🇮🇩
bps-statistics
2026-09-05 08:59:28
(2 hours ago)
Web Application Attacks
Web App Attack
🇩🇪
raph
2026-09-04 15:02:07
(20 hours ago)
[DOT FILES] crawler *.env*, .git*, .config*, etc.
Bad Web Bot
Web App Attack
Anonymous
2026-09-04 14:59:04
(20 hours ago)
Bot / scanning and/or hacking attempts: GET /actuator/configprops HTTP/1.1, GET /.env.dev HTTP/1.1, ...
show more
Bot / scanning and/or hacking attempts: GET /actuator/configprops HTTP/1.1, GET /.env.dev HTTP/1.1, GET /.env.production HTTP/1.1, GET /.env.old HTTP/1.1, GET /crusader-404-probe HTTP/1.1, GET /actuator/env HTTP/1.1
show less
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 14:45:42
(20 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.151.194.182 (182.194.151.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.151.194.182 (182.194.151.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 10:45:38.716270 2026] [security2:error] [pid 7543:tid 7543] [client 34.151.194.182:34472] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "chefmarcelcooks.com"] [uri "/.env"] [unique_id "aprZkvUwJ2Hsx5ZWiRjJNwAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 14:08:23
(21 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.151.194.182 (182.194.151.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.151.194.182 (182.194.151.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 10:08:17.143483 2026] [security2:error] [pid 8296:tid 8310] [client 34.151.194.182:48236] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.104ventures.com"] [uri "/.env.save"] [unique_id "aprQ0ahTWN4V_haVdZmJUwAAAEg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
n2nguyenn2nguyen
2026-09-04 13:45:38
(21 hours ago)
Blocked by YFC Security on https://1904.brixzly.com — type: directory_scan_attempts
Web App Attack
🇳🇱
debestelapp
2026-09-04 12:55:12
(22 hours ago)
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 12:35:52
(22 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.151.194.182 (182.194.151.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.151.194.182 (182.194.151.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 08:35:45.392016 2026] [security2:error] [pid 18478:tid 18478] [client 34.151.194.182:49610] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "globalmappinginc.com"] [uri "/.env.prod"] [unique_id "apq7ITrFYYVY9-CD32CJRQAAAD4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
WeCloudit-Anti-Abuse
2026-09-04 10:31:54
(1 day ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-04 10:23:10
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.151.194.182 (182.194.151.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.151.194.182 (182.194.151.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 06:23:04.869770 2026] [security2:error] [pid 12906:tid 12906] [client 34.151.194.182:45516] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "nube.vientodelevante.es"] [uri "/.env.backup"] [unique_id "apqcCIoMjgAxe8CZ1o09ZwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 08:44:11
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.151.194.182 (182.194.151.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.151.194.182 (182.194.151.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 04:44:07.424941 2026] [security2:error] [pid 10984:tid 10984] [client 34.151.194.182:55498] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "reiki.proyectando.com"] [uri "/.env.production"] [unique_id "apqE1x8eldM6qbSh3roXOgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 08:24:52
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.151.194.182 (182.194.151.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.151.194.182 (182.194.151.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 04:24:45.771016 2026] [security2:error] [pid 907:tid 907] [client 34.151.194.182:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.empoweruamerica.org"] [uri "/.env.backup"] [unique_id "apqATfo9ctMNaYmpYIq_ogAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
FD-IX
2026-09-04 08:16:55
(1 day ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 07:48:42
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.151.194.182 (182.194.151.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.151.194.182 (182.194.151.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 03:48:37.957112 2026] [security2:error] [pid 26847:tid 26847] [client 34.151.194.182:34692] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "futuresgrowhere.com"] [uri "/.env"] [unique_id "app31cRVR-HjDEq3qZpUMAAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇮🇹
clamehost.it
2026-09-04 07:44:07
(1 day ago)
Automatic report - Brute Force attack using this IP address
Brute-Force