Anonymous
2026-09-06 06:15:36
(5 hours ago)
[ns41.kdns.gr] httpd-config-scan: logs=/var/log/httpd/access_log; samples=/.env.local | /.env | /.en ...
show more
[ns41.kdns.gr] httpd-config-scan: logs=/var/log/httpd/access_log; samples=/.env.local | /.env | /.env.bak
show less
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 02:26:11
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.185.74.174 (174.74.185.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.185.74.174 (174.74.185.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 22:26:05.785808 2026] [security2:error] [pid 22177:tid 22224] [client 34.185.74.174:45134] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "southsideeconomic.org"] [uri "/.env"] [unique_id "apzPPbFrBBBv6RD6KBcJsAAAAMo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇦🇺
A.i.D.A.N.N
2026-09-06 01:37:48
(10 hours ago)
A.i.D.A.N.N: Anomaly Detected - Signature match Web Service - Web vulnerability scanning detected
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 01:12:09
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.185.74.174 (174.74.185.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.185.74.174 (174.74.185.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 21:12:01.830535 2026] [security2:error] [pid 22966:tid 22966] [client 34.185.74.174:53568] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.auditleverage.com"] [uri "/.env.local"] [unique_id "apy94TEd6re15dUJU7nP3QAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
dynamix
2026-09-06 00:51:06
(10 hours ago)
Multiple WAF Violations
Web App Attack
Anonymous
2026-09-06 00:32:30
(11 hours ago)
2026/09/05 21:32:29 [error] 1371#1371: *88337 access forbidden by rule, client: 34.185.74.174, serve ...
show more
2026/09/05 21:32:29 [error] 1371#1371: *88337 access forbidden by rule, client: 34.185.74.174, server: blog.sorotop.com.br, request: "GET /.env.production HTTP/1.1", host: "blog.sorotop.com.br"
2026/09/05 21:32:29 [error] 1372#1372: *88341 access forbidden by rule, client: 34.185.74.174, server: blog.sorotop.com.br, request: "GET /.env.save HTTP/1.1", host: "blog.sorotop.com.br"
2026/09/05 21:32:29 [error] 1371#1371: *88336 access forbidden by rule, client: 34.185.74.174, server: blog.sorotop.com.br, request: "GET /.env.dev HTTP/1.1", host: "blog.sorotop.com.br"
...
show less
Port Scan
Anonymous
2026-09-05 23:59:50
(11 hours ago)
(mod_security) mod_security triggered on hostname [redacted] 34.185.74.174 (US/United States/174.74. ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.185.74.174 (US/United States/174.74.185.34.bc.googleusercontent.com)
show less
SQL Injection
🇺🇸
TPI-Abuse
2026-09-05 23:31:12
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.185.74.174 (174.74.185.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.185.74.174 (174.74.185.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 19:31:06.950942 2026] [security2:error] [pid 28877:tid 28877] [client 34.185.74.174:51716] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htaccess" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.taacorp.com"] [uri "/.htaccess"] [unique_id "apymOqJIlASdDlW58ydnMgAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
e.fierstra
2026-09-05 23:17:48
(12 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 23:08:19
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.185.74.174 (174.74.185.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.185.74.174 (174.74.185.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 19:08:14.128700 2026] [security2:error] [pid 8388:tid 8388] [client 34.185.74.174:45626] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "roughexports.velvetculture.com"] [uri "/wp-config.php.swp"] [unique_id "apyg3olqHGoJ4oyC0WH7gwAAAHw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
mnsf
2026-09-05 23:06:27
(12 hours ago)
Scanning/Probing (20)
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 22:51:01
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.185.74.174 (174.74.185.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.185.74.174 (174.74.185.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 18:50:54.980157 2026] [security2:error] [pid 14428:tid 14428] [client 34.185.74.174:34222] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "dusty-buggz.aisoftwaretools.com"] [uri "/.env.save"] [unique_id "apyczv2a9kbB51e5IH9Z9gAAAJU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 22:27:56
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.185.74.174 (174.74.185.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.185.74.174 (174.74.185.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 18:27:52.986497 2026] [security2:error] [pid 5311:tid 5311] [client 34.185.74.174:37702] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.garretthillary.com"] [uri "/.env.save"] [unique_id "apyXaBmAqA3YgDc75sVf_gAAADM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇧🇪
voormedia
2026-09-05 22:25:35
(13 hours ago)
Accessed trap at '/.env'
Web App Attack
🇺🇦
URAN Publishing Service
2026-09-05 22:03:17
(13 hours ago)
[06/Sep/2026:01:03:17 +0300] -- 34.185.74.174 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET / ...
show more
[06/Sep/2026:01:03:17 +0300] -- 34.185.74.174 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET /.env HTTP/1.1
show less
Bad Web Bot
Web App Attack