web App Attack
🇳🇱
WeCloudit-Anti-Abuse
2026-09-05 20:33:14
(6 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
Anonymous
2026-09-05 20:28:02
(6 hours ago)
GET /.env.save HTTP/1.1
...
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 20:24:57
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.104.232.23 (23.232.104.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.104.232.23 (23.232.104.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 16:24:53.413554 2026] [security2:error] [pid 18720:tid 18720] [client 34.104.232.23:34164] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ilil.net.caonabo.com"] [uri "/.env.prod"] [unique_id "apx6lQ639h_RmMQgz-F9jQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-05 07:48:01
(19 hours ago)
Bad Web Bot