πΊπΈ
TPI-Abuse
2026-08-01 17:28:38
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.118.48.73 (73.48.118.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.118.48.73 (73.48.118.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 13:28:34.063512 2026] [security2:error] [pid 3079165:tid 3079165] [client 34.118.48.73:49444] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "tomweston.net.marxistphilosophy.org"] [uri "/.env"] [unique_id "am4swlf0MFZIB6GpCb1VawAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-01 17:14:46
(16 hours ago)
[server.tmg.gr] httpd-config-scan: sites=www.cardiorenal2026.gr; logs=/var/log/httpd/domains/cardior ...
show more
[server.tmg.gr] httpd-config-scan: sites=www.cardiorenal2026.gr; logs=/var/log/httpd/domains/cardiorenal2026.gr.log; samples=/.env.old | /.env.example | /.env.save
show less
Hacking
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-01 17:10:46
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.118.48.73 (73.48.118.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.118.48.73 (73.48.118.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 13:10:39.650107 2026] [security2:error] [pid 2437361:tid 2437361] [client 34.118.48.73:34314] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.littlestarbookspub.com.flashbackmusicmemories.com"] [uri "/.env"] [unique_id "am4oj7hQ9XwLCdvfLeJEjQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-01 16:55:45
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.118.48.73 (73.48.118.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.118.48.73 (73.48.118.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 12:55:40.626954 2026] [security2:error] [pid 2252494:tid 2252494] [client 34.118.48.73:38790] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "rallentarecg.com"] [uri "/.env.example"] [unique_id "am4lDCDya2k7ySZ4ROATAAAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-01 16:15:57
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.118.48.73 (73.48.118.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.118.48.73 (73.48.118.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 12:15:50.653606 2026] [security2:error] [pid 776808:tid 776808] [client 34.118.48.73:53616] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.burnshieldmena.thechoiceint.com"] [uri "/.env"] [unique_id "am4btm8HZJLsWARtZkgPlQAAACo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π¨π
4server
2026-08-01 15:51:42
(18 hours ago)
[SatAug0117:51:37.9691042026][security2:error][pid4112730:tid4112805][client34.118.48.73:0]ModSecuri ...
show more
[SatAug0117:51:37.9691042026][security2:error][pid4112730:tid4112805][client34.118.48.73:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\".env\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"365\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"hostingsvizzera.ch\"][uri\"/.env.local\"][unique_id\"am4WCQR7L7N01Q574W1jpgAAAYc\"]
show less
Hacking
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-01 15:48:14
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.118.48.73 (73.48.118.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.118.48.73 (73.48.118.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 11:48:07.226312 2026] [security2:error] [pid 976543:tid 976543] [client 34.118.48.73:49444] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "billhumphreyresearch.com"] [uri "/.env.bak"] [unique_id "am4VN2Jv8_94tiqAA2iP8AAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
Webhoster
2026-08-01 15:43:27
(18 hours ago)
{"ClientAddr":"162.158.102.175:10313","ClientHost":"34.118.48.73","ClientPort":"10313","ClientUserna ...
show more
{"ClientAddr":"162.158.102.175:10313","ClientHost":"34.118.48.73","ClientPort":"10313","ClientUsername":"-","DownstreamContentSize":0,"DownstreamStatus":403,"Duration":53408482,"OriginContentSize":0,"OriginDuration":0,"OriginStatus":0,"Overhead":53408482,"RequestAddr":"ai.timvdberg.dev","RequestContentSize":0,"RequestCount":624109,"RequestHost":"ai.timvdberg.dev","RequestMethod":"GET","RequestPath":"/.env.example","RequestPort":"-","RequestProtocol":"HTTP/2.0","RequestScheme":"https","RetryAttempts":0,"RouterName":"ai@file","StartLocal":"2026-08-01T15:43:26.256988253Z","StartUTC":"2026-08-01T15:43:26.256988253Z","TLSCipher":"TLS_AES_128_GCM_SHA256","TLSVersion":"1.3","entryPointName":"https","level":"info","msg":"","request_Cf-Connecting-Ip":"34.118.48.73","request_X-Forwarded-For":"34.118.48.73","request_X-Real-Ip":"162.158.102.175","time":"2026-08-01T15:43:26Z"}
{"ClientAddr":"172.64.200.54:10623","ClientHost":"34.118.48.73","ClientPort":"10623","ClientUsername":"-","DownstreamConten
...
show less
Port Scan
Hacking
Bad Web Bot
Web App Attack
Anonymous
2026-08-01 15:20:03
(18 hours ago)
suspicious request in access.log
Web App Attack
πΈπͺ
vaia.cloud
2026-08-01 14:55:02
(19 hours ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
π§π·
Halux
2026-08-01 14:43:43
(19 hours ago)
34.118.48.73 Probing protected path or service
Web App Attack
πΊπΈ
Matthew Ping
2026-08-01 14:30:03
(19 hours ago)
ModSecurity rule 949110 triggered on d865. Web application attack blocked by CSF/LFD.
Web App Attack
Hacking
π©πͺ
dbmwebdesign
2026-08-01 14:15:08
(19 hours ago)
WAF repeated trigger detected by Fail2Ban in plesk-modsecurity jail
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-01 14:14:04
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.118.48.73 (73.48.118.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.118.48.73 (73.48.118.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 10:13:58.847221 2026] [security2:error] [pid 1989688:tid 1989688] [client 34.118.48.73:48030] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.weismaninfrared.daveweisman.com"] [uri "/.env"] [unique_id "am3_Jp_b-YjnS9KIFw_iPAAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-01 14:08:17
(19 hours ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack