๐บ๐ธ
TPI-Abuse
2026-07-31 17:26:42
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.26.1.51 (51.1.26.34.bc.googleusercontent.com ...
show more
(mod_security) mod_security (id:210492) triggered by 34.26.1.51 (51.1.26.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 31 13:26:35.242761 2026] [security2:error] [pid 849616:tid 849616] [client 34.26.1.51:49696] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ahijado.org"] [uri "/.env"] [unique_id "amzay5C5c79ziUWVPb2WHQAAAEU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-31 17:02:37
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.26.1.51 (51.1.26.34.bc.googleusercontent.com ...
show more
(mod_security) mod_security (id:210492) triggered by 34.26.1.51 (51.1.26.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 31 13:02:30.114912 2026] [security2:error] [pid 3379740:tid 3379754] [client 34.26.1.51:47962] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "accreditedfinancialanalyst.com"] [uri "/.env"] [unique_id "amzVJuvI59xyGJmh8L0JLAAAAIs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
cmbplf
2026-07-31 16:47:17
(16 hours ago)
608 requests with url.path *.env
Brute-Force
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-07-31 16:40:13
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.26.1.51 (51.1.26.34.bc.googleusercontent.com ...
show more
(mod_security) mod_security (id:210492) triggered by 34.26.1.51 (51.1.26.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 31 12:40:08.773675 2026] [security2:error] [pid 5713:tid 5713] [client 34.26.1.51:41216] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.handyrehab.zunosaki.com"] [uri "/.env"] [unique_id "amzP6F-9HpE2qGbTHpS6XAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
4server
2026-07-31 16:39:08
(16 hours ago)
[FriJul3118:39:03.6041412026][security2:error][pid3812722:tid3812937][client34.26.1.51:0]ModSecurity ...
show more
[FriJul3118:39:03.6041412026][security2:error][pid3812722:tid3812937][client34.26.1.51:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\".env\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"365\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"ticinosystem.ch.81-17-25-250.cpanel.site\"][uri\"/.env\"][unique_id\"amzPp6hBDkMDUljSOAHDtQAAAIs\"]
show less
Hacking
Web App Attack
๐บ๐ธ
anon333
2026-07-31 16:06:17
(17 hours ago)
Invalid probes to web server T1206
Hacking
Exploited Host
๐บ๐ธ
mnsf
2026-07-31 16:05:24
(17 hours ago)
Abuse Detected (10)
Brute-Force
Web App Attack
Anonymous
2026-07-31 15:50:01
(17 hours ago)
suspicious request in access.log
Web App Attack
๐ท๐บ
DZBOT
2026-07-31 15:42:19
(17 hours ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-31 15:39:13
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.26.1.51 (51.1.26.34.bc.googleusercontent.com ...
show more
(mod_security) mod_security (id:210492) triggered by 34.26.1.51 (51.1.26.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 31 11:39:08.074739 2026] [security2:error] [pid 874851:tid 874851] [client 34.26.1.51:44244] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "aticom.net.aticom.es"] [uri "/.env"] [unique_id "amzBnH_Smix-Rrwa828SkQAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-31 15:19:17
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.26.1.51 (51.1.26.34.bc.googleusercontent.com ...
show more
(mod_security) mod_security (id:210492) triggered by 34.26.1.51 (51.1.26.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 31 11:19:12.887250 2026] [security2:error] [pid 3205051:tid 3205051] [client 34.26.1.51:50842] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "frenosilent.com.ar"] [uri "/.env"] [unique_id "amy88KCw1c_-VWv_SIRBjAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-07-31 15:14:34
(17 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
๐ฉ๐ช
Holger
2026-07-31 14:59:10
(18 hours ago)
URL probing: GET /.env
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-31 14:54:43
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.26.1.51 (51.1.26.34.bc.googleusercontent.com ...
show more
(mod_security) mod_security (id:210492) triggered by 34.26.1.51 (51.1.26.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 31 10:54:39.000089 2026] [security2:error] [pid 889569:tid 889569] [client 34.26.1.51:52214] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cyber-matrix.org"] [uri "/.env"] [unique_id "amy3LpKZoqfvuw0AsgGCBwAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
OptimusGO
2026-07-31 14:49:21
(18 hours ago)
Malicious activity detected: web_attack
Server: commstackbc (185.127.18.66)
Attack: web_attack
Time ...
show more
Malicious activity detected: web_attack
Server: commstackbc (185.127.18.66)
Attack: web_attack
Timestamp: 2026-07-31 15:49:21 UTC
Log evidence:
34.26.1.51 - - [31/Jul/2026:15:49:21 +0100] "GET /.env HTTP/1.1" 404 146 "-" "crusader-worker/1.0"
07/31/2026-15:49:21.186532 [wDrop] [**] [1:1000110:2] SECURITY CRITICAL: .env File Access Attempt - INSTANT BAN [**] [Classification: Attempted Administrator Privilege Gain] [Priority: 1] {TCP} 34.26.1.51:43372 -> 185.127.18.66:80
07/31/2026-15:49:21.186532 [wDrop] [**] [1:7000911:2] FINSERV CRITICAL: Environment File Access [**] [Classification: Web Application Attack] [Priority: 1] {TCP} 34.26.1.51:43372 -> 185.127.18.66:80
show less
Port Scan
Brute-Force