π³π±
homeshowdomain.nl
2026-09-01 22:00:12
(11 hours ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-08-31.
show less
Web App Attack
SSH
Hacking
πΊπΈ
TPI-Abuse
2026-09-01 13:49:58
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.147.73.246 (246.73.147.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.147.73.246 (246.73.147.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 09:49:52.767333 2026] [security2:error] [pid 24836:tid 24836] [client 34.147.73.246:52782] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.flowergirlbaskets.com"] [uri "/.env"] [unique_id "apbYAIqPrPu0lGEdKkO4UgAAAFU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
tentwentyfour
2026-09-01 13:10:09
(20 hours ago)
Blocked for probing for sensitive web application components
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-01 13:02:42
(20 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.147.73.246 (246.73.147.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.147.73.246 (246.73.147.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 09:02:36.635436 2026] [security2:error] [pid 15357:tid 15357] [client 34.147.73.246:45182] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "pinetreedistrict.org"] [uri "/.env.production"] [unique_id "apbM7N321dMMcM_wSvWrrwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
big-cloud.nl
2026-09-01 12:02:50
(21 hours ago)
Try to access /.env
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-01 11:01:39
(22 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.147.73.246 (246.73.147.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.147.73.246 (246.73.147.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 07:01:31.389572 2026] [security2:error] [pid 30501:tid 30501] [client 34.147.73.246:56726] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.aquanauticsige.com"] [uri "/.env.backup"] [unique_id "apawi7PHEir0-9psSZpgiQAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
4server
2026-09-01 10:28:15
(23 hours ago)
[TueSep0112:28:10.5386212026][security2:error][pid4029682:tid4029696][client34.147.73.246:0]ModSecur ...
show more
[TueSep0112:28:10.5386212026][security2:error][pid4029682:tid4029696][client34.147.73.246:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:5\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.10\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"acquaallaspina.ch\"][uri\"/.env.prod\"][unique_id\"apaoul2hVoUQe8gAbKuLtAAAAAM\"]
show less
Port Scan
Brute-Force
Web App Attack
π³π΄
jad-abuse
2026-09-01 10:21:22
(23 hours ago)
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: env_probe ...
show more
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: env_probe, source_backup, scanner_ua, actuator, ignition_debug, config_backup. Observed by 1 sensor(s); 52 hits.
show less
Hacking
Web App Attack
π¬π§
consul.to
2026-09-01 10:01:45
(23 hours ago)
Web attack/malicious scanning detected
Web App Attack
π¦πΊ
A.i.D.A.N.N
2026-09-01 10:01:34
(23 hours ago)
A.i.D.A.N.N: Anomaly Detected - Signature match Web Service - Web application attack detected
Web App Attack
π³π±
e.fierstra
2026-09-01 09:34:31
(23 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
π©πͺ
kkw
2026-09-01 09:30:02
(23 hours ago)
[REDACTED] 34.147.73.246 - - [01/Sep/2026:11:30:01 +0200] "GET /.env.example HTTP/1.1" 301 4697 "-" ...
show more
[REDACTED] 34.147.73.246 - - [01/Sep/2026:11:30:01 +0200] "GET /.env.example HTTP/1.1" 301 4697 "-" "crusader-worker/1.0"
... (mode: searching http-sensitive-files)
show less
Bad Web Bot
Web App Attack
π¨π¦
Sakusen
2026-09-01 09:21:27
(1 day ago)
Automated web attack: 19 reqs, 19 paths probed, 12 returned 404; probed: 10 .env, 5 other, 3 .php, 1 ...
show more
Automated web attack: 19 reqs, 19 paths probed, 12 returned 404; probed: 10 .env, 5 other, 3 .php, 1 log
show less
Hacking
Bad Web Bot
Web App Attack
πΈπͺ
vaia.cloud
2026-09-01 08:35:01
(1 day ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
π©πͺ
webanyone
2026-09-01 08:02:30
(1 day ago)
WAF repeated trigger detected by Fail2Ban in plesk-modsecurity jail
Web App Attack