๐ซ๐ท
dynamix
2026-06-13 10:52:51
(12 hours ago)
Multiple WAF Violations
Web App Attack
๐ฉ๐ช
updown.io
2026-06-13 10:32:49
(13 hours ago)
{"level":"info","ts":1781346768.373296,"logger":"http.log.access.log1","msg":"handled request","requ ...
show more
{"level":"info","ts":1781346768.373296,"logger":"http.log.access.log1","msg":"handled request","request":{"remote_ip":"34.16.221.224","remote_port":"42140","client_ip":"34.16.221.224","proto":"HTTP/1.1","method":"GET","host":"srqupdate.ihgfedcbaupdate.yxwvutsrqponmlonihgfedcbwwwc7402a95-6fc9-4756-b4e6-fa6c7eeb29c6.random.159.89.98.98.nip.io","uri":"/.env.save","headers":{"Accept-Charset":["utf-8"],"Accept-Encoding":["gzip"],"Connection":["close"],"User-Agent":["Mozilla/5.0 (Linux; Android 4.1.2; GT-N8013) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/71.0.3578.99 Safari/537.36"]}},"bytes_read":0,"user_id":"","duration":0.000091514,"size":0,"status":308,"resp_headers":{"Server":["Caddy"],"Connection":["close"],"Location":["https://srqupdate.ihgfedcbaupdate.yxwvutsrqponmlonihgfedcbwwwc7402a95-6fc9-4756-b4e6-fa6c7eeb29c6.random.159.89.98.98.nip.io/.env.save"],"Content-Type":[]}}
{"level":"info","ts":1781346768.3853178,"logger":"http.log.access.log1","msg":"handled request","request":{"rem
...
show less
DDoS Attack
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-13 10:07:36
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.16.221.224 (224.221.16.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.16.221.224 (224.221.16.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 13 06:07:31.616678 2026] [security2:error] [pid 21099:tid 21099] [client 34.16.221.224:40320] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.test.altruaglobalsolutions.com"] [uri "/.env"] [unique_id "ai0r4w7aZI56E2Jbxs9zggAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
pltcldvlpr
2026-06-13 09:37:28
(14 hours ago)
CMS/framework probe: 34.16.221.224 - - [13/Jun/2026:11:37:17 +0200] "GET /.env.old HTTP/1.1" 404 484 ...
show more
CMS/framework probe: 34.16.221.224 - - [13/Jun/2026:11:37:17 +0200] "GET /.env.old HTTP/1.1" 404 4845 "-" "Mozilla/5.0 (Unknown; U; UNIX BSD/SYSV system; C -) AppleWebKit/527 (KHTML, like Gecko, Safari/419.3) Arora/0.10.2" asn=396982 org="Google LLC" country=US
...
show less
Web App Attack
Anonymous
2026-06-13 09:26:12
(14 hours ago)
[news.tmg.gr] httpd-suspicious-path: sites=global; logs=/var/log/httpd/access_log; samples=/api/.env ...
show more
[news.tmg.gr] httpd-suspicious-path: sites=global; logs=/var/log/httpd/access_log; samples=/api/.env.local | /.env.old | /api/.env.production
show less
Hacking
Web App Attack
๐ณ๐ด
jad@
2026-06-13 08:58:52
(14 hours ago)
ThreatFeed automated detection: malicious HTTP scanning / exploit attempts. Signatures: env_probe. O ...
show more
ThreatFeed automated detection: malicious HTTP scanning / exploit attempts. Signatures: env_probe. Observed by 1 sensor(s); 297 hits.
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-13 07:26:12
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.16.221.224 (224.221.16.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.16.221.224 (224.221.16.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 13 03:26:07.502027 2026] [security2:error] [pid 7188:tid 7199] [client 34.16.221.224:42996] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "fix4life.com"] [uri "/.env.bak"] [unique_id "ai0GD1gYcb-zzplmn64EWgAAAEk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-13 06:10:42
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.16.221.224 (224.221.16.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.16.221.224 (224.221.16.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 13 02:10:35.609886 2026] [security2:error] [pid 2940:tid 2940] [client 34.16.221.224:43992] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.terruven.badritual.art"] [uri "/.env.preprod"] [unique_id "aiz0W7zPg8cvpn26fTs2_gAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
VHosting
2026-06-13 05:15:03
(18 hours ago)
Detected WordPress attack from 4 different servers
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-13 04:41:26
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.16.221.224 (224.221.16.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.16.221.224 (224.221.16.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 13 00:41:22.382750 2026] [security2:error] [pid 12791:tid 12791] [client 34.16.221.224:52300] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "uhfcfoundation.org"] [uri "/.env.backup.txt"] [unique_id "aizfci_onbtDurIDli7aLQAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack