🇫🇷
SpaceHost-Server
2026-09-04 22:19:41
(15 hours ago)
Brute-Force
Web App Attack
🇺🇸
mnsf
2026-09-04 16:05:26
(21 hours ago)
Scanning/Probing (20)
Brute-Force
Web App Attack
Anonymous
2026-09-04 15:18:52
(22 hours ago)
[server.tmg.gr] httpd-config-scan: sites=www.crisis-management2018.eu; logs=/var/log/httpd/domains/c ...
show more
[server.tmg.gr] httpd-config-scan: sites=www.crisis-management2018.eu; logs=/var/log/httpd/domains/crisis-management2018.eu.log; samples=/.env.backup | /.env.bak | /.env.old
show less
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 15:16:55
(22 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.152.42.215 (215.42.152.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.152.42.215 (215.42.152.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 11:16:48.501145 2026] [security2:error] [pid 28209:tid 28209] [client 34.152.42.215:51834] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.sympalais.com"] [uri "/wp-config.php.swp"] [unique_id "aprg4E3Pt7qiE9F298OaLAAAADY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇨🇦
Anytech
2026-09-04 15:01:20
(23 hours ago)
Blocked by Conn-Monitor: env-probing
Web App Attack
Hacking
🇩🇪
tsZero
2026-09-04 14:15:19
(23 hours ago)
Scan example: path=/.env.dev status=404
Hacking
🇬🇧
Aetherweb Ark
2026-09-04 14:14:10
(23 hours ago)
(mod_security) mod_security (id:949110) triggered by 34.152.42.215 (CA/Canada/215.42.152.34.bc.googl ...
show more
(mod_security) mod_security (id:949110) triggered by 34.152.42.215 (CA/Canada/215.42.152.34.bc.googleusercontent.com): N in the last X secs
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 14:08:39
(23 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.152.42.215 (215.42.152.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.152.42.215 (215.42.152.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 10:08:34.758922 2026] [security2:error] [pid 12210:tid 12210] [client 34.152.42.215:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.plaiatech.com"] [uri "/.env.save"] [unique_id "aprQ4oVh8EaHKFCvEqRsTQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
macrob
2026-09-04 13:43:50
(1 day ago)
2026/09/04 13:43:48 [error] 754817#754817: *556007139 access forbidden by rule, client: 34.152.42.21 ...
show more
2026/09/04 13:43:48 [error] 754817#754817: *556007139 access forbidden by rule, client: 34.152.42.215, server: binixo.ro, request: "GET /.env.production HTTP/1.1", host: "admin.binixo.ro"
2026/09/04 13:43:48 [error] 754821#754821: *556007141 access forbidden by rule, client: 34.152.42.215, server: binixo.ro, request: "GET /.env.dev HTTP/1.1", host: "admin.binixo.ro"
2026/09/04 13:43:48 [error] 754817#754817: *556007140 access forbidden by rule, client: 34.152.42.215, server: binixo.ro, request: "GET /wp-config.php~ HTTP/1.1", host: "admin.binixo.ro"
...
show less
Web App Attack
🇳🇱
MM-bot
2026-09-04 13:35:35
(1 day ago)
URL-probe: HTTP/1.1 GET request on /env (2026-09-04 15:35:35 UTC+2)
Web App Attack
Hacking
🇫🇷
dynamix
2026-09-04 12:18:37
(1 day ago)
Multiple WAF Violations
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 12:18:05
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.152.42.215 (215.42.152.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.152.42.215 (215.42.152.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 08:17:59.852515 2026] [security2:error] [pid 31075:tid 31075] [client 34.152.42.215:56838] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "minietonrailroad.org"] [uri "/.env"] [unique_id "apq29w1LMPqF_6bj34g4ggAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 12:01:09
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.152.42.215 (215.42.152.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.152.42.215 (215.42.152.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 08:01:05.419507 2026] [security2:error] [pid 32674:tid 32674] [client 34.152.42.215:53828] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "tanandteh.com"] [uri "/.env.example"] [unique_id "apqzAZ1qXr6R2QVI8HHT9gAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 11:17:31
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.152.42.215 (215.42.152.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.152.42.215 (215.42.152.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 07:17:27.089321 2026] [security2:error] [pid 29598:tid 29598] [client 34.152.42.215:48672] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "eboredom.benlbrown.com"] [uri "/wp-config.php.swp"] [unique_id "apqox4Gj6f9624_0BxNQ4QAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 10:58:17
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.152.42.215 (215.42.152.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.152.42.215 (215.42.152.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 06:58:10.798578 2026] [security2:error] [pid 24424:tid 24424] [client 34.152.42.215:44336] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "blog.ptr.com.post-therapyreconditioning.com"] [uri "/.env.local"] [unique_id "apqkQqRt5nQdsMhYIzWsswAAACM"]
show less
Brute-Force
Bad Web Bot
Web App Attack