🇳🇱
wlt-blocker
2026-09-06 06:19:11
(4 hours ago)
Unauthorized access to webpage admin
Web App Attack
🇺🇸
RogueAutomata
2026-09-06 06:19:06
(4 hours ago)
Detected malicious request: GET /.env.prod
Detections triggered: Environment/config probe
Access vi ...
show more
Detected malicious request: GET /.env.prod
Detections triggered: Environment/config probe
Access via IP addr (v4)
show less
Web App Attack
Anonymous
2026-09-06 04:41:24
(5 hours ago)
Aggressive web scan
Web App Attack
🇩🇪
paissangroup
2026-09-06 03:52:57
(6 hours ago)
Multiple WAF Violations
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 03:19:35
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.175.139.159 (159.139.175.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.175.139.159 (159.139.175.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 23:19:27.777782 2026] [security2:error] [pid 19400:tid 19400] [client 34.175.139.159:57986] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "dentsville398.org"] [uri "/.env.old"] [unique_id "apzbvzWUKrl1DeCiMb07RAAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
Hazzard
2026-09-06 03:05:34
(7 hours ago)
(mod_security) mod_security triggered on hostname [redacted]): (CF_ENABLE)
SQL Injection
🇫🇷
dynamix
2026-09-06 02:30:23
(8 hours ago)
Multiple WAF Violations
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 02:29:02
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.175.139.159 (159.139.175.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.175.139.159 (159.139.175.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 22:28:56.187494 2026] [security2:error] [pid 648:tid 648] [client 34.175.139.159:42784] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sinobabel.com"] [uri "/.env"] [unique_id "apzP6PZ3t26i7-cdVJItUQAAAEE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-06 01:35:17
(9 hours ago)
Failed login attempt detected by Fail2Ban in plesk-modsecurity jail
Exploited Host
🇺🇸
TPI-Abuse
2026-09-06 01:22:33
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.175.139.159 (159.139.175.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.175.139.159 (159.139.175.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 21:22:28.322190 2026] [security2:error] [pid 15385:tid 15385] [client 34.175.139.159:59460] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "techsuite7.net"] [uri "/.env.example"] [unique_id "apzAVH5K3PV0acjghCaXOwAAACY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-06 01:16:43
(9 hours ago)
34.175.139.159 - - [05/Sep/2026:22:16:42 -0300] "GET /.env.local HTTP/2.0" Dest:Port 443 HTTP_Status ...
show more
34.175.139.159 - - [05/Sep/2026:22:16:42 -0300] "GET /.env.local HTTP/2.0" Dest:Port 443 HTTP_Status: 302
...
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 23:46:26
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.175.139.159 (159.139.175.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.175.139.159 (159.139.175.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 19:46:22.027367 2026] [security2:error] [pid 2750:tid 2750] [client 34.175.139.159:33868] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "10bestrealtors.directoryofbikes.com"] [uri "/.env.backup"] [unique_id "apypzsOQJ9t_TtBXdZP8yQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 22:58:43
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.175.139.159 (159.139.175.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.175.139.159 (159.139.175.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 18:58:37.024189 2026] [security2:error] [pid 6512:tid 6512] [client 34.175.139.159:58514] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.modernsalessolutions.com"] [uri "/wp-config.php.bak"] [unique_id "apyenWv9Qjw7JYfUs1N4FQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 22:31:00
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.175.139.159 (159.139.175.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.175.139.159 (159.139.175.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 18:30:53.424367 2026] [security2:error] [pid 11645:tid 11677] [client 34.175.139.159:48916] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "touba.newtrendmag.org"] [uri "/.env.example"] [unique_id "apyYHSV7lRfnBdEsmahPqgAAAEc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
e.fierstra
2026-09-05 21:54:20
(12 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack