๐ง๐ช
cmbplf
2026-05-01 12:36:18
(4 months ago)
155 requests with url.path *.env
Brute-Force
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-05-01 10:00:24
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 34.139.49.255 (255.49.139.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.139.49.255 (255.49.139.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 01 05:59:56.569337 2026] [security2:error] [pid 30831:tid 30831] [client 34.139.49.255:47652] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jaragoodrich.com"] [uri "/.env.local"] [unique_id "afR5nGCgJh5xwnNYaC_sbwAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-05-01 09:53:55
(4 months ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-01 06:43:33
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 34.139.49.255 (255.49.139.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.139.49.255 (255.49.139.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 01 02:43:26.841249 2026] [security2:error] [pid 7140:tid 7140] [client 34.139.49.255:50928] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.bayarealangarts.com"] [uri "/.env"] [unique_id "afRLjnmWPhwDj3ahZs2OigAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
Inartis
2026-05-01 06:42:18
(4 months ago)
34.139.49.255 - - [01/May/2026:08:42:17 +0200] "GET /admin/.env HTTP/1.1" 403 4090 "-" "Mozilla/5.0 ...
show more
34.139.49.255 - - [01/May/2026:08:42:17 +0200] "GET /admin/.env HTTP/1.1" 403 4090 "-" "Mozilla/5.0 (X11; NetBSD amd64; rv:30.0) Gecko/20100101 Firefox/30.0"
34.139.49.255 - - [01/May/2026:08:42:17 +0200] "GET /.env.local HTTP/1.1" 403 4090 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_6_8) AppleWebKit/535.7 (KHTML, like Gecko) Chrome/16.0.912.36 Safari/535.7"
34.139.49.255 - - [01/May/2026:08:42:17 +0200] "GET /.env HTTP/1.1" 403 4090 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 12_1_4 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Mobile/16D57"
...
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-30 16:25:08
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 34.139.49.255 (255.49.139.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.139.49.255 (255.49.139.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Apr 30 12:25:02.255483 2026] [security2:error] [pid 22568:tid 22568] [client 34.139.49.255:55690] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "4photogifts.com"] [uri "/.env"] [unique_id "afOCXlCs9kb79Smft2ysiwAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
4server
2026-04-30 15:18:44
(5 months ago)
[ThuApr3017:18:38.2477982026][security2:error][pid3048125:tid3049271][client34.139.49.255:0]ModSecur ...
show more
[ThuApr3017:18:38.2477982026][security2:error][pid3048125:tid3049271][client34.139.49.255:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\".env\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"364\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"carolin-mizio.ch\"][uri\"/admin/.env\"][unique_id\"afNyzkQ-AJVD7iy36pwcLwAAAQo\"]
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-30 15:18:01
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 34.139.49.255 (255.49.139.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.139.49.255 (255.49.139.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Apr 30 11:17:53.292021 2026] [security2:error] [pid 15517:tid 15517] [client 34.139.49.255:45180] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "azcrittergetter.com"] [uri "/api/.env"] [unique_id "afNyoQg3ZXPlbkwQMlkawQAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
masterguru
2026-04-30 15:16:49
(5 months ago)
. Matched phrase "/.env" at REQUEST_URI. (210492-123)
Web App Attack
๐บ๐ธ
mnsf
2026-04-30 15:05:17
(5 months ago)
Scanning/Probing (20)
Brute-Force
Web App Attack
๐ซ๐ท
fenogent.com
2026-04-30 14:40:02
(5 months ago)
CrowdSec: crowdsecurity/recidive (1 events)
Web App Attack
Anonymous
2026-04-30 14:39:49
(5 months ago)
Web App Attack
Brute-Force
Exploited Host
Web App Attack
๐ฉ๐ช
Ba-Yu
2026-04-30 14:38:36
(5 months ago)
General hacking/exploits/scanning
Web Spam
Hacking
Brute-Force
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-30 14:37:52
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 34.139.49.255 (255.49.139.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.139.49.255 (255.49.139.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Apr 30 10:37:47.144764 2026] [security2:error] [pid 14447:tid 14447] [client 34.139.49.255:57178] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "brupharm.eu"] [uri "/.env"] [unique_id "afNpO55xhu11tD9vh9piYAAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-04-30 14:30:02
(5 months ago)
suspicious request in access.log
Web App Attack