🇫🇷
Catalin Negru
2026-09-09 04:40:55
(1 hour ago)
Recidive ban by fail2ban on server.blackbit.ro
Brute-Force
🇳🇱
e.fierstra
2026-09-08 12:30:46
(17 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 11:20:35
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.159.210.89 (89.210.159.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.159.210.89 (89.210.159.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 07:20:28.812042 2026] [security2:error] [pid 32555:tid 32555] [client 34.159.210.89:33076] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.owenmail.com"] [uri "/.env.production"] [unique_id "ap_vfEZ6auLN5OEYYFF4uwAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇱🇻
garmtech.com
2026-09-08 11:07:06
(18 hours ago)
Attempted access to sensitive endpoint (/.env.bak) detected. Automated scan or unauthorized probing.
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 10:01:34
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.159.210.89 (89.210.159.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.159.210.89 (89.210.159.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 06:01:27.308843 2026] [security2:error] [pid 27322:tid 27322] [client 34.159.210.89:37190] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.crankalicious.com"] [uri "/.env.example"] [unique_id "ap_c94obtbhnYcUpiPOn_QAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇱🇻
garmtech.com
2026-09-08 04:16:16
(1 day ago)
Attempted access to sensitive endpoint (/.env) detected. Automated scan or unauthorized probing.
Web App Attack
🇨🇭
copestack
2026-09-07 16:00:07
(1 day ago)
Automated detection: HTTP environment file enumeration (.env credential harvesting). 1 decisions on ...
show more
Automated detection: HTTP environment file enumeration (.env credential harvesting). 1 decisions on ov-9acb4e.
show less
Web App Attack
🇫🇷
dynamix
2026-09-07 06:10:33
(1 day ago)
Multiple WAF Violations
Web App Attack
🇳🇱
homeshowdomain.nl
2026-09-06 22:02:50
(2 days ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-09-05.
show less
Web App Attack
SSH
Hacking
🇳🇱
WeCloudit-Anti-Abuse
2026-09-06 04:44:53
(3 days ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
🇫🇷
Catalin Negru
2026-09-06 03:55:16
(3 days ago)
Recidive ban by fail2ban on server.blackbit.ro
Brute-Force
🇺🇸
TPI-Abuse
2026-09-06 03:49:00
(3 days ago)
(mod_security) mod_security (id:210730) triggered by 34.159.210.89 (89.210.159.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.159.210.89 (89.210.159.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 23:48:53.906701 2026] [security2:error] [pid 305389:tid 305425] [client 34.159.210.89:58790] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||almerirock.com.emehache.net|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "almerirock.com.emehache.net"] [uri "/backup.sql"] [unique_id "apzipedZ4xRVqzYhVJzFMwAAAUs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 02:58:04
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.159.210.89 (89.210.159.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.159.210.89 (89.210.159.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 22:57:58.082364 2026] [security2:error] [pid 7308:tid 7308] [client 34.159.210.89:44780] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.mindbodyrestored.com"] [uri "/.env.example"] [unique_id "apzWth6r7i5CtPC8x9UFwgAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
debestelapp
2026-09-06 02:25:12
(3 days ago)
Web App Attack
🇫🇷
✨
2026-09-06 02:25:09
(3 days ago)
Domain : content.lembas.co.uk
Rule : env
2026-09-06 02:22:46 ***hidden-privacy*** GET /.env.local - ...
show more
Domain : content.lembas.co.uk
Rule : env
2026-09-06 02:22:46 ***hidden-privacy*** GET /.env.local - 443 - 34.159.210.89 HTTP/1.1 crusader-worker/1.0 - content.lembas.co.uk 404 0 2 1688 102 34 - -
show less
Hacking
SQL Injection