π±π»
garmtech.com
2026-09-01 11:04:39
(1 day ago)
Attempted access to sensitive endpoint (/.env.local) detected. Automated scan or unauthorized probin ...
show more
Attempted access to sensitive endpoint (/.env.local) detected. Automated scan or unauthorized probing.
show less
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-01 10:52:17
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.143.177.163 (163.177.143.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.143.177.163 (163.177.143.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 06:52:10.429447 2026] [security2:error] [pid 14036:tid 14036] [client 34.143.177.163:51628] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "penninesolutions.com"] [uri "/.env.backup"] [unique_id "apauWiHNrt-QRHMCtSZ0jQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-01 10:29:46
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.143.177.163 (163.177.143.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.143.177.163 (163.177.143.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 06:29:39.292116 2026] [security2:error] [pid 19424:tid 19424] [client 34.143.177.163:40380] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "adona.info"] [uri "/.env.production"] [unique_id "apapE5cg8HCmlHZe68-6pQAAAB8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π¨π
zynex
2026-09-01 10:01:17
(1 day ago)
URL Probing: /wp-config.php.bak
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-01 09:35:49
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.143.177.163 (163.177.143.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.143.177.163 (163.177.143.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 05:35:45.327374 2026] [security2:error] [pid 30273:tid 30273] [client 34.143.177.163:46512] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "smartstylehair.com"] [uri "/.env.bak"] [unique_id "apaccYNUU--6FIMW-pj8uwAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π¨π
leo1305
2026-09-01 08:47:12
(1 day ago)
CrowdSec detection | scenario: http-probing
Port Scan
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-01 08:45:28
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.143.177.163 (163.177.143.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.143.177.163 (163.177.143.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 04:45:20.367184 2026] [security2:error] [pid 12396:tid 12396] [client 34.143.177.163:52738] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sendera.mx"] [uri "/.env.save"] [unique_id "apaQoCQ9jOwgUyz0eMr7TwAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π·π΄
iulianh
2026-09-01 08:35:38
(1 day ago)
80,443
Brute-Force
SSH
πΊπΈ
TPI-Abuse
2026-09-01 07:45:12
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.143.177.163 (163.177.143.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.143.177.163 (163.177.143.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 03:45:08.216536 2026] [security2:error] [pid 19275:tid 19275] [client 34.143.177.163:57454] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "furnaceinthehayloft.horsesaw.com"] [uri "/.env.bak"] [unique_id "apaChCpdrsPaYYrRGzUL3gAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
e.fierstra
2026-09-01 06:59:19
(1 day ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
π©πͺ
webanyone
2026-09-01 06:32:46
(1 day ago)
WAF repeated trigger detected by Fail2Ban in plesk-modsecurity jail
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-01 06:23:31
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.143.177.163 (163.177.143.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.143.177.163 (163.177.143.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 02:23:27.001963 2026] [security2:error] [pid 12873:tid 12873] [client 34.143.177.163:47778] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.abecasis.com"] [uri "/.env.production"] [unique_id "apZvX1ZDGH4Z7PBcgIVUewAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π―π΅
beon
2026-09-01 06:22:33
(1 day ago)
[DateTime=>2026-09-01T06:22:33Z (UTC)] , [HoneyPot_Hits=>19 times] , [HoneyPots=>/wp-config.php.bak, ...
show more
[DateTime=>2026-09-01T06:22:33Z (UTC)] , [HoneyPot_Hits=>19 times] , [HoneyPots=>/wp-config.php.bak, /actuator/configprops, /env, /actuator/env, /.env.backup, /.env.prod and others] , [total_Hits=>19 times] , [Keyword=>WordPress, Laravel]
show less
Bad Web Bot
Web App Attack
Hacking
πΊπΈ
TPI-Abuse
2026-09-01 06:04:06
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.143.177.163 (163.177.143.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.143.177.163 (163.177.143.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 02:03:58.314861 2026] [security2:error] [pid 31179:tid 31179] [client 34.143.177.163:53476] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.gacstoday.com"] [uri "/.env.dev"] [unique_id "apZqzo0VWUMM5s269c8pnAAAACM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πͺπΈ
masterguru
2026-09-01 06:00:28
(1 day ago)
Inbound Anomaly Score Exceeded (Total Score: 10). Operator GE matched 5 at TX:anomaly_score. (949110 ...
show more
Inbound Anomaly Score Exceeded (Total Score: 10). Operator GE matched 5 at TX:anomaly_score. (949110-122)
show less
Hacking