Anonymous
2026-08-01 17:06:07
(14 minutes ago)
Trying to access config files
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-01 16:41:01
(39 minutes ago)
(mod_security) mod_security (id:210492) triggered by 34.20.236.1 (1.236.20.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.20.236.1 (1.236.20.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 12:40:54.512247 2026] [security2:error] [pid 511677:tid 511677] [client 34.20.236.1:35984] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.feaverslane.com"] [uri "/.env.example"] [unique_id "am4hlimNBVkrLu5ngLZLhQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
[email protected]
2026-08-01 16:40:28
(40 minutes ago)
Fail2Ban jail apache-json-scanners detected activity on 2026-08-01T16:40:28Z
Brute-Force
๐ฉ๐ช
4server
2026-08-01 16:33:43
(46 minutes ago)
[SatAug0118:33:41.6235402026][security2:error][pid1730179:tid1730242][client34.20.236.1:0]ModSecurit ...
show more
[SatAug0118:33:41.6235402026][security2:error][pid1730179:tid1730242][client34.20.236.1:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:5\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.10\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"jetfuel.ch.136-243-54-122.cpanel.site\"][uri\"/.env.dev\"][unique_id\"am4f5R43Osv8TwtWFOdpDgAAAII\"]
show less
Port Scan
Brute-Force
Web App Attack
๐บ๐ธ
aks4226
2026-08-01 16:18:17
(1 hour ago)
Bot search, attacking common web applications.
Web App Attack
๐บ๐ธ
[email protected]
2026-08-01 16:04:33
(1 hour ago)
Fail2Ban jail apache-json-scanners detected activity on 2026-08-01T16:04:32Z
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-08-01 16:03:39
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.20.236.1 (1.236.20.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.20.236.1 (1.236.20.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 12:03:32.926516 2026] [security2:error] [pid 388329:tid 388356] [client 34.20.236.1:53102] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "terratoolscorp.com"] [uri "/.env.old"] [unique_id "am4Y1K_ZX0Ma0o1LUa_POwAAANI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-01 15:51:54
(1 hour ago)
Blocked by ModSec and CSF
Port Scan
๐บ๐ธ
TPI-Abuse
2026-08-01 15:33:50
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.20.236.1 (1.236.20.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.20.236.1 (1.236.20.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 11:33:44.125024 2026] [security2:error] [pid 1915910:tid 1915910] [client 34.20.236.1:35990] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sabecocont.com"] [uri "/.env.example"] [unique_id "am4R2BCTfCd32ReLGB5xhwAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-08-01 15:29:26
(1 hour ago)
Restricted File Access Attempt. Matched phrase ".env" at REQUEST_FILENAME. (930130-195)
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-01 15:14:22
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.20.236.1 (1.236.20.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.20.236.1 (1.236.20.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 11:14:17.800585 2026] [security2:error] [pid 4047231:tid 4047231] [client 34.20.236.1:53600] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "reneehill.net"] [uri "/.env.old"] [unique_id "am4NSXiu5yPe8gQtpBXgWgAAADc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-08-01 14:59:26
(2 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-01 14:27:40
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.20.236.1 (1.236.20.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.20.236.1 (1.236.20.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 10:27:33.913229 2026] [security2:error] [pid 500566:tid 500566] [client 34.20.236.1:57228] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.acarsubscription.com"] [uri "/.env.prod"] [unique_id "am4CVQLATXaAkEd56UiHdwAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
[email protected]
2026-08-01 14:18:06
(3 hours ago)
Fail2Ban jail apache-json-scanners detected activity on 2026-08-01T14:18:06Z
Brute-Force
๐ซ๐ฎ
paissangroup
2026-08-01 14:16:34
(3 hours ago)
Multiple WAF Violations
Web App Attack