๐บ๐ธ
TPI-Abuse
2026-06-15 06:48:10
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.176.110.178 (178.110.176.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.176.110.178 (178.110.176.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 15 02:48:06.511701 2026] [security2:error] [pid 25485:tid 25485] [client 34.176.110.178:38138] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "hazelzito.com"] [uri "/.env.production"] [unique_id "ai-gJpNQur_-WMx-ZqtLDQAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-06-15 04:35:22
(1 day ago)
34.176.110.178 - - [15/Jun/2026:07:35:21 +0300] "GET /prod/.env HTTP/1.1" 404 3305 "-" "Mozilla/5.0 ...
show more
34.176.110.178 - - [15/Jun/2026:07:35:21 +0300] "GET /prod/.env HTTP/1.1" 404 3305 "-" "Mozilla/5.0 (Macintosh; U; Intel Mac OS X 10_6_5; de-de) AppleWebKit/534.15 (KHTML, like Gecko) Version/5.0.3 Safari/533.19.4"
34.176.110.178 - - [15/Jun/2026:07:35:21 +0300] "GET /test/.env HTTP/1.1" 404 3306 "-" "Mozilla/5.0 (Linux; Android 9; SM-A705GM) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/75.0.3770.143 Mobile Safari/537.36"
...
show less
Web App Attack
๐ซ๐ท
masterguru
2026-06-15 03:52:48
(1 day ago)
Restricted File Access Attempt. Matched phrase ".env" at REQUEST_FILENAME. (930130-196)
Hacking
Web App Attack
๐ฌ๐ง
consul.to
2026-06-15 02:42:35
(2 days ago)
Web attack/malicious scanning detected
Web App Attack
Anonymous
2026-06-15 01:47:08
(2 days ago)
[Mon Jun 15 01:47:07.631259 2026] [authz_core:error] [pid 658476:tid 658476] [client 34.176.110.178: ...
show more
[Mon Jun 15 01:47:07.631259 2026] [authz_core:error] [pid 658476:tid 658476] [client 34.176.110.178:59128] AH01630: client denied by server configuration: /var/www/shop.gassycat.be/htdocs/app/.env.production
[Mon Jun 15 01:47:07.643876 2026] [authz_core:error] [pid 658067:tid 658067] [client 34.176.110.178:59130] AH01630: client denied by server configuration: /var/www/shop.gassycat.be/htdocs/app/.env.prod
[Mon Jun 15 01:47:07.636386 2026] [authz_core:error] [pid 658482:tid 658482] [client 34.176.110.178:59138] AH01630: client denied by server configuration: /var/www/shop.gassycat.be/htdocs/app/.env.backup
[Mon Jun 15 01:47:07.719740 2026] [authz_core:error] [pid 658060:tid 658060] [client 34.176.110.178:59204] AH01630: client denied by server configuration: /var/www/shop.gassycat.be/htdocs/app/backend
[Mon Jun 15 01:47:07.756914 2026] [authz_core:error] [pid 658076:tid 658076] [client 34.176.110.178:59224] AH01630: client denied by server configuration: /var/www/shop.gassycat.be/htdoc
...
show less
Brute-Force
๐ซ๐ท
Octopuce
2026-06-15 00:45:09
(2 days ago)
Aggressive web search of vulnerable pages: /backend/api/.env /frontend/.env /frontend/.env.local /ap ...
show more
Aggressive web search of vulnerable pages: /backend/api/.env /frontend/.env /frontend/.env.local /api/.env /test/.env ...
show less
Web App Attack
๐บ๐ธ
mnsf
2026-06-15 00:18:22
(2 days ago)
Scanning/Probing (98)
Request Overload (103)
Brute-Force
Web App Attack
๐บ๐ธ
Starburst SysOp Team
2026-06-14 23:27:12
(2 days ago)
Restricted File Access Attempt. Matched phrase ".env" at REQUEST_FILENAME. (930130-mnz6-1)
Hacking
Web App Attack
๐จ๐ญ
Sonics
2026-06-14 14:44:22
(2 days ago)
Automated scanner: .env/.git/phpinfo scan
Web App Attack
๐ฉ๐ช
NihiliousMonk
2026-06-14 06:03:50
(2 days ago)
Fail2Ban report from jail npm-scanners
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-14 05:59:06
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.176.110.178 (178.110.176.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.176.110.178 (178.110.176.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 01:59:02.167835 2026] [security2:error] [pid 29195:tid 29195] [client 34.176.110.178:35376] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "rwfrancis.com"] [uri "/.env.template"] [unique_id "ai5DJpP0Tw0slEkTE6q3QAAAAHs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-06-14 05:07:01
(2 days ago)
Excessive 404/403 errors
Brute-Force
Anonymous
2026-06-14 04:49:12
(2 days ago)
(caddyscan) Scanner path probe from 34.176.110.178 (178.110.176.34.bc.googleusercontent.com): 5 in t ...
show more
(caddyscan) Scanner path probe from 34.176.110.178 (178.110.176.34.bc.googleusercontent.com): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 2627 34.176.110.178 - - [14/Jun/2026:04:49:00 +0000] "GET /.env.copy HTTP/1.1"
[REDACTED] 200 2627 34.176.110.178 - - [14/Jun/2026:04:49:00 +0000] "GET /admin/.env HTTP/1.1"
[REDACTED] 200 2627 34.176.110.178 - - [14/Jun/2026:04:49:00 +0000] "GET /app/.env.production HTTP/1.1"
[REDACTED] 200 2627 34.176.110.178 - - [14/Jun/2026:04:49:00 +0000] "GET /api/.env.production HTTP/1.1"
[REDACTED] 200 2627 34.176.110.178 - - [14/Jun/2026:04:49:00 +0000] "GET /api/.env.bak HTTP/1.1"
show less
Port Scan
Anonymous
2026-06-14 04:15:36
(2 days ago)
Multiple web server 400 error codes from same source ip
Web App Attack
๐ฎ๐น
VHosting
2026-06-14 04:15:04
(2 days ago)
Detected WordPress attack from 4 different servers
Brute-Force
Web App Attack