🇮🇪
AutosOnShow
2026-09-05 07:10:07
(5 hours ago)
blocked for webapp attack | path requested: / | seen at 2026-09-05 07:09:33.005 |
Web App Attack
🇧🇾
lns.bz
2026-09-05 06:56:49
(5 hours ago)
Too many 404 requests [BY]
Web App Attack
Anonymous
2026-09-05 06:47:12
(5 hours ago)
Bot / seems abusive / Apache connections: 24
DDoS Attack
Web Spam
Bad Web Bot
Web App Attack
🇹🇷
Threat.live
2026-09-05 06:45:03
(5 hours ago)
Threat.live: Web Scan
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 15:22:21
(20 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.135.31.75 (75.31.135.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.135.31.75 (75.31.135.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 11:22:14.585014 2026] [security2:error] [pid 19999:tid 19999] [client 34.135.31.75:46160] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.sponsorzilla.com"] [uri "/.env.dev"] [unique_id "apriJl1C4UBo1vWP1JFGTQAAAEI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 14:18:13
(22 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.135.31.75 (75.31.135.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.135.31.75 (75.31.135.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 10:18:05.880174 2026] [security2:error] [pid 12124:tid 12124] [client 34.135.31.75:53538] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.slpawb.com"] [uri "/.env.dev"] [unique_id "aprTHTOBdw6rMHXAHVCw_wAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
kosada.com
2026-09-04 13:53:01
(22 hours ago)
Repeated requests for suspicious nonexistent URLs, for example: /.env.local (HTTP/1.1 port 443, user ...
show more
Repeated requests for suspicious nonexistent URLs, for example: /.env.local (HTTP/1.1 port 443, user agent: "crusader-worker/1.0")
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 13:45:57
(22 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.135.31.75 (75.31.135.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.135.31.75 (75.31.135.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 09:45:49.453183 2026] [security2:error] [pid 26473:tid 26491] [client 34.135.31.75:38468] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "aceelectricalsupplies.com"] [uri "/.env"] [unique_id "aprLjSXXwczvxj3cIwPXDgAAAEk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇮🇹
zenmorro
2026-09-04 13:43:45
(22 hours ago)
Honeypot hit (wordpress:8080) — scanner-path: /.env.local. Automated report from honeypot infrastruc ...
show more
Honeypot hit (wordpress:8080) — scanner-path: /.env.local. Automated report from honeypot infrastructure
show less
Port Scan
Web App Attack
🇧🇪
sid3windr
2026-09-04 13:35:13
(22 hours ago)
GET /.env (Tarpitted for 4m20s, wasted 15.35kB)
Web App Attack
Anonymous
2026-09-04 13:05:02
(23 hours ago)
suspicious request in access.log
Web App Attack
🇩🇪
FeG Deutschland
2026-09-04 12:19:44
(1 day ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 12:03:22
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.135.31.75 (75.31.135.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.135.31.75 (75.31.135.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 08:03:17.607796 2026] [security2:error] [pid 1420:tid 1420] [client 34.135.31.75:34942] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "tlphotogifts.com.iyp-home.com"] [uri "/.env.example"] [unique_id "apqzheEW3k4ED58q2cFXTwAAACE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 10:58:10
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.135.31.75 (75.31.135.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.135.31.75 (75.31.135.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 06:58:06.904519 2026] [security2:error] [pid 12125:tid 12125] [client 34.135.31.75:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "blog.nyemdr.com"] [uri "/.env.old"] [unique_id "apqkPoXDYPCb5icoJQDbSQAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 10:23:38
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.135.31.75 (75.31.135.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.135.31.75 (75.31.135.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 06:23:32.859124 2026] [security2:error] [pid 2851062:tid 2851405] [client 34.135.31.75:53334] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "nopictures.org"] [uri "/wp-config.php.swp"] [unique_id "apqcJMB6z_qmuejzZ9-HNAAAAUg"]
show less
Brute-Force
Bad Web Bot
Web App Attack