๐บ๐ธ
TPI-Abuse
2026-08-29 06:42:30
(1 minute ago)
(mod_security) mod_security (id:210492) triggered by 34.22.242.182 (182.242.22.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.22.242.182 (182.242.22.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 02:42:22.063557 2026] [security2:error] [pid 14714:tid 14714] [client 34.22.242.182:23634] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.harmonyexpos.com"] [uri "/@fs/.env"] [unique_id "apJ_Tqd8lp4JW1notkBpHAAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ท๐ด
iulianh
2026-08-29 05:42:42
(1 hour ago)
80,443
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2026-08-29 05:15:43
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.22.242.182 (182.242.22.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.22.242.182 (182.242.22.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 01:15:34.941407 2026] [security2:error] [pid 9706:tid 9706] [client 34.22.242.182:22430] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.mute-swan.com"] [uri "/@fs/.env"] [unique_id "apJq9q4f52ixCN5cQLrBoAAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
openstrike.co.uk
2026-08-29 05:13:58
(1 hour ago)
241 attacks on password grabbing URLs, config grabbing URLs (type 2), VC URLs, PHP URLs, env grabbin ...
show more
241 attacks on password grabbing URLs, config grabbing URLs (type 2), VC URLs, PHP URLs, env grabbing URLs, site downloads:
GET /_next/../.aws/credentials HTTP/1.1
GET /config/environment.json HTTP/1.1
GET /.git/config HTTP/1.1
GET /phpinfo.php HTTP/1.1
GET /frontend/.env.prod HTTP/1.1
GET /dump.sql HTTP/1.1
show less
Hacking
Web App Attack
๐ฉ๐ช
FD-IX
2026-08-29 05:07:22
(1 hour ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
๐ฉ๐ช
TheDjRider
2026-08-29 04:59:20
(1 hour ago)
CrowdSec detected Sensitive file or backup discovery attempt. Scenario: local/apache-sensitive-paths ...
show more
CrowdSec detected Sensitive file or backup discovery attempt. Scenario: local/apache-sensitive-paths. Automatic ban triggered. Detection time (UTC): 2026-08-29T04:59:18.046111327Z. Context: http_status=404
show less
Hacking
Web App Attack
๐ฉ๐ช
kommunos
2026-08-29 04:34:37
(2 hours ago)
/.env
Web App Attack
๐ฑ๐บ
SiteXL
2026-08-29 04:33:02
(2 hours ago)
Automated Fail2Ban detection: malicious activity observed; source IP was banned.
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-08-29 04:30:45
(2 hours ago)
Restricted File Access Attempt. Matched phrase ".env" at REQUEST_FILENAME. (930130-196)
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-29 03:48:36
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.22.242.182 (182.242.22.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.22.242.182 (182.242.22.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 23:48:32.276484 2026] [security2:error] [pid 4966:tid 4966] [client 34.22.242.182:1404] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.dimitri.daras.name"] [uri "/@fs/.env"] [unique_id "apJWkM0XbyCDacoP417ziQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-08-29 03:05:20
(3 hours ago)
Scanning/Probing (26)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-29 02:53:48
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.22.242.182 (182.242.22.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.22.242.182 (182.242.22.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 22:53:40.474586 2026] [security2:error] [pid 2855:tid 2855] [client 34.22.242.182:56776] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.reachpoint.com"] [uri "/@fs/root/.env"] [unique_id "apJJtKtrTiRqtvPkQAxSmwAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-08-29 02:08:44
(4 hours ago)
Restricted File Access Attempt. Matched phrase "/@fs/" at REQUEST_FILENAME. (930130-193)
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-29 01:50:24
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.22.242.182 (182.242.22.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.22.242.182 (182.242.22.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 21:50:07.528753 2026] [security2:error] [pid 16738:tid 16738] [client 34.22.242.182:48856] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.canaldumidi360.com"] [uri "/@fs/src/.env"] [unique_id "apI6zzl1Jlrf4vPWcTaVIgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฟ๐ฆ
conure.sh
2026-08-29 01:21:58
(5 hours ago)
csagent: score 20.0: secrets grab x2; 1 domain(s) in 5s
Web App Attack