๐ณ๐ฑ
Savvii
2026-06-15 16:10:56
(8 hours ago)
20 attempts against mh-misbehave-ban on redirect
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Savvii
2026-06-15 14:14:43
(10 hours ago)
20 attempts against mh_ha-misbehave-ban on lime
Brute-Force
Bad Web Bot
Web App Attack
๐ฒ๐พ
Rizzy
2026-06-15 08:40:05
(16 hours ago)
Multiple WAF Violations
Brute-Force
Web App Attack
Anonymous
2026-06-15 05:33:42
(19 hours ago)
Multiple web server 400 error codes from same source ip
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-15 05:24:59
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.11.18.169 (169.18.11.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.11.18.169 (169.18.11.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 15 01:24:55.701640 2026] [security2:error] [pid 24974:tid 24974] [client 34.11.18.169:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.c2cservices.com"] [uri "/.env.backup"] [unique_id "ai-MpzNOv9oMJwakJVKpSgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
SiyCah
2026-06-15 03:00:02
(22 hours ago)
IP banned by fail2ban; banned in jail apache-modsecurity. Report generated by fail2abuseipdb.
Hacking
Brute-Force
Web App Attack
Anonymous
2026-06-15 02:34:04
(22 hours ago)
Bot / scanning and/or hacking attempts: GET /wp/.env HTTP/1.1, GET /public/.env HTTP/1.1, GET /.env. ...
show more
Bot / scanning and/or hacking attempts: GET /wp/.env HTTP/1.1, GET /public/.env HTTP/1.1, GET /.env.production HTTP/1.1, GET /api/.env.production HTTP/1.1, GET /.env.preprod HTTP/1.1, GET /.env.uat HTTP/1.1, GET /docker/.env HTTP/1.1, GET /private/.env.production HTTP/1.1, GET /sendgrid/.env.local HTTP/1.1, GET /app/sendgrid.env HTTP/1.1, GET /email/sendgrid.env HTTP/1.1, GET /html/.env HTTP/1.1, GET /backend/.env.bak HTTP/1.1, GET /sendgrid/.env.backup HTTP/1.1, GET /sendgrid/.env.production HTTP/1.1, GET /uat/.env HTTP/1.1, GET /src/sendgrid.env HTTP/1.1, GET /mailer/sendgrid.env HTTP/1.1, GET /mail/sendgrid.env HTTP/1.1
show less
Hacking
Web App Attack
๐ฌ๐ง
consul.to
2026-06-15 02:00:29
(23 hours ago)
Web attack/malicious scanning detected
Web App Attack
๐ฌ๐ท
setupgr
2026-06-15 01:51:49
(23 hours ago)
(mod_security) mod_security (id:11000011) triggered by 34.11.18.169: 1 in the last 86400 secs; Ports ...
show more
(mod_security) mod_security (id:11000011) triggered by 34.11.18.169: 1 in the last 86400 secs; Ports: *; Direction: inout; Trigger: LF_TRIGGER; Logs: [Mon Jun 15 04:51:45.625532 2026] [security2:error] [pid 921889:tid 922066] [client 34.11.18.169:60780] ModSecurity: Access denied with code 406 (phase 1). Matched phrase "googleusercontent.com" at REMOTE_HOST. [file "/etc/apache2/conf.d/modsec/modsec2.user.conf"] [line "128"] [id "11000011"] [msg "BLOCKED BAD DOMAIN: 169.18.11.34.bc.googleusercontent.com"] [hostname "babis.photo"] [uri "/backend/.env"] [unique_id "ai9asSykT1eM1OfD7bs8FgAAAUs"]
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-06-15 00:41:47
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.11.18.169 (169.18.11.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.11.18.169 (169.18.11.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 20:41:41.171989 2026] [security2:error] [pid 10196:tid 10196] [client 34.11.18.169:44520] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.clubmarshall.com.andrewrmarshall.com"] [uri "/.env.local"] [unique_id "ai9KRTvVq9f1N1orwIjisAAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-06-14 23:02:28
(1 day ago)
Excessive 404/403 errors
Brute-Force
๐ณ๐ฑ
debestelapp
2026-06-14 22:25:09
(1 day ago)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-14 21:02:28
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.11.18.169 (169.18.11.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.11.18.169 (169.18.11.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 17:02:21.022914 2026] [security2:error] [pid 28655:tid 28655] [client 34.11.18.169:60282] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.bodyonabudget.daebakdesign.com"] [uri "/.env.local"] [unique_id "ai8W3QVL_Y1luenv0LCJiwAAADI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Baking333
2026-06-14 19:10:15
(1 day ago)
[redacted] 34.11.18.169 - - [14/Jun/2026:20:10:14 +0100] "GET /.env HTTP/1.1" 200 3937 0/94900 "-" " ...
show more
[redacted] 34.11.18.169 - - [14/Jun/2026:20:10:14 +0100] "GET /.env HTTP/1.1" 200 3937 0/94900 "-" "Mozilla/5.0 (Linux; Android 8.0.0; RNE-L21) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/76.0.3809.89 Mobile Safari/537.36" [redacted] 34.11.18.169 - - [14/Jun/2026:20:10:14 +0100] "GET /.[redacted] HTTP/1.1" 200 3937 0/95318 "-" "Mozilla/5.0 (Linux; Android 6.0; HTC One M9 Build/MRA58K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.98 Mobile Safari/537.36"
show less
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Savvii
2026-06-14 17:51:34
(1 day ago)
81 attempts against mh-misbehave-ban on tin
Brute-Force
Bad Web Bot
Web App Attack