๐บ๐ธ
TPI-Abuse
2026-08-29 02:51:54
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.139.219.210 (210.219.139.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.139.219.210 (210.219.139.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 22:51:49.001127 2026] [security2:error] [pid 166148:tid 166206] [client 34.139.219.210:38850] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.bacalodgecom.sloveniaflyfishing.com"] [uri "/.env.old"] [unique_id "apJJRcfpcEjKeocP2SxB9QAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-08-29 02:30:50
(9 hours ago)
Restricted File Access Attempt. Matched phrase ".env" at REQUEST_FILENAME. (930130-201)
Hacking
Web App Attack
๐บ๐ธ
MatCat
2026-08-29 02:05:13
(9 hours ago)
Banned by fail2ban: apache-webprobe
Port Scan
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-08-29 01:11:29
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.139.219.210 (210.219.139.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.139.219.210 (210.219.139.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 21:11:23.086905 2026] [security2:error] [pid 16435:tid 16435] [client 34.139.219.210:50138] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.prettygirlstuff.grayhost.net"] [uri "/.env.local"] [unique_id "apIxu-xv-J23TJcy2wmNMAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Marc
2026-08-29 01:04:11
(10 hours ago)
34.139.219.210 - - [29/Aug/2026:03:04:11 +0200] "GET /.env.prod HTTP/1.1" 404 4616 "-" "crusader-wor ...
show more
34.139.219.210 - - [29/Aug/2026:03:04:11 +0200] "GET /.env.prod HTTP/1.1" 404 4616 "-" "crusader-worker/1.0" 34.139.219.210 - - [29/Aug/2026:03:04:11 +0200] "GET /.env.local HTTP/1.1" 404 4616 "-" "crusader-worker/1.0" 34.139.219.210 - - [29/Aug/2026:03:04:11 +0200] "GET /wp-config.php~ HTTP/1.1" 404 4616 "-" "crusader-worker/1.0"
show less
Brute-Force
๐ฉ๐ช
Philister11
2026-08-29 00:21:08
(11 hours ago)
CrowdSec: crowdsecurity/http-probing (US/AS396982)
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-08-29 00:06:48
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.139.219.210 (210.219.139.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.139.219.210 (210.219.139.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 20:06:39.353397 2026] [security2:error] [pid 882:tid 882] [client 34.139.219.210:40268] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "carmichaellaw.org"] [uri "/.env.old"] [unique_id "apIij9St1hfcHDNwoaN3rgAAAC8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
4server
2026-08-28 23:57:12
(12 hours ago)
[SatAug2901:57:06.5002592026][security2:error][pid3337144:tid3337176][client34.139.219.210:0]ModSecu ...
show more
[SatAug2901:57:06.5002592026][security2:error][pid3337144:tid3337176][client34.139.219.210:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Patternmatch\"\(\?i\)\(\?:/\(\?:\^\|/\)\\\\\\\\.\(env\|git\|svn\|hg\|DS_Store\)\|/\(\?:wp-config\|\\\\\\\\.htaccess\|\\\\\\\\.htpasswd\)\|\\\\\\\\.\(\?:sql\|bak\|old\|log\)\$\)\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"156\"][id\"960720\"][msg\"Forbiddenfileaccessattempt\"][severity\"CRITICAL\"][hostname\"webdisk.buletti-panettoni.ch\"][uri\"/.env.bak\"][unique_id\"apIgUvAsjGmzy5AmfBu2HAAAABU\"]
show less
Port Scan
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 23:42:13
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.139.219.210 (210.219.139.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.139.219.210 (210.219.139.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 19:42:08.199183 2026] [security2:error] [pid 8097:tid 8097] [client 34.139.219.210:47136] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mobresearchinc.markthwaite.com"] [uri "/.env"] [unique_id "apIc0LJy7VWg2aTdMvZu1AAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ฐ
ScamAware
2026-08-28 23:35:42
(12 hours ago)
Detected by Cloudflare Security Events via WordPress automation. Detection: sensitive_files (Sensiti ...
show more
Detected by Cloudflare Security Events via WordPress automation. Detection: sensitive_files (Sensitive files, source control, config, and backups). Hits from same IP in last 60 minutes: 20. Unique request paths counted internally: 20. Cloudflare action: block. Cloudflare source: firewallCustom.
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 23:09:44
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.139.219.210 (210.219.139.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.139.219.210 (210.219.139.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 19:09:39.389947 2026] [security2:error] [pid 20267:tid 20267] [client 34.139.219.210:34420] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "grantjennings.com"] [uri "/wp-config.php.swp"] [unique_id "apIVM1df9l1jtb978v0tFwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-28 20:45:55
(15 hours ago)
apache vulnerability scan
Web App Attack
Anonymous
2026-08-28 20:12:05
(15 hours ago)
(mod_security) mod_security triggered on hostname [redacted])
SQL Injection
๐ธ๐ช
vaia.cloud
2026-08-28 19:10:03
(16 hours ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
๐ท๐ด
iulianh
2026-08-28 18:39:43
(17 hours ago)
80,443
Brute-Force
SSH