๐ง๐ช
voormedia
2026-07-31 15:34:07
(29 minutes ago)
Accessed trap at '/.env'
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-31 14:24:29
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.126.119.157 (157.119.126.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.126.119.157 (157.119.126.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 31 10:24:21.673047 2026] [security2:error] [pid 360049:tid 360049] [client 34.126.119.157:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.wiszen.org"] [uri "/.env.bak"] [unique_id "amywFXi8cccxQKy97TVaGQAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-31 12:57:05
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.126.119.157 (157.119.126.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.126.119.157 (157.119.126.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 31 08:56:57.503933 2026] [security2:error] [pid 2928866:tid 2928911] [client 34.126.119.157:51594] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.yourwitch.com"] [uri "/backend/.env"] [unique_id "amybmTrx2P0l5YfbyYhtYwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
mediarama.com
2026-07-31 12:55:31
(3 hours ago)
Banned by Fail2Ban
Web App Attack
๐ณ๐ฑ
melroy89
2026-07-31 12:14:39
(3 hours ago)
34.126.119.157 - - [31/Jul/2026:14:13:48 +0200] "GET /secrets/aws.json HTTP/1.1" 403 9 "-" "meta-ex ...
show more
34.126.119.157 - - [31/Jul/2026:14:13:48 +0200] "GET /secrets/aws.json HTTP/1.1" 403 9 "-" "meta-externalagent/1.1 (+https://developers.facebook.com/docs/sharing/webmasters/crawler)" "find.melroy.org" 0.000
34.126.119.157 - - [31/Jul/2026:14:13:48 +0200] "GET /application.yml HTTP/1.1" 403 9 "-" "Mozilla/5.0 (compatible; DeepSeekBot/1.0; +https://www.deepseek.com/bot)" "find.melroy.org" 0.000
34.126.119.157 - - [31/Jul/2026:14:13:48 +0200] "GET /wp-config.php.save HTTP/1.1" 403 9 "-" "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" "find.melroy.org" 0.000
34.126.119.157 - - [31/Jul/2026:14:13:48 +0200] "GET /service-account-key.json HTTP/1.1" 403 9 "-" "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" "find.melroy.org" 0.000
34.126.119.157 - - [31/Jul/2026:14:13:48 +0200] "GET /firebase-service-account.json HTTP/1.1" 403 9 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ChatGPT-User/1.0; +https://openai.com/bot)" "
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-31 12:12:12
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.126.119.157 (157.119.126.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.126.119.157 (157.119.126.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 31 08:12:06.315296 2026] [security2:error] [pid 24579:tid 24579] [client 34.126.119.157:29652] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.microbooty.com"] [uri "/.env"] [unique_id "amyRFjmQXE86m__mYxgM5gAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
ConsulHosting
2026-07-31 12:01:22
(4 hours ago)
Automatically blocked due to distributed attack
Hacking
๐ฉ๐ช
ghostwarriors
2026-07-31 11:50:30
(4 hours ago)
Webpage scraping
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
Aetherweb Ark
2026-07-31 11:28:29
(4 hours ago)
(mod_security) mod_security (id:949110) triggered by 34.126.119.157 (SG/Singapore/157.119.126.34.bc. ...
show more
(mod_security) mod_security (id:949110) triggered by 34.126.119.157 (SG/Singapore/157.119.126.34.bc.googleusercontent.com): N in the last X secs
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-31 10:29:00
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.126.119.157 (157.119.126.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.126.119.157 (157.119.126.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 31 06:28:51.302506 2026] [security2:error] [pid 3079713:tid 3079713] [client 34.126.119.157:2218] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.venture2-22.org"] [uri "/.env.development"] [unique_id "amx44zmnJwnHCdtiyrancgAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
alferez
2026-07-31 09:31:25
(6 hours ago)
Searching .(env|sql|zip|tar|rar) files
Hacking
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-31 08:12:20
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.126.119.157 (157.119.126.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.126.119.157 (157.119.126.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 31 04:12:13.714052 2026] [security2:error] [pid 2675630:tid 2675630] [client 34.126.119.157:7414] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.wholesaleglassjars.com"] [uri "/.env.local"] [unique_id "amxY3Yv42foMsEB6IoLA9QAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
taivas.nl
2026-07-31 08:02:12
(8 hours ago)
Bad_requests
Bad Web Bot
Anonymous
2026-07-31 07:39:27
(8 hours ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-31 07:21:14
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.126.119.157 (157.119.126.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.126.119.157 (157.119.126.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 31 03:21:08.760607 2026] [security2:error] [pid 3365396:tid 3365396] [client 34.126.119.157:56542] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "fishleadership.org"] [uri "/.env.local"] [unique_id "amxM5HFiNLo4EBUwMUl94wAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack