๐บ๐ธ
TPI-Abuse
2026-09-01 06:05:34
(12 minutes ago)
(mod_security) mod_security (id:210492) triggered by 34.186.133.95 (95.133.186.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.186.133.95 (95.133.186.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 02:05:27.085525 2026] [security2:error] [pid 20085:tid 20193] [client 34.186.133.95:34136] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.ade-summers-photography.com"] [uri "/.env.production"] [unique_id "apZrJ22LTempPzhL_z44YwAAAQs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Hazzard
2026-09-01 05:21:16
(56 minutes ago)
(mod_security) mod_security triggered on hostname [redacted]): (CF_ENABLE)
SQL Injection
๐ฉ๐ช
LRob
2026-09-01 03:48:30
(2 hours ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /.env.production (+12 more) | 2026-09-01 03:48 UTC
show less
Hacking
Web App Attack
๐จ๐ฆ
polycoda
2026-09-01 03:27:25
(2 hours ago)
AutoBlock: ๐ฏ Vulnerability Scanner (Non Decay-Based) - โ๏ธ Configuration File Access (Non Decay-Based ...
show more
AutoBlock: ๐ฏ Vulnerability Scanner (Non Decay-Based) - โ๏ธ Configuration File Access (Non Decay-Based) - โ Excessive 40X Errors (Decay-Based)
show less
Hacking
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 03:01:12
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.186.133.95 (95.133.186.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.186.133.95 (95.133.186.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 23:01:08.093795 2026] [security2:error] [pid 10170:tid 10170] [client 34.186.133.95:59244] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kippert.com"] [uri "/.env.save"] [unique_id "apY_9MYAIX8Xz-1WZ3ulTgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Octopuce
2026-09-01 02:55:07
(3 hours ago)
Aggressive web search of vulnerable pages: /.env.backup /.env.old /.env.production /.env /.env.bak / ...
show more
Aggressive web search of vulnerable pages: /.env.backup /.env.old /.env.production /.env /.env.bak /.env.dev /.env.local /.env.example /wp-conf ...
show less
Web App Attack
Anonymous
2026-09-01 02:55:02
(3 hours ago)
suspicious request in access.log
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 02:38:59
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.186.133.95 (95.133.186.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.186.133.95 (95.133.186.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 22:38:51.355720 2026] [security2:error] [pid 31409:tid 31409] [client 34.186.133.95:49924] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.yevid.com"] [uri "/.env"] [unique_id "apY6u5M3PCjYnQ1zBH-n8AAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
consul.to
2026-09-01 02:26:07
(3 hours ago)
Web attack/malicious scanning detected
Web App Attack
Anonymous
2026-09-01 02:25:02
(3 hours ago)
Bot / scanning and/or hacking attempts: GET /.env.dev HTTP/1.1, GET /env HTTP/1.1, GET /actuator/con ...
show more
Bot / scanning and/or hacking attempts: GET /.env.dev HTTP/1.1, GET /env HTTP/1.1, GET /actuator/configprops HTTP/1.1, GET /wp-config.php.swp HTTP/1.1, GET /.env.old HTTP/1.1, GET /wp-config.php~ HTTP/1.1, GET /wp-config.php.bak HTTP/1.1, GET /.env.local HTTP/1.1, GET /.env.production HTTP/1.1, GET /.env.save HTTP/1.1, GET /.env HTTP/1.1, GET /_ignition/health-check HTTP/1.1, GET /.env.example HTTP/1.1, GET /.env.prod HTTP/1.1, GET /storage/logs/laravel.log HTTP/1.1, GET /actuator/env HTTP/1.1, GET /.env.bak HTTP/1.1
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 02:23:33
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.186.133.95 (95.133.186.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.186.133.95 (95.133.186.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 22:23:26.024694 2026] [security2:error] [pid 8926:tid 8926] [client 34.186.133.95:38038] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "goodmanhvac.savingshvac.com"] [uri "/wp-config.php.bak"] [unique_id "apY3HmW8byR13U8L6V7s-gAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-01 01:31:39
(4 hours ago)
[da.kdns.gr] httpd-config-scan: logs=/var/log/httpd/access_log; samples=/wp-config.php.bak | /wp-con ...
show more
[da.kdns.gr] httpd-config-scan: logs=/var/log/httpd/access_log; samples=/wp-config.php.bak | /wp-config.php.swp | /.env.dev
show less
Hacking
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-09-01 00:56:35
(5 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐ฉ๐ช
Philister11
2026-09-01 00:54:34
(5 hours ago)
CrowdSec: crowdsecurity/http-probing (US/AS396982)
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-01 00:48:54
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.186.133.95 (95.133.186.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.186.133.95 (95.133.186.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 20:48:46.738460 2026] [security2:error] [pid 13074:tid 13074] [client 34.186.133.95:36640] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "dakotagraphics.com"] [uri "/wp-config.php~"] [unique_id "apYg7jQ8TIVEjRfG4aCktQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack