๐บ๐ธ
TPI-Abuse
2026-09-01 05:05:28
(7 minutes ago)
(mod_security) mod_security (id:210492) triggered by 34.39.215.217 (217.215.39.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.39.215.217 (217.215.39.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 01:05:24.635892 2026] [security2:error] [pid 5324:tid 5324] [client 34.39.215.217:51014] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.manatawnycreekfarm.com"] [uri "/.env.save"] [unique_id "apZdFBZQKJLXFN28sIUWGAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 02:41:34
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.39.215.217 (217.215.39.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.39.215.217 (217.215.39.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 22:41:29.417252 2026] [security2:error] [pid 13920:tid 13922] [client 34.39.215.217:57022] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.ainavelas.com"] [uri "/wp-config.php~"] [unique_id "apY7WSBYKdvcloMp0GTeZAAAAIA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 01:28:46
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.39.215.217 (217.215.39.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.39.215.217 (217.215.39.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 21:28:40.966018 2026] [security2:error] [pid 21828:tid 21828] [client 34.39.215.217:56182] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "dynamic-therapy-mn.com"] [uri "/.env"] [unique_id "apYqSLWDwZov1uH0S2MNXgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-01 01:26:11
(3 hours ago)
[server.dsamoodle.de] httpd-config-scan: sites=www.dsamoodle.de,www.dsamun.gr; logs=/var/log/httpd/d ...
show more
[server.dsamoodle.de] httpd-config-scan: sites=www.dsamoodle.de,www.dsamun.gr; logs=/var/log/httpd/domains/dsamoodle.de.log,/var/log/httpd/domains/dsamun.gr.log; samples=/.env.production | /.env.old | /.env.local
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 00:55:50
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.39.215.217 (217.215.39.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.39.215.217 (217.215.39.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 20:55:42.836126 2026] [security2:error] [pid 9297:tid 9335] [client 34.39.215.217:53982] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "degreesoflove.com.teritemme.com"] [uri "/.env.dev"] [unique_id "apYijoJpHo3M7Vb04yWpyAAAAYA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
MPL
2026-09-01 00:53:05
(4 hours ago)
tcp ports: 80,443 (76 or more attempts)
Port Scan
๐บ๐ธ
TPI-Abuse
2026-09-01 00:13:11
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.39.215.217 (217.215.39.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.39.215.217 (217.215.39.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 20:13:05.957384 2026] [security2:error] [pid 21585:tid 21585] [client 34.39.215.217:42218] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cowboyholidaycards.com"] [uri "/.env.old"] [unique_id "apYYkeZwRptJfTderKQQWQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-31 22:56:31
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.39.215.217 (217.215.39.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.39.215.217 (217.215.39.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 18:56:25.502817 2026] [security2:error] [pid 13980:tid 13980] [client 34.39.215.217:47276] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "brigittecavanagh.com"] [uri "/wp-config.php~"] [unique_id "apYGmYcb1-eZaNx2LJaFbgAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Vegascosmetics
2026-08-31 22:34:48
(6 hours ago)
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after sensitive config/credentials exposure ...
show more
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after sensitive config/credentials exposure probe. Evidence: AttackPattern: /\.env (Match: /.env)
show less
Hacking
Brute-Force
Web App Attack
Anonymous
2026-08-31 22:34:25
(6 hours ago)
Web App Attack
Brute-Force
Exploited Host
Web App Attack
๐ฉ๐ช
FD-IX
2026-08-31 22:33:58
(6 hours ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-31 22:20:18
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.39.215.217 (217.215.39.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.39.215.217 (217.215.39.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 18:20:10.679292 2026] [security2:error] [pid 1812:tid 1812] [client 34.39.215.217:45424] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.j3pr.com"] [uri "/.env.example"] [unique_id "apX-GuYjq24U_KzKpXDh6AAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ท๐ด
clauss
2026-08-31 22:07:15
(7 hours ago)
34.39.215.217 - - [01/Sep/2026:01:07:14 +0300] "GET /actuator/configprops HTTP/2.0" 404 37565 "-" "c ...
show more
34.39.215.217 - - [01/Sep/2026:01:07:14 +0300] "GET /actuator/configprops HTTP/2.0" 404 37565 "-" "crusader-worker/1.0"
34.39.215.217 - - [01/Sep/2026:01:07:14 +0300] "GET /actuator/env HTTP/2.0" 404 37569 "-" "crusader-worker/1.0"
...
show less
Web App Attack
๐ฉ๐ช
raph
2026-08-31 21:40:53
(7 hours ago)
[DOT FILES] crawler *.env*, .git*, .config*, etc.
Bad Web Bot
Web App Attack
๐ฎ๐น
VHosting
2026-08-31 21:40:04
(7 hours ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack