๐ง๐ช
cmbplf
2026-07-31 17:45:58
(14 hours ago)
489 requests with url.path *.env
Brute-Force
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-07-31 17:33:53
(14 hours ago)
(mod_security) mod_security (id:949110) triggered by 34.159.204.144 (144.204.159.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:949110) triggered by 34.159.204.144 (144.204.159.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 31 13:33:46.212488 2026] [security2:error] [pid 830874:tid 830874] [client 34.159.204.144:35624] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "www.tgto.cescfoundation.org"] [uri "/.env"] [unique_id "amzcemh3Bkiz62mM7exf5AAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-31 16:56:25
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.159.204.144 (144.204.159.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.159.204.144 (144.204.159.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 31 12:56:20.803136 2026] [security2:error] [pid 3288221:tid 3288221] [client 34.159.204.144:40088] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.angove.biz"] [uri "/.env"] [unique_id "amzTtHyoDX11K0ExgBkS8wAAAGs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ท๐บ
DZBOT
2026-07-31 16:33:38
(15 hours ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-31 16:24:02
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.159.204.144 (144.204.159.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.159.204.144 (144.204.159.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 31 12:23:54.705837 2026] [security2:error] [pid 3338833:tid 3338850] [client 34.159.204.144:56010] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.draas.newtrendmag.org"] [uri "/.env"] [unique_id "amzMGtvul5JuDCcN82yOygAAAMw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
todix
2026-07-31 16:22:31
(15 hours ago)
Web App Attack Exploid from 34.159.204.144
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-31 15:53:41
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.159.204.144 (144.204.159.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.159.204.144 (144.204.159.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 31 11:53:34.507521 2026] [security2:error] [pid 3473954:tid 3473954] [client 34.159.204.144:52692] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.thepinelandclub.com.velvetculture.com"] [uri "/.env"] [unique_id "amzE_ucxGHzsEo4sDPng3wAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-31 15:36:32
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.159.204.144 (144.204.159.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.159.204.144 (144.204.159.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 31 11:36:28.931592 2026] [security2:error] [pid 25026:tid 25033] [client 34.159.204.144:44380] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "lasertagandgames.com"] [uri "/.env"] [unique_id "amzA_EVBQ3boFgLfCbo4KQAAAMU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
4server
2026-07-31 15:20:07
(16 hours ago)
[FriJul3117:20:02.0598762026][security2:error][pid3572224:tid3572469][client34.159.204.144:0]ModSecu ...
show more
[FriJul3117:20:02.0598762026][security2:error][pid3572224:tid3572469][client34.159.204.144:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\".env\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"365\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"giulianodemarco.ch\"][uri\"/.env\"][unique_id\"amy9IjuOjJl7LxOwSNrErQAAAJE\"]
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-31 15:00:16
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.159.204.144 (144.204.159.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.159.204.144 (144.204.159.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 31 11:00:10.620078 2026] [security2:error] [pid 1162536:tid 1162595] [client 34.159.204.144:43710] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "stephanie.stauffer.name"] [uri "/.env"] [unique_id "amy4etVlva_y7RO_A-apWQAAAcA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
hidemail.app
2026-07-31 14:51:46
(17 hours ago)
Automated scan for exposed config/secret files and known web exploits (e.g. /.env, RCE probes); auto ...
show more
Automated scan for exposed config/secret files and known web exploits (e.g. /.env, RCE probes); auto-banned by fail2ban.
show less
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-07-31 14:42:00
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.159.204.144 (144.204.159.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.159.204.144 (144.204.159.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 31 10:41:53.281459 2026] [security2:error] [pid 3862344:tid 3862344] [client 34.159.204.144:48788] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kerrywood.com"] [uri "/.env"] [unique_id "amy0Me3PajItAe4eVDfY0AAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
mail.avx.gr
2026-07-31 14:40:03
(17 hours ago)
Plesk Fail2Ban jail: Plesk-Web-Exploits. Evidence: default-10-0-0-4:443 34.159.204.144 - - [31/Jul/2 ...
show more
Plesk Fail2Ban jail: Plesk-Web-Exploits. Evidence: default-10-0-0-4:443 34.159.204.144 - - [31/Jul/2026:17:40:03 +0300] "GET /.env HTTP/1.1" 403 2437 "-" "crusader-worker/1.0"
show less
Web App Attack
Anonymous
2026-07-31 14:25:02
(17 hours ago)
suspicious request in access.log
Web App Attack
Anonymous
2026-07-31 13:54:24
(17 hours ago)
34.159.204.144 - - [31/Jul/2026:21:54:24 +0800] "GET /.env HTTP/1.1" 404 196 "-" "crusader-worker/1. ...
show more
34.159.204.144 - - [31/Jul/2026:21:54:24 +0800] "GET /.env HTTP/1.1" 404 196 "-" "crusader-worker/1.0"
...
show less
Bad Web Bot
Web App Attack