๐บ๐ธ
TPI-Abuse
2026-08-01 17:27:17
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.151.75.223 (223.75.151.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.151.75.223 (223.75.151.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 13:27:11.068735 2026] [security2:error] [pid 2546908:tid 2546908] [client 34.151.75.223:44078] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "gaksato.com"] [uri "/.env.local"] [unique_id "am4sb3SPpu7EXV270SXCyAAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob
2026-08-01 17:17:10
(16 hours ago)
CrowdSec: crowdsecurity/http-sensitive-files | req: /.env.backup | 5 distinct paths | UA: crusader-w ...
show more
CrowdSec: crowdsecurity/http-sensitive-files | req: /.env.backup | 5 distinct paths | UA: crusader-worker/1.0
show less
Hacking
๐ฉ๐ช
seal
2026-08-01 17:13:11
(16 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
SSH
Brute-Force
๐ง๐ช
voormedia
2026-08-01 17:03:51
(16 hours ago)
Accessed trap at '/.env'
Web App Attack
Anonymous
2026-08-01 17:02:09
(16 hours ago)
Web application attack detected.
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-01 16:40:48
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.151.75.223 (223.75.151.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.151.75.223 (223.75.151.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 12:40:39.816742 2026] [security2:error] [pid 1002186:tid 1002186] [client 34.151.75.223:37710] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "estudio-altamirano.com"] [uri "/.env.prod"] [unique_id "am4hh08ZdcRvhfWpO4BNdwAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
COMAITE
2026-08-01 15:12:18
(18 hours ago)
Suspicious URL access.
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-01 15:10:46
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.151.75.223 (223.75.151.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.151.75.223 (223.75.151.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 11:10:42.240588 2026] [security2:error] [pid 1826395:tid 1826395] [client 34.151.75.223:47510] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.pushthemarketing.com"] [uri "/.env.dev"] [unique_id "am4McsV-Thcv6gILr5_rBwAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-01 15:10:02
(18 hours ago)
suspicious request in access.log
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-08-01 15:02:43
(18 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐ฟ๐ฆ
conure
2026-08-01 14:54:01
(19 hours ago)
csagent: score 20.5: 404 noise floor x2, secrets grab x2; 1 domain(s) in 0s
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-01 13:43:25
(20 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.151.75.223 (223.75.151.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.151.75.223 (223.75.151.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 09:43:21.874751 2026] [security2:error] [pid 1708404:tid 1708404] [client 34.151.75.223:33786] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.astglobaltech.com"] [uri "/.env.old"] [unique_id "am33-diL2gBFVJSjPf5XcgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
DEV-DNS
2026-08-01 13:43:11
(20 hours ago)
(mod_security) mod_security triggered on hostname [redacted])
SQL Injection
๐บ๐ธ
TPI-Abuse
2026-08-01 13:07:33
(20 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.151.75.223 (223.75.151.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.151.75.223 (223.75.151.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 09:07:26.329544 2026] [security2:error] [pid 1948013:tid 1948013] [client 34.151.75.223:37642] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ironheadsofseo.powerlinemultimedia.net"] [uri "/.env.dev"] [unique_id "am3vjpr_3DcFHJdHV4snCgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-08-01 12:40:01
(21 hours ago)
Multiple unauthorized connection attempts
Web App Attack