π³π±
Savvii
2026-06-15 10:49:35
(16 hours ago)
20 attempts against mh_ha-misbehave-ban on star
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
Lezetho
2026-06-15 10:00:24
(17 hours ago)
DDoS, WebSpam, Web Attack, and Brute-force blocked by Cloudflare
DDoS Attack
Email Spam
Hacking
Brute-Force
πΊπΈ
TPI-Abuse
2026-06-15 09:20:09
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.174.70.28 (28.70.174.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.174.70.28 (28.70.174.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 15 05:20:03.140688 2026] [security2:error] [pid 11863:tid 11881] [client 34.174.70.28:35044] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.coloradospringsmardigras.aafm.us"] [uri "/.env.development.local"] [unique_id "ai_Dw4ZIWF6VeU_-JqulKgAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
Site.eu
2026-06-15 08:48:59
(18 hours ago)
Excessive multi-domain requests
Brute-Force
π«π·
Feelautom
2026-06-15 08:07:48
(19 hours ago)
[FeelAutom Auto-Ban] PathScan: /.env.dev.local (Score: 840)
Port Scan
π«π·
Octopuce
2026-06-15 07:55:33
(19 hours ago)
Aggressive web search of vulnerable pages: /api/.env /api/.env.local /v1/.env /api/v3/.env /prod/.en ...
show more
Aggressive web search of vulnerable pages: /api/.env /api/.env.local /v1/.env /api/v3/.env /prod/.env ...
show less
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-15 07:42:21
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.174.70.28 (28.70.174.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.174.70.28 (28.70.174.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 15 03:42:13.493609 2026] [security2:error] [pid 28673:tid 28673] [client 34.174.70.28:49656] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.williambarfoot.com.lakesidedetectiveagency.com"] [uri "/.env.old"] [unique_id "ai-s1TaluZPL15SX-CHnNgAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π¬π§
consul.to
2026-06-15 05:49:55
(21 hours ago)
Web attack/malicious scanning detected
Web App Attack
πΊπΈ
mnsf
2026-06-15 03:06:17
(1 day ago)
Scanning/Probing (115)
Request Overload (120)
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-15 02:54:07
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.174.70.28 (28.70.174.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.174.70.28 (28.70.174.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 22:53:59.768148 2026] [security2:error] [pid 14161:tid 14213] [client 34.174.70.28:47476] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "evrmorebrand.com"] [uri "/.env.backup"] [unique_id "ai9pR-2w3KZ_7sN75fCacQAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-15 01:19:36
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.174.70.28 (28.70.174.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.174.70.28 (28.70.174.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 21:19:31.343921 2026] [security2:error] [pid 22067:tid 22067] [client 34.174.70.28:39450] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "inlinesoftware.net"] [uri "/.env.old"] [unique_id "ai9TI6frjEHgbDESI53uBQAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π«π·
dynamix
2026-06-14 23:52:52
(1 day ago)
Multiple WAF Violations
Web App Attack
π©πͺ
4server
2026-06-14 22:17:41
(1 day ago)
[MonJun1500:17:38.9374432026][security2:error][pid2397638:tid2397691][client34.174.70.28:0]ModSecuri ...
show more
[MonJun1500:17:38.9374432026][security2:error][pid2397638:tid2397691][client34.174.70.28:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Patternmatch\"\(\?i\)\(\?:/\(\?:\^\|/\)\\\\\\\\.\(env\|git\|svn\|hg\|DS_Store\)\|/\(\?:wp-config\|\\\\\\\\.htaccess\|\\\\\\\\.htpasswd\)\|\\\\\\\\.\(\?:sql\|bak\|old\|log\)\$\)\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"156\"][id\"960720\"][msg\"Forbiddenfileaccessattempt\"][severity\"CRITICAL\"][hostname\"www.bluecirclecapital.ch.136-243-54-122.cpanel.site\"][uri\"/.env.old\"][unique_id\"ai8ogoIGxdWB6J8Ev6enJQAAAFE\"]
show less
Port Scan
Brute-Force
Web App Attack
π«π·
Lino Project
2026-06-14 22:17:34
(1 day ago)
34.174.70.28 - - [15/Jun/2026:00:17:32 +0200] "GET /.env.development HTTP/1.1" 302 4300 "-" "Mozilla ...
show more
34.174.70.28 - - [15/Jun/2026:00:17:32 +0200] "GET /.env.development HTTP/1.1" 302 4300 "-" "Mozilla/5.0 (SymbianOS/9.1; U; en-us) AppleWebKit/413 (KHTML, like Gecko) Safari/413 es50"
34.174.70.28 - - [15/Jun/2026:00:17:32 +0200] "GET /.env.qa HTTP/1.1" 302 4282 "-" "Mozilla/5.0 (Macintosh; U; PPC Mac OS X; en) AppleWebKit/125.2 (KHTML, like Gecko) Safari/85.8"
...
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-14 15:58:19
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.174.70.28 (28.70.174.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.174.70.28 (28.70.174.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 11:58:15.343223 2026] [security2:error] [pid 9436:tid 9436] [client 34.174.70.28:34376] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "301i.com"] [uri "/.env"] [unique_id "ai7Pl4BLkTxETLG34osCkAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack