๐บ๐ธ
TPI-Abuse
2026-08-28 17:05:36
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.24.245.172 (172.245.24.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.24.245.172 (172.245.24.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 13:05:31.599612 2026] [security2:error] [pid 21098:tid 21098] [client 34.24.245.172:36814] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "rentkase.com"] [uri "/.env.backup"] [unique_id "apG_28jkmg9Micb_6HeJRwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-28 16:35:16
(6 hours ago)
Failed login attempt detected by Fail2Ban in plesk-modsecurity jail
Exploited Host
๐ฎ๐ฉ
Burayot
2026-08-28 16:26:28
(6 hours ago)
LF_MODSEC: (mod_security) mod_security (id:949110) triggered by 34.24.245.172 (US/United States/172. ...
show more
LF_MODSEC: (mod_security) mod_security (id:949110) triggered by 34.24.245.172 (US/United States/172.245.24.34.bc.googleusercontent.com): 2 in the last 3600 secs
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 16:22:06
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.24.245.172 (172.245.24.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.24.245.172 (172.245.24.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 12:21:58.993677 2026] [security2:error] [pid 2754589:tid 2754691] [client 34.24.245.172:54188] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "tomskrodzki.com"] [uri "/.env"] [unique_id "apG1pi1sB9VMuemgdcUzmQAAAZQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
joharikop
2026-08-28 15:56:03
(7 hours ago)
Nginx: credential/secret file probe (/.env, /.git, /.aws etc). Automated ban via fail2ban nginx-cred ...
show more
Nginx: credential/secret file probe (/.env, /.git, /.aws etc). Automated ban via fail2ban nginx-credential-probes jail.
show less
Web App Attack
๐จ๐ฆ
polycoda
2026-08-28 15:37:52
(7 hours ago)
AutoBlock: ๐ฏ Vulnerability Scanner (Non Decay-Based) - โ๏ธ Configuration File Access (Non Decay-Based ...
show more
AutoBlock: ๐ฏ Vulnerability Scanner (Non Decay-Based) - โ๏ธ Configuration File Access (Non Decay-Based) - โ Excessive 40X Errors (Decay-Based)
show less
Hacking
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 15:24:50
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.24.245.172 (172.245.24.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.24.245.172 (172.245.24.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 11:24:46.381146 2026] [security2:error] [pid 13836:tid 13836] [client 34.24.245.172:42580] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "archief.org"] [uri "/.env"] [unique_id "apGoPrgXSWqUT4dPHnM10wAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-08-28 15:05:51
(7 hours ago)
Scanning/Probing (30)
Brute-Force
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-08-28 15:02:34
(7 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐บ๐ธ
SLSLLC
2026-08-28 14:18:15
(8 hours ago)
34.24.245.172 - - [28/Aug/2026:14:18:13 +0000] "GET /.env HTTP/2.0" 403 1927 "-" "crusader-worker/1. ...
show more
34.24.245.172 - - [28/Aug/2026:14:18:13 +0000] "GET /.env HTTP/2.0" 403 1927 "-" "crusader-worker/1.0"
...
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 14:03:35
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.24.245.172 (172.245.24.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.24.245.172 (172.245.24.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 10:03:32.202513 2026] [security2:error] [pid 2610:tid 2610] [client 34.24.245.172:60054] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.merlinaerospace.com"] [uri "/.env.save"] [unique_id "apGVNIQ-jJM0aMFjsQFDuAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ธ๐ช
vaia.cloud
2026-08-28 13:35:05
(9 hours ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
๐ฉ๐ช
webanyone
2026-08-28 12:46:38
(10 hours ago)
WAF repeated trigger detected by Fail2Ban in plesk-modsecurity jail
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 12:46:17
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.24.245.172 (172.245.24.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.24.245.172 (172.245.24.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 08:46:10.211415 2026] [security2:error] [pid 28139:tid 28139] [client 34.24.245.172:41192] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "acmyles.com"] [uri "/.env.prod"] [unique_id "apGDElQiNld5zq1Hj3qEVgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-28 12:46:00
(10 hours ago)
Aggressive web scan
Bad Web Bot
Web App Attack