πΊπΈ
TPI-Abuse
2026-08-01 17:25:01
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.175.73.46 (46.73.175.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.175.73.46 (46.73.175.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 13:24:56.480476 2026] [security2:error] [pid 14799:tid 14799] [client 34.175.73.46:34098] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "applemaccomputerconsulting.com"] [uri "/.env.old"] [unique_id "am4r6CS6YDfSai6WJ0cRrQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
conrad10781
2026-08-01 17:23:10
(16 hours ago)
nginx-dot-env
Web App Attack
π©πͺ
4server
2026-08-01 17:18:19
(16 hours ago)
[SatAug0119:18:17.1401312026][security2:error][pid1782664:tid1782688][client34.175.73.46:0]ModSecuri ...
show more
[SatAug0119:18:17.1401312026][security2:error][pid1782664:tid1782688][client34.175.73.46:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Patternmatch\"\(\?i\)\(\?:/\(\?:\^\|/\)\\\\\\\\.\(env\|git\|svn\|hg\|DS_Store\)\|/\(\?:wp-config\|\\\\\\\\.htaccess\|\\\\\\\\.htpasswd\)\|\\\\\\\\.\(\?:sql\|bak\|old\|log\)\$\)\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"156\"][id\"960720\"][msg\"Forbiddenfileaccessattempt\"][severity\"CRITICAL\"][hostname\"www.archi-box.ch\"][uri\"/.env.old\"][unique_id\"am4qWSntPM0Ga8c2HXCu1AAAAAs\"]
show less
Port Scan
Brute-Force
Web App Attack
π©πͺ
wpadm4
2026-08-01 16:59:36
(16 hours ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
π¦πΊ
2000cn.com.au
2026-08-01 16:31:17
(17 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
πΊπΈ
TPI-Abuse
2026-08-01 16:31:08
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.175.73.46 (46.73.175.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.175.73.46 (46.73.175.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 12:31:03.954113 2026] [security2:error] [pid 123659:tid 123659] [client 34.175.73.46:58912] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "web217.dnchosting.com"] [uri "/.env.production"] [unique_id "am4fR59Sf7KXaiufPduPKAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
LRob
2026-08-01 16:30:02
(17 hours ago)
CrowdSec: crowdsecurity/http-sensitive-files | req: /.env.prod | 5 distinct paths | UA: crusader-wor ...
show more
CrowdSec: crowdsecurity/http-sensitive-files | req: /.env.prod | 5 distinct paths | UA: crusader-worker/1.0
show less
Hacking
π³π±
e.fierstra
2026-08-01 16:21:05
(17 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-01 16:15:47
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.175.73.46 (46.73.175.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.175.73.46 (46.73.175.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 12:15:39.410121 2026] [security2:error] [pid 771483:tid 771483] [client 34.175.73.46:33320] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.credit.ic1.biz"] [uri "/.env.local"] [unique_id "am4bq8KT0qXZhplk3tVjawAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
Zydzy
2026-08-01 15:30:14
(18 hours ago)
Automated attack detected. Server: 95.140.154.181. Jail: nginx-exploit.
Web App Attack
π©πͺ
FeG Deutschland
2026-08-01 15:18:56
(18 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
π¨π
4server
2026-08-01 15:02:00
(18 hours ago)
[SatAug0117:01:52.9423372026][security2:error][pid3964166:tid3964385][client34.175.73.46:0]ModSecuri ...
show more
[SatAug0117:01:52.9423372026][security2:error][pid3964166:tid3964385][client34.175.73.46:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\".env\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"365\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"mail.edilmarra.ch\"][uri\"/.env.backup\"][unique_id\"am4KYNM7TEqV2Y5_--bTXQAAAQI\"]
show less
Hacking
Web App Attack
π·πΊ
DZBOT
2026-08-01 14:29:50
(19 hours ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-01 14:17:33
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.175.73.46 (46.73.175.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.175.73.46 (46.73.175.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 10:17:29.905494 2026] [security2:error] [pid 2275453:tid 2275453] [client 34.175.73.46:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.hvacs-aircon.com"] [uri "/.env.bak"] [unique_id "am3_-T467uacEgqOjG9OxgAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-01 13:57:58
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.175.73.46 (46.73.175.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.175.73.46 (46.73.175.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 09:57:52.471192 2026] [security2:error] [pid 900891:tid 900910] [client 34.175.73.46:59656] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "gamecrazy.hdtv55.com"] [uri "/.env.prod"] [unique_id "am37YK8faALD3ixpUpeXpgAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack