๐ฑ๐ป
garmtech.com
2026-07-19 00:49:14
(1 day ago)
IM360 WAF: Direct access to sensitive file or dotfile MV:/.env.staging
Web App Attack
๐ฑ๐ป
garmtech.com
2026-07-18 19:42:32
(1 day ago)
IM360 WAF: Direct access to sensitive file or dotfile MV:/.env.production
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-18 14:58:58
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.122.33.47 (47.33.122.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.122.33.47 (47.33.122.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 18 10:58:51.289880 2026] [security2:error] [pid 2241146:tid 2241146] [client 34.122.33.47:63469] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "hotpay.co"] [uri "/.env"] [unique_id "aluUq1Regezu_AwmXUapGwAAAAA"], referer: https://google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฑ๐ป
garmtech.com
2026-07-18 14:28:16
(1 day ago)
IM360 WAF: Direct access to sensitive file or dotfile MV:/.env
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-18 12:45:43
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.122.33.47 (47.33.122.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.122.33.47 (47.33.122.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 18 08:45:35.946886 2026] [security2:error] [pid 31170:tid 31170] [client 34.122.33.47:65017] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "healthpointphysicians.co"] [uri "/.env"] [unique_id "alt1bxavrYTSZTDUIdinFQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-18 11:37:42
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.122.33.47 (47.33.122.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.122.33.47 (47.33.122.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 18 07:37:35.832056 2026] [security2:error] [pid 16289:tid 16289] [client 34.122.33.47:62905] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "forwardfusion.co"] [uri "/.env"] [unique_id "altlf3u40oWc1KaLmLhMqAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-18 11:10:00
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.122.33.47 (47.33.122.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.122.33.47 (47.33.122.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 18 07:09:55.040299 2026] [security2:error] [pid 12113:tid 12113] [client 34.122.33.47:63597] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "genesis7.co"] [uri "/.env"] [unique_id "altfA24CxHzmEskvl_vm4AAAAAQ"], referer: https://google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-18 10:34:00
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.122.33.47 (47.33.122.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.122.33.47 (47.33.122.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 18 06:33:55.613119 2026] [security2:error] [pid 4713:tid 4713] [client 34.122.33.47:56734] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mobileonlinecasinos.co"] [uri "/.env"] [unique_id "altWkzeVkVQdRT-Zm-CYAwAAAAg"], referer: https://google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-17 12:06:58
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.122.33.47 (47.33.122.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.122.33.47 (47.33.122.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 17 08:06:53.715711 2026] [security2:error] [pid 807541:tid 807541] [client 34.122.33.47:49230] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "waleed.co"] [uri "/.env"] [unique_id "aloa3Vla5XYPyFteglc8swAAABE"], referer: https://google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-17 11:30:12
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.122.33.47 (47.33.122.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.122.33.47 (47.33.122.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 17 07:30:05.005109 2026] [security2:error] [pid 724251:tid 724251] [client 34.122.33.47:58351] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "epetsure.co"] [uri "/.env"] [unique_id "aloSPajplnRFSWVW6SYOSgAAABc"], referer: https://google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-17 11:05:13
(2 days ago)
34.122.33.47 - - [17/Jul/2026:19:05:13 +0800] "GET /.env HTTP/1.1" 301 236 "-" "Mozilla/5.0 (Windows ...
show more
34.122.33.47 - - [17/Jul/2026:19:05:13 +0800] "GET /.env HTTP/1.1" 301 236 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3626 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-17 10:35:21
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.122.33.47 (47.33.122.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.122.33.47 (47.33.122.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 17 06:35:14.825390 2026] [security2:error] [pid 895879:tid 895892] [client 34.122.33.47:57634] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "maxpowered.jp"] [uri "/.env"] [unique_id "aloFYnn4zXXy2_DpB7tS0wAAAMM"], referer: https://google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
2000cn.com.au
2026-07-17 09:43:20
(2 days ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-07-17 08:45:39
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.122.33.47 (47.33.122.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.122.33.47 (47.33.122.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 17 04:45:31.905322 2026] [security2:error] [pid 15561:tid 15561] [client 34.122.33.47:58288] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "gabrielapostres.co"] [uri "/.env"] [unique_id "alnrq0IZcc1Ne29ik4aclwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-07-13 22:05:12
(6 days ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-07-12.
show less
Web App Attack
SSH
Hacking