๐ต๐ฑ
nfsec.pl
2026-06-15 07:01:14
(1 week ago)
34.176.246.110 - - [15/Jun/2026:07:01:13 +0000] "GET /.env.backup.txt HTTP/1.1" 403 7993 "-" "Mozill ...
show more
34.176.246.110 - - [15/Jun/2026:07:01:13 +0000] "GET /.env.backup.txt HTTP/1.1" 403 7993 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:10.0.1) Gecko/20100101 Firefox/10.0.1"
34.176.246.110 - - [15/Jun/2026:07:01:13 +0000] "GET /.env.local HTTP/1.1" 403 8080 "-" "Mozilla/5.0 (Linux; U; Android 2.3.3; en-us ; LS670 Build/GRI40) AppleWebKit/533.1 (KHTML, like Gecko) Version/4.0 Mobile Safari/533.1/UCBrowser/8.6.1.262/145/355"
34.176.246.110 - - [15/Jun/2026:07:01:13 +0000] "GET /.env.bak HTTP/1.1" 403 8058 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3626.121 YaBrowser/19.3.1.828 Yowser/2.5 Safari/537.36"
34.176.246.110 - - [15/Jun/2026:07:01:13 +0000] "GET /.env.prod.bak HTTP/1.1" 403 8061 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 YaBrowser/19.6.2.594 (beta) Yowser/2.5 Safari/537.36"
34.176.246.110 - - [15/Jun/2026:07:01:13 +0000] "GET /.env.dev HTTP/1.1" 403 8032 "-" "Mozilla/5.0 (Window
...
show less
Web App Attack
Exploited Host
๐ฒ๐พ
Rizzy
2026-06-15 04:50:12
(1 week ago)
Multiple WAF Violations
Brute-Force
Web App Attack
๐ซ๐ท
dynamix
2026-06-15 03:31:48
(1 week ago)
Multiple WAF Violations
Web App Attack
๐ฉ๐ฐ
ScamAware
2026-06-15 02:05:03
(1 week ago)
Detected by Cloudflare Security Events via WordPress automation. Detection: sensitive_files (Sensiti ...
show more
Detected by Cloudflare Security Events via WordPress automation. Detection: sensitive_files (Sensitive files, source control, config, and backups). Hits from same IP in last 60 minutes: 154. Unique request paths counted internally: 154. Cloudflare action: block. Cloudflare source: firewallCustom.
show less
Web App Attack
๐ซ๐ท
Octopuce
2026-06-15 00:04:50
(1 week ago)
Aggressive web search of vulnerable pages: /v3/.env /api/v2/.env /v1/.env /api/.env.local /staging/. ...
show more
Aggressive web search of vulnerable pages: /v3/.env /api/v2/.env /v1/.env /api/.env.local /staging/.env ...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-14 21:18:04
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.176.246.110 (110.246.176.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.176.246.110 (110.246.176.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 17:18:00.915383 2026] [security2:error] [pid 1556:tid 1556] [client 34.176.246.110:36340] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "onward.ws"] [uri "/.env.stage"] [unique_id "ai8aiDv3IgsL4zeVqqBpDAAAAEo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ท๐ด
iulianh
2026-06-14 05:29:47
(2 weeks ago)
80,443
Brute-Force
SSH
๐บ๐ธ
mnsf
2026-06-14 05:09:42
(2 weeks ago)
Abuse Detected (56)
Brute-Force
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-06-14 04:06:13
(2 weeks ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐ช๐ธ
gnom4ik
2026-06-14 03:56:08
(2 weeks ago)
ban-reviewer auto report; ip=34.176.246.110; scenario=crowdsecurity/http-bad-user-agent; verdict=val ...
show more
ban-reviewer auto report; ip=34.176.246.110; scenario=crowdsecurity/http-bad-user-agent; verdict=valid_ban; confidence=0.92; categories=14,15,18,22; active_decisions=3; lookback_decisions=3; nginx_requests=0; appsec_matches=0; auth_events=0; kernel_events=0; signals=ip_decision_count_high; ip_active_decision_count_high
show less
Port Scan
Hacking
Brute-Force
SSH
๐ณ๐ฑ
Site.eu
2026-06-14 03:06:24
(2 weeks ago)
Excessive 404/403 errors
Brute-Force