๐บ๐ธ
TPI-Abuse
2026-09-01 05:09:23
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.19.134.64 (64.134.19.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.19.134.64 (64.134.19.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 01:09:19.767594 2026] [security2:error] [pid 6718:tid 6718] [client 34.19.134.64:44684] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.pinkrays.com"] [uri "/.env.dev"] [unique_id "apZd_-1udhY5aqfFRkzHkgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-09-01 04:47:48
(1 day ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐ณ๐ฑ
BlueWire Hosting
2026-09-01 04:42:30
(1 day ago)
Probing websites for vulnerabilities
Web App Attack
๐ฉ๐ช
Ano_Nym
2026-09-01 03:49:36
(1 day ago)
CrowdSec IDS alert on VPS 217.154.115.19 (DE). Scenario: crowdsecurity/http-probing
Web App Attack
๐ฌ๐ง
consul.to
2026-09-01 03:39:28
(1 day ago)
Web attack/malicious scanning detected
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-09-01 03:36:59
(1 day ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 02:48:47
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.19.134.64 (64.134.19.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.19.134.64 (64.134.19.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 22:48:39.695550 2026] [security2:error] [pid 31405:tid 31405] [client 34.19.134.64:54340] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jpwatters.net"] [uri "/.env.old"] [unique_id "apY9BwJT1wJfKPQeAhI3qQAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
mail.avx.gr
2026-09-01 02:44:57
(1 day ago)
(nginxENVSCAN) nginx environment-file scanner detected from 34.19.134.64 (CA/Canada/Quebec/Montreal/ ...
show more
(nginxENVSCAN) nginx environment-file scanner detected from 34.19.134.64 (CA/Canada/Quebec/Montreal/64.134.19.34.bc.googleusercontent.com)
show less
Hacking
๐ฉ๐ช
4server
2026-09-01 02:38:36
(1 day ago)
[TueSep0104:38:33.7186622026][security2:error][pid3534242:tid3534357][client34.19.134.64:0]ModSecuri ...
show more
[TueSep0104:38:33.7186622026][security2:error][pid3534242:tid3534357][client34.19.134.64:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:5\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.10\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"autodiscover.archi-box.ch\"][uri\"/.env.prod\"][unique_id\"apY6qXVQm_F0HgVdioA3jgAAAc8\"]
show less
Port Scan
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 02:30:19
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.19.134.64 (64.134.19.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.19.134.64 (64.134.19.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 22:30:14.975094 2026] [security2:error] [pid 2509:tid 2509] [client 34.19.134.64:50160] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "omahareact.org"] [uri "/.env.old"] [unique_id "apY4to3aQhLninQjsk81xwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-09-01 00:56:33
(2 days ago)
Restricted File Access Attempt. Matched phrase ".env" at REQUEST_FILENAME. (930130-197)
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 00:29:11
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.19.134.64 (64.134.19.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.19.134.64 (64.134.19.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 20:29:05.695520 2026] [security2:error] [pid 2930:tid 2930] [client 34.19.134.64:48518] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.picklebillystayandplay.com"] [uri "/.env.example"] [unique_id "apYcUSk-vbQT4_N1YBI3QwAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-09-01 00:15:15
(2 days ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 00:12:52
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.19.134.64 (64.134.19.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.19.134.64 (64.134.19.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 20:12:43.726073 2026] [security2:error] [pid 21585:tid 21585] [client 34.19.134.64:39722] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "countrywoodworking.net.bandsolution.net"] [uri "/.env.dev"] [unique_id "apYYe-ZwRptJfTderKQQUQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
bancix
2026-08-31 23:44:00
(2 days ago)
Heimdall NIDS: Automatic ban triggered. Reason: RST_LIMIT_EXCEEDED (5/5)
Port Scan