๐บ๐ธ
zcampbell
2026-08-29 03:09:47
(2 hours ago)
Web vulnerability scanning: probing for exposed sensitive files (.env). Detected and blocked automat ...
show more
Web vulnerability scanning: probing for exposed sensitive files (.env). Detected and blocked automatically.
show less
Web App Attack
Bad Web Bot
๐ฎ๐ช
AutosOnShow
2026-08-29 03:06:05
(2 hours ago)
blocked for webapp attack | path requested: / | seen at 2026-08-29 03:05:28.718 |
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-29 02:40:58
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.26.92.38 (38.92.26.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.26.92.38 (38.92.26.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 22:40:50.983490 2026] [security2:error] [pid 26223:tid 26223] [client 34.26.92.38:38390] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "styxwamworld.com"] [uri "/.env.save"] [unique_id "apJGsvN6TJWfMFXZSR-QlQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-29 01:37:00
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.26.92.38 (38.92.26.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.26.92.38 (38.92.26.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 21:36:52.490791 2026] [security2:error] [pid 31878:tid 31878] [client 34.26.92.38:47762] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "doctorspainmanagement.com"] [uri "/.env.example"] [unique_id "apI3tPII_ewwx8C_jQUrhgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
consul.to
2026-08-29 01:25:33
(4 hours ago)
Web attack/malicious scanning detected
Web App Attack
๐ฉ๐ช
Philister11
2026-08-29 00:09:03
(5 hours ago)
CrowdSec: crowdsecurity/http-probing (US/AS396982)
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-08-29 00:07:47
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.26.92.38 (38.92.26.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.26.92.38 (38.92.26.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 20:07:39.836843 2026] [security2:error] [pid 15429:tid 15429] [client 34.26.92.38:52498] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.bartholow.inetbrain.com"] [uri "/.env.dev"] [unique_id "apIiyyMdwHww9Kl_pCRvwgAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
BlueWire Hosting
2026-08-28 23:01:30
(6 hours ago)
Aggressive scanning resulting into 404
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-08-28 22:17:56
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.26.92.38 (38.92.26.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.26.92.38 (38.92.26.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 18:17:51.877624 2026] [security2:error] [pid 17744:tid 17744] [client 34.26.92.38:46250] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "borgeschiro.southtahoechurchofchrist.com"] [uri "/.env.dev"] [unique_id "apIJD3bUhClOnyacHSVYgwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Petros Stefanakis
2026-08-28 21:20:45
(8 hours ago)
(mod_security) mod_security triggered on hostname [redacted] 34.26.92.38 (US/United States/38.92.26. ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.26.92.38 (US/United States/38.92.26.34.bc.googleusercontent.com)
show less
SQL Injection
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-08-28 20:21:57
(9 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐จ๐ฆ
polycoda
2026-08-28 19:32:09
(10 hours ago)
AutoBlock: ๐ฏ Vulnerability Scanner (Non Decay-Based) - โช๏ธ Excessive 30X Errors (Decay-Based)
Hacking
Bad Web Bot
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-08-28 19:02:14
(10 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 19:00:07
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.26.92.38 (38.92.26.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.26.92.38 (38.92.26.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 14:59:59.221864 2026] [security2:error] [pid 3363342:tid 3363359] [client 34.26.92.38:51100] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.trillium-botanicals.anthonydalessandro.com"] [uri "/.env.prod"] [unique_id "apHar2-f09rsyFsPsuSD8wAAAUc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ธ๐ช
vaia.cloud
2026-08-28 18:45:43
(11 hours ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack