๐บ๐ธ
mnsf
2026-05-15 20:05:32
(1 month ago)
Scanning/Probing (20)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-15 09:31:20
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 34.182.232.203 (203.232.182.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.182.232.203 (203.232.182.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 15 05:31:13.559062 2026] [security2:error] [pid 14775:tid 14775] [client 34.182.232.203:47118] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "krugmans.org"] [uri "/.env.dev.local"] [unique_id "agbn4dQO_NwivqzF5U2IIQAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ท๐บ
DZBOT
2026-05-15 06:26:24
(1 month ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-15 04:20:32
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 34.182.232.203 (203.232.182.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.182.232.203 (203.232.182.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 15 00:20:26.179052 2026] [security2:error] [pid 24328:tid 24328] [client 34.182.232.203:39158] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bonvivantorganics.com"] [uri "/.env.local"] [unique_id "agafCgTE-pwSbUGbKx9pHgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-05-15 04:02:48
(1 month ago)
Restricted File Access Attempt. Matched phrase ".env" at REQUEST_FILENAME. (930130-193)
Hacking
Web App Attack
๐ซ๐ฎ
YF
2026-05-15 02:08:17
(1 month ago)
Environment file probe
Web App Attack
Anonymous
2026-05-15 00:59:36
(1 month ago)
(caddyscan) Scanner path probe from 34.182.232.203 (US/United States/203.232.182.34.bc.googleusercon ...
show more
(caddyscan) Scanner path probe from 34.182.232.203 (US/United States/203.232.182.34.bc.googleusercontent.com): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 2627 34.182.232.203 - - [15/May/2026:00:59:33 +0000] "GET /.env.development.local HTTP/1.1"
[REDACTED] 200 2627 34.182.232.203 - - [15/May/2026:00:59:33 +0000] "GET /admin/.env HTTP/1.1"
[REDACTED] 200 2627 34.182.232.203 - - [15/May/2026:00:59:33 +0000] "GET /app/.env HTTP/1.1"
[REDACTED] 200 2627 34.182.232.203 - - [15/May/2026:00:59:33 +0000] "GET /api/.env HTTP/1.1"
[REDACTED] 200 2627 34.182.232.203 - - [15/May/2026:00:59:33 +0000] "GET /.env.local HTTP/1.1"
show less
Port Scan
Anonymous
2026-05-15 00:55:03
(1 month ago)
suspicious request in access.log
Web App Attack
๐จ๐ญ
4server
2026-05-14 22:11:29
(1 month ago)
[FriMay1500:11:21.9913382026][security2:error][pid1845946:tid1845988][client34.182.232.203:0]ModSecu ...
show more
[FriMay1500:11:21.9913382026][security2:error][pid1845946:tid1845988][client34.182.232.203:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\".env\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"364\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"fimka-icp.com\"][uri\"/.env.local\"][unique_id\"agZIibJ2StVCQwRwsyY_AAAAAEM\"]
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-14 20:50:43
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 34.182.232.203 (203.232.182.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.182.232.203 (203.232.182.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 14 16:50:39.180957 2026] [security2:error] [pid 13645:tid 13645] [client 34.182.232.203:43992] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "stickittomebuttons.com"] [uri "/.env.local"] [unique_id "agY1n7jconX0UJ113fLKLgAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-05-14 19:05:56
(1 month ago)
Scanning/Probing (20)
Brute-Force
Web App Attack
๐ฉ๐ช
Ba-Yu
2026-05-14 18:39:54
(1 month ago)
General hacking/exploits/scanning
Web Spam
Hacking
Brute-Force
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-14 16:28:41
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 34.182.232.203 (203.232.182.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.182.232.203 (203.232.182.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 14 12:28:32.938552 2026] [security2:error] [pid 13325:tid 13325] [client 34.182.232.203:52926] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "leeu100.com"] [uri "/.env"] [unique_id "agX4MFkHeb2-crp5slJoVAAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-05-11 22:03:52
(1 month ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-05-10.
show less
Web App Attack
SSH
Hacking
๐ณ๐ฑ
homeshowdomain.nl
2026-05-10 22:00:54
(1 month ago)
Auto-ban: >3000 req/min op 2026-05-10
Web App Attack
SSH
Hacking