๐ธ๐ช
vaia.cloud
2026-08-01 15:05:04
(40 seconds ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-08-01 14:59:39
(6 minutes ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐บ๐ธ
Matthew Ping
2026-08-01 14:30:03
(35 minutes ago)
ModSecurity rule 949110 triggered on dedicated4785. Web application attack blocked by CSF/LFD.
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-08-01 14:26:01
(39 minutes ago)
(mod_security) mod_security (id:210492) triggered by 34.154.55.226 (226.55.154.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.154.55.226 (226.55.154.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 10:25:56.205581 2026] [security2:error] [pid 719825:tid 719825] [client 34.154.55.226:44310] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "book-runningonempty.com"] [uri "/.env.bak"] [unique_id "am4B9ObgXHyIAmGfDFM9tAAAAC8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-01 14:20:39
(45 minutes ago)
Apache brute-force
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-08-01 14:07:17
(58 minutes ago)
(mod_security) mod_security (id:210492) triggered by 34.154.55.226 (226.55.154.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.154.55.226 (226.55.154.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 10:07:10.578621 2026] [security2:error] [pid 2749475:tid 2749475] [client 34.154.55.226:38356] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.montymilburn.com"] [uri "/.env.bak"] [unique_id "am39jrMm7lQJftEd4vVxSAAAACY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
0xffffffff
2026-08-01 14:01:17
(1 hour ago)
[2026-08-01 17:01:15.785433] [authz_core:error] [pid 203677:tid 136847237830336] [client 34.154.55.2 ...
show more
[2026-08-01 17:01:15.785433] [authz_core:error] [pid 203677:tid 136847237830336] [client 34.154.55.226:50314] AH01630: client denied by server configuration: /var/www/*/.env.production , error_notes:wrong-host , URI:'/.env.production'
[2026-08-01 17:01:15.787774] [authz_core:error] [pid 203674:tid 136847221044928] [client 34.154.55.226:50324] AH01630: client denied by server configuration: /var/www/*/.env.dev , error_notes:wrong-host , URI:'/.env.dev'
[2026-08-01 17:01:15.793907] [authz_core:error] [pid 203674:tid 136847229437632] [client 34.154.55.226:50330] AH01630: client denied by server configuration: /var/www/*/.env.local , error_notes:wrong-host , URI:'/.env.local'
[2026-08-01 17:01:15.794016] [authz_core:error] [pid 203674:tid 136847336912576] [client 34.154.55.226:50332] AH01630: client denied by server configuration: /var/www/*/.env.old , error_notes:backup-files , URI:'/.env.old'
[2026-08-01 17:01:15.794558] [authz_core:error] [pid 203674:tid 136847237830336] [client 34.154.55.226:50334] AH01630: c
show less
Web App Attack
Bad Web Bot
Anonymous
2026-08-01 13:37:04
(1 hour ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
๐ฆ๐บ
2000cn.com.au
2026-08-01 13:30:31
(1 hour ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐ฉ๐ช
webanyone
2026-08-01 13:16:00
(1 hour ago)
WAF repeated trigger detected by Fail2Ban in plesk-modsecurity jail
Web App Attack
Anonymous
2026-08-01 13:01:44
(2 hours ago)
34.154.55.226 - - [01/Aug/2026:15:01:44 +0200] "GET /.env.bak HTTP/1.1" 403 442 "-" "crusader-worker ...
show more
34.154.55.226 - - [01/Aug/2026:15:01:44 +0200] "GET /.env.bak HTTP/1.1" 403 442 "-" "crusader-worker/1.0"
34.154.55.226 - - [01/Aug/2026:15:01:44 +0200] "GET /.env.bak HTTP/1.1" 403 281 "-" "crusader-worker/1.0"
34.154.55.226 - - [01/Aug/2026:15:01:44 +0200] "GET /.env.prod HTTP/1.1" 403 442 "-" "crusader-worker/1.0"
34.154.55.226 - - [01/Aug/2026:15:01:44 +0200] "GET /.env.prod HTTP/1.1" 403 281 "-" "crusader-worker/1.0"
34.154.55.226 - - [01/Aug/2026:15:01:44 +0200] "GET /.env.local HTTP/1.1" 403 442 "-" "crusader-worker/1.0"
34.154.55.226 - - [01/Aug/2026:15:01:44 +0200] "GET /.env.local HTTP/1.1" 403 281 "-" "crusader-worker/1.0"
34.154.55.226 - - [01/Aug/2026:15:01:44 +0200] "GET /.env.production HTTP/1.1" 403 442 "-" "crusader-worker/1.0"
34.154.55.226 - - [01/Aug/2026:15:01:44 +0200] "GET /.env.production HTTP/1.1" 403 281 "-" "crusader-worker/1.0"
34.154.55.226 - - [01/Aug/2026:15:01:44 +0200] "GET /.env.backup HTTP/1.1" 403 442 "-" "crusader-worker/1.0"
34.154.55.226 - - [01/A
...
show less
Bad Web Bot
Web App Attack
Anonymous
2026-08-01 12:59:52
(2 hours ago)
path attack /.env
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-01 12:46:20
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.154.55.226 (226.55.154.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.154.55.226 (226.55.154.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 08:46:16.034996 2026] [security2:error] [pid 14232:tid 14232] [client 34.154.55.226:52364] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.fairfieldfarms.net"] [uri "/.env.example"] [unique_id "am3qmKKfPou3vJ3aaYzJ7gAAADE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
consul.to
2026-08-01 12:38:16
(2 hours ago)
Web attack/malicious scanning detected
Web App Attack
๐ซ๐ท
dynamix
2026-08-01 12:23:00
(2 hours ago)
Multiple WAF Violations
Web App Attack