🇫🇷
Lunix
2026-09-06 06:36:35
(47 minutes ago)
Brute-Force
Web App Attack
🇩🇪
FD-IX
2026-09-06 03:53:18
(3 hours ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 03:49:25
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.39.159.187 (187.159.39.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.39.159.187 (187.159.39.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 23:49:19.379103 2026] [security2:error] [pid 28137:tid 28137] [client 34.39.159.187:47772] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.goalsnet.net"] [uri "/.env"] [unique_id "apzivyMEz77NfKJdg1dx2wAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 03:01:20
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.39.159.187 (187.159.39.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.39.159.187 (187.159.39.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 23:01:13.986056 2026] [security2:error] [pid 14519:tid 14519] [client 34.39.159.187:58292] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.rejuvenationresources.com"] [uri "/.env.dev"] [unique_id "apzXeU-JZhUSB9JMMh4WJAAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
Aetherweb Ark
2026-09-06 02:44:42
(4 hours ago)
(mod_security) mod_security (id:949110) triggered by 34.39.159.187 (BR/Brazil/187.159.39.34.bc.googl ...
show more
(mod_security) mod_security (id:949110) triggered by 34.39.159.187 (BR/Brazil/187.159.39.34.bc.googleusercontent.com): N in the last X secs
show less
Web App Attack
🇫🇷
masterguru
2026-09-06 02:39:17
(4 hours ago)
Restricted File Access Attempt. Matched phrase ".env" at REQUEST_FILENAME. (930130-197)
Hacking
Web App Attack
Anonymous
2026-09-06 02:07:03
(5 hours ago)
Automated web scanner. Requested suspicious paths: /.env.local | /.env.backup | /crusader-404-probe ...
show more
Automated web scanner. Requested suspicious paths: /.env.local | /.env.backup | /crusader-404-probe | /actuator/configprops | /.env | /.env.save | /.env.example | /storage/logs/laravel.log | /_ignition/health-check | /actuator/env | /.env.production | /.env.bak | /.env.dev | /.env.old | /env | /.env.prod. UTC: 2026-09-06 01:16:51.
show less
Web App Attack
🇫🇷
✨
2026-09-06 01:59:21
(5 hours ago)
Domain : membership.lake9.co.uk
Rule : env
2026-09-06 01:58:03 ***hidden-privacy*** GET /.env - 80 - ...
show more
Domain : membership.lake9.co.uk
Rule : env
2026-09-06 01:58:03 ***hidden-privacy*** GET /.env - 80 - 34.39.159.187 HTTP/1.1 crusader-worker/1.0 - membership.lake9.co.uk 403 501 0 1424 98 704 - -
show less
Hacking
SQL Injection
🇺🇸
TPI-Abuse
2026-09-06 01:55:36
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.39.159.187 (187.159.39.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.39.159.187 (187.159.39.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 21:55:31.214141 2026] [security2:error] [pid 14333:tid 14333] [client 34.39.159.187:54446] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "argcreativegroup.com"] [uri "/.env.bak"] [unique_id "apzIEzBxWwhcilJjvZU_VwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-06 01:37:03
(5 hours ago)
Web scanner: GET /.env.prod
Web App Attack
Hacking
🇩🇪
raph
2026-09-06 01:31:56
(5 hours ago)
[DOT FILES] crawler *.env*, .git*, .config*, etc.
Bad Web Bot
Web App Attack
🇩🇪
FeG Deutschland
2026-09-06 00:53:23
(6 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 00:47:46
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.39.159.187 (187.159.39.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.39.159.187 (187.159.39.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 20:47:39.099826 2026] [security2:error] [pid 2989:tid 2989] [client 34.39.159.187:57598] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.progressivefileshare.org"] [uri "/wp-config.php.swp"] [unique_id "apy4K4Lz7f0R-kjBXWwR_wAAACE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 00:01:45
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.39.159.187 (187.159.39.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.39.159.187 (187.159.39.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 20:01:38.706438 2026] [security2:error] [pid 1118:tid 1118] [client 34.39.159.187:40792] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kenirving.com"] [uri "/.env.old"] [unique_id "apytYtl_VDQckaej-m97QwAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-05 23:57:26
(7 hours ago)
(mod_security) mod_security triggered on hostname [redacted])
SQL Injection