Anonymous
2026-06-15 08:42:16
(8 hours ago)
Multiple web server 400 error codes from same source ip
Web App Attack
๐ฌ๐ง
openstrike.co.uk
2026-06-15 05:13:56
(11 hours ago)
151 attacks on env grabbing URLs:
GET /sendgrid/.env.prod HTTP/1.1
Hacking
๐ท๐บ
DZBOT
2026-06-15 04:26:39
(12 hours ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-15 04:06:04
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.19.202.14 (14.202.19.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.19.202.14 (14.202.19.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 15 00:05:56.567548 2026] [security2:error] [pid 22552:tid 22552] [client 34.19.202.14:58432] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "leesart.org"] [uri "/.env.prod.bak"] [unique_id "ai96JBDt7KL88vOtyB9-PwAAADc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-15 03:27:11
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.19.202.14 (14.202.19.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.19.202.14 (14.202.19.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 23:27:06.914667 2026] [security2:error] [pid 11692:tid 11695] [client 34.19.202.14:53860] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.atlasrecordssearch.com.venezuelaguia.com"] [uri "/.env.txt"] [unique_id "ai9xChnntfI0eOF6-sTELAAAAUE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
pipeline.es
2026-06-15 02:50:24
(14 hours ago)
Web scanning / probing for vulnerable paths | URL: /config/sendgrid.env | Evidence: agc.orbishoteles ...
show more
Web scanning / probing for vulnerable paths | URL: /config/sendgrid.env | Evidence: agc.orbishoteles.com 34.19.202.14 - - [15/Jun/2026:04:49:57 +0200] \"GET /config/sendgrid.env HTTP/1.1\" 404 3904 \"-\" \"HTC_Dream Mozilla/5.0 (Linux; U; Android 1.5; en-ca; Build/CUPCAKE) AppleWebKit/528.5 (KHTML, like Gecko) Version/3.1.2 Mobile Safari/525.20.1\" GEOIP_COUNTRY_CODE=CA | ASN: GOOGLE-CLOUD-PLATFORM | Country: CA
show less
Port Scan
Web App Attack
๐ซ๐ท
COMAITE
2026-06-15 01:06:55
(15 hours ago)
Suspicious URL access.
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-14 22:38:36
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.19.202.14 (14.202.19.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.19.202.14 (14.202.19.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 18:38:31.852482 2026] [security2:error] [pid 3800:tid 3800] [client 34.19.202.14:45760] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bacpool.com"] [uri "/.env.dev"] [unique_id "ai8tZ2z6cd6INpynQ5SeOQAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-06-14 19:50:31
(21 hours ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
NXTwoThou
2026-06-14 19:25:07
(21 hours ago)
/.env
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-14 07:08:20
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.19.202.14 (14.202.19.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.19.202.14 (14.202.19.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 03:08:14.068170 2026] [security2:error] [pid 24073:tid 24073] [client 34.19.202.14:53106] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "donutlocations.com"] [uri "/.env.stage"] [unique_id "ai5TXre8q2n9KSkOt1BpHgAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
VHosting
2026-06-14 05:50:03
(1 day ago)
Detected WordPress attack from 4 different servers
Brute-Force
Web App Attack
๐จ๐ญ
Origon
2026-06-14 03:59:27
(1 day ago)
http-bad-user-agent - IP: 34.19.202.14 - time="2026-06-14T05:59:26+02:00" level=info msg="(555f66b4 ...
show more
http-bad-user-agent - IP: 34.19.202.14 - time="2026-06-14T05:59:26+02:00" level=info msg="(555f66b4f6a74558bc11e3f93469658es8App0Mcc0TKEeje/crowdsec) crowdsecurity/http-bad-user-agent by ip 34.19.202.14 (CA/396982) : 4h ban on Ip 34.19.202.14" module=db
show less
Bad Web Bot