Anonymous
2026-08-28 19:45:28
(40 minutes ago)
IP banned by Fail2Ban in jail nginx-abusive-ips
Web App Attack
Brute-Force
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-08-28 19:00:33
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.28.31.119 (119.31.28.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.28.31.119 (119.31.28.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 15:00:27.800391 2026] [security2:error] [pid 18096:tid 18096] [client 34.28.31.119:45766] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "rebeccapratt.com"] [uri "/.env.dev"] [unique_id "apHayxT0U7IpoxI1T5tSewAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
Celtic
2026-08-28 17:22:44
(3 hours ago)
Blocked by Fail2Ban with Jail (plesk-modsecurity)
Brute-Force
SSH
๐ง๐ท
Halux
2026-08-28 17:08:09
(3 hours ago)
34.28.31.119 Probing protected path or service
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 16:45:57
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.28.31.119 (119.31.28.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.28.31.119 (119.31.28.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 12:45:51.729857 2026] [security2:error] [pid 14861:tid 14861] [client 34.28.31.119:49850] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "socialstudiesforkids.com"] [uri "/.env"] [unique_id "apG7PxKKDXZJwN5UCf7LngAAACg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 16:14:05
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.28.31.119 (119.31.28.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.28.31.119 (119.31.28.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 12:13:57.500711 2026] [security2:error] [pid 29368:tid 29368] [client 34.28.31.119:42490] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.aoklandco.com.interforce.com"] [uri "/.env.example"] [unique_id "apGzxVUq7muiGOrFyV-tqwAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ต๐ฑ
Niko's Stuff
2026-08-28 15:51:17
(4 hours ago)
Triggered crowdsecurity/http-probing. More information at: https://app.crowdsec.net/cti/34.28.31.119
Web App Attack
Hacking
๐ฉ๐ช
4server
2026-08-28 15:09:32
(5 hours ago)
[FriAug2817:09:28.7716772026][security2:error][pid2816128:tid2816267][client34.28.31.119:0]ModSecuri ...
show more
[FriAug2817:09:28.7716772026][security2:error][pid2816128:tid2816267][client34.28.31.119:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Patternmatch\"\(\?i\)\(\?:/\(\?:\^\|/\)\\\\\\\\.\(env\|git\|svn\|hg\|DS_Store\)\|/\(\?:wp-config\|\\\\\\\\.htaccess\|\\\\\\\\.htpasswd\)\|\\\\\\\\.\(\?:sql\|bak\|old\|log\)\$\)\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"156\"][id\"960720\"][msg\"Forbiddenfileaccessattempt\"][severity\"CRITICAL\"][hostname\"ecosuber.com\"][uri\"/.env.bak\"][unique_id\"apGkqDOotZfbuszRgMrauwAAARg\"]
show less
Port Scan
Brute-Force
Web App Attack
Anonymous
2026-08-28 15:02:02
(5 hours ago)
Bot / scanning and/or hacking attempts: GET /.env.save HTTP/1.1, GET /.env.local HTTP/1.1, GET /.env ...
show more
Bot / scanning and/or hacking attempts: GET /.env.save HTTP/1.1, GET /.env.local HTTP/1.1, GET /.env.dev HTTP/1.1
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 14:32:56
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.28.31.119 (119.31.28.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.28.31.119 (119.31.28.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 10:32:51.971818 2026] [security2:error] [pid 19664:tid 19708] [client 34.28.31.119:51232] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.annastasiamason.com"] [uri "/.env.local"] [unique_id "apGcE3OzscTQeWZ4X8C58gAAAYw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 14:07:23
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.28.31.119 (119.31.28.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.28.31.119 (119.31.28.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 10:07:18.868622 2026] [security2:error] [pid 10250:tid 10250] [client 34.28.31.119:54592] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ecuablue.farm"] [uri "/.env.backup"] [unique_id "apGWFp66QQvSRYvPn9XWOAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-08-28 13:43:13
(6 hours ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 13:35:22
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.28.31.119 (119.31.28.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.28.31.119 (119.31.28.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 09:35:15.744784 2026] [security2:error] [pid 26394:tid 26394] [client 34.28.31.119:54338] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.built4ullc.com.jbcllcnet.com"] [uri "/.env.production"] [unique_id "apGOk8FQqoMHVT4D3NM7pAAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ธ๐ช
vaia.cloud
2026-08-28 13:35:06
(6 hours ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
Anonymous
2026-08-28 13:15:01
(7 hours ago)
suspicious request in access.log
Web App Attack