๐บ๐ธ
TPI-Abuse
2026-09-01 13:49:24
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.179.208.227 (227.208.179.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.179.208.227 (227.208.179.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 09:49:21.348632 2026] [security2:error] [pid 30094:tid 30094] [client 34.179.208.227:45580] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.uglykid.net"] [uri "/.env.save"] [unique_id "apbX4YP5pAwqO6gysr7wrgAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ท๐ด
iulianh
2026-09-01 13:02:40
(9 hours ago)
80,443
Brute-Force
SSH
๐ฎ๐ฉ
Burayot
2026-09-01 12:00:10
(10 hours ago)
LF_MODSEC: (mod_security) mod_security (id:949110) triggered by 34.179.208.227 (DE/Germany/227.208.1 ...
show more
LF_MODSEC: (mod_security) mod_security (id:949110) triggered by 34.179.208.227 (DE/Germany/227.208.179.34.bc.googleusercontent.com): 2 in the last 3600 secs
show less
Web App Attack
๐บ๐ธ
WPJoe
2026-09-01 11:33:53
(10 hours ago)
34.179.208.227 - - [01/Sep/2026:11:33:52 +0000] "GET /.env.production HTTP/1.1" 403 4359 "-" "crusad ...
show more
34.179.208.227 - - [01/Sep/2026:11:33:52 +0000] "GET /.env.production HTTP/1.1" 403 4359 "-" "crusader-worker/1.0"
34.179.208.227 - - [01/Sep/2026:11:33:52 +0000] "GET /.env.old HTTP/1.1" 403 4360 "-" "crusader-worker/1.0"
...
show less
Web App Attack
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-01 11:08:55
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.179.208.227 (227.208.179.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.179.208.227 (227.208.179.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 07:08:50.530992 2026] [security2:error] [pid 25665:tid 25665] [client 34.179.208.227:59616] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "washburn-books.com"] [uri "/.env.save"] [unique_id "apayQks7-zk5hMEGN5EccAAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-01 10:50:01
(11 hours ago)
suspicious request in access.log
Web App Attack
๐ฉ๐ช
Hazzard
2026-09-01 10:13:28
(11 hours ago)
(mod_security) mod_security triggered on hostname [redacted]): (CF_ENABLE)
SQL Injection
๐ณ๐ฑ
e.fierstra
2026-09-01 10:08:28
(12 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 10:04:47
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.179.208.227 (227.208.179.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.179.208.227 (227.208.179.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 06:04:43.842938 2026] [security2:error] [pid 5916:tid 5916] [client 34.179.208.227:51832] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "united-kingdom-boat-registration.com"] [uri "/.env.production"] [unique_id "apajO20mJE7Z55lPIKd8MwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 09:34:54
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.179.208.227 (227.208.179.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.179.208.227 (227.208.179.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 05:34:46.628528 2026] [security2:error] [pid 29742:tid 29931] [client 34.179.208.227:50376] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "southerncalifornia.aafm.us"] [uri "/.env.dev"] [unique_id "apacNu_wdJAdgtQQjjxAigAAAZU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
MyGlobalFlowers
2026-09-01 09:33:29
(12 hours ago)
Multiple WAF Violations
Web App Attack
๐ฉ๐ช
yvoictra
2026-09-01 09:32:17
(12 hours ago)
Bloqueado automรกticamente por CrowdSec. Escenario: crowdsecurity/http-sensitive-files
Web App Attack
๐ซ๐ท
masterguru
2026-09-01 09:32:16
(12 hours ago)
Restricted File Access Attempt. Matched phrase ".env" at REQUEST_FILENAME. (930130-193)
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 08:35:20
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.179.208.227 (227.208.179.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.179.208.227 (227.208.179.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 04:35:16.603429 2026] [security2:error] [pid 29692:tid 29692] [client 34.179.208.227:57428] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "maldivesautismcentre.org"] [uri "/wp-config.php.swp"] [unique_id "apaORL4G0kUESkf8LVQWpgAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
big-cloud.nl
2026-09-01 08:15:49
(13 hours ago)
Try to access /.env
Web App Attack