๐ช๐ธ
alferez
2026-08-01 17:23:24
(1 hour ago)
Searching .(env|sql|zip|tar|rar) files
Hacking
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-01 17:22:02
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.17.34.96 (96.34.17.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.17.34.96 (96.34.17.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 13:21:55.158720 2026] [security2:error] [pid 2647038:tid 2647038] [client 34.17.34.96:53932] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.escribaniasmith.syconline.com"] [uri "/.env.bak"] [unique_id "am4rM8N0X0TEpMpGHJgacAAAACs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-01 16:33:30
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.17.34.96 (96.34.17.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.17.34.96 (96.34.17.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 12:33:25.977948 2026] [security2:error] [pid 2875242:tid 2875266] [client 34.17.34.96:53132] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.cityfilms-lb.com.oplconnect.com"] [uri "/.env.example"] [unique_id "am4f1cbMBn1nErInZot72QAAARI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
itsolon
2026-08-01 16:31:24
(1 hour ago)
[01/Aug/2026:18:31:24 +0200] 178560188442.973702 34.17.34.96 0 217.154.7.177 443
[01/Aug/2026:18:31: ...
show more
[01/Aug/2026:18:31:24 +0200] 178560188442.973702 34.17.34.96 0 217.154.7.177 443
[01/Aug/2026:18:31:24 +0200] 178560188461.161320 34.17.34.96 0 217.154.7.177 443
[01/Aug/2026:18:31:24 +0200] 178560188494.004040 34.17.34.96 0 217.154.7.177 443
[01/Aug/2026:18:31:24 +0200] 178560188467.238816 34.17.34.96 0 217.154.7.177 443
[01/Aug/2026:18:31:24 +0200] 178560188414.109585 34.17.34.96 0 217.154.7.177 443
...
show less
Port Scan
Hacking
Brute-Force
Web App Attack
๐ซ๐ท
Little Iguana
2026-08-01 16:28:37
(1 hour ago)
Attempt to hack Wordpress Login, XMLRPC or other login
Hacking
Anonymous
2026-08-01 16:05:02
(2 hours ago)
suspicious request in access.log
Web App Attack
Anonymous
2026-08-01 16:04:46
(2 hours ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
๐ธ๐ช
vaia.cloud
2026-08-01 15:50:03
(2 hours ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-01 15:41:08
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.17.34.96 (96.34.17.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.17.34.96 (96.34.17.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 11:41:04.600996 2026] [security2:error] [pid 2438095:tid 2438095] [client 34.17.34.96:58472] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.coolex.cloudex.link"] [uri "/.env.old"] [unique_id "am4TkBftBupTKff6rg528QAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-01 15:34:02
(2 hours ago)
Bot / scanning and/or hacking attempts: GET /.env.bak HTTP/1.1, GET /.env HTTP/1.1
Hacking
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-08-01 15:22:15
(3 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐ฎ๐น
ciccio diddo
2026-08-01 15:16:02
(3 hours ago)
High Burst multiple 40X port:Tcp/80,443
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-01 14:51:24
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.17.34.96 (96.34.17.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.17.34.96 (96.34.17.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 10:51:19.197702 2026] [security2:error] [pid 26381:tid 26381] [client 34.17.34.96:44964] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "dogdimension.com"] [uri "/.env.example"] [unique_id "am4H568RDKW69U6VmDJtYwAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-01 14:32:45
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.17.34.96 (96.34.17.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.17.34.96 (96.34.17.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 10:32:40.923637 2026] [security2:error] [pid 347621:tid 347621] [client 34.17.34.96:42626] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "grupoimaginarte.com"] [uri "/.env"] [unique_id "am4DiANW0hbKXVrdd5IGfgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob
2026-08-01 14:24:31
(4 hours ago)
CrowdSec: crowdsecurity/http-sensitive-files | req: /.env | 5 distinct paths | UA: crusader-worker/1 ...
show more
CrowdSec: crowdsecurity/http-sensitive-files | req: /.env | 5 distinct paths | UA: crusader-worker/1.0
show less
Hacking