🇨🇭
SOC [GOLINE SA]
2026-09-06 07:04:26
(5 hours ago)
FortiGate detected IPS attack from IPv4 address 34.48.93.253
Hacking
🇺🇸
Major Hostility
2026-09-06 06:23:18
(6 hours ago)
"GET /.env.dev HTTP/1.1" 404
"GET /.env.old HTTP/1.1" 404
Web App Attack
🇧🇾
lns.bz
2026-09-06 06:06:08
(6 hours ago)
.env scanning [BY]
Web App Attack
🇨🇦
SSH-Admin
2026-09-06 04:00:05
(8 hours ago)
Probing for Exploits on ns200
Exploited Host
Web App Attack
🇨🇦
SSH-Admin
2026-09-06 02:34:02
(10 hours ago)
Probing for Exploits on ns45
Exploited Host
Web App Attack
🇺🇸
WizardsToolkit
2026-09-06 02:04:16
(10 hours ago)
tried to access forbidden files; attempted to access /storage/logs/laravel.log
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 01:20:07
(11 hours ago)
(mod_security) mod_security (id:949110) triggered by 34.48.93.253 (253.93.48.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:949110) triggered by 34.48.93.253 (253.93.48.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 21:20:04.015136 2026] [security2:error] [pid 985:tid 985] [client 34.48.93.253:43404] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "thebealcompany.net.armstrongenvironmental.com"] [uri "/.env.dev"] [unique_id "apy_xFYAPX2oBvJl9K3riQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 00:48:39
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.48.93.253 (253.93.48.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.48.93.253 (253.93.48.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 20:48:33.188038 2026] [security2:error] [pid 28613:tid 28613] [client 34.48.93.253:51908] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.pundtlaw.com"] [uri "/.env.bak"] [unique_id "apy4YeGBV4v6z3DhKQ8ZpQAAACE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-06 00:30:32
(12 hours ago)
[ns31.kdns.gr] httpd-config-scan: sites=www.myrofores.gr; logs=/var/log/httpd/domains/myrofores.gr.l ...
show more
[ns31.kdns.gr] httpd-config-scan: sites=www.myrofores.gr; logs=/var/log/httpd/domains/myrofores.gr.log; samples=/.env.dev | /.env.example | /wp-config.php~
show less
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 23:56:02
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.48.93.253 (253.93.48.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.48.93.253 (253.93.48.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 19:55:54.304987 2026] [security2:error] [pid 23248:tid 23248] [client 34.48.93.253:49422] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autowinderband.tremulant.com"] [uri "/.env.example"] [unique_id "apysCs-4kGVP9fI6Qxe_yAAAACE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 23:13:52
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.48.93.253 (253.93.48.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.48.93.253 (253.93.48.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 19:13:45.410281 2026] [security2:error] [pid 17290:tid 17290] [client 34.48.93.253:35260] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "texascottagebakers.com"] [uri "/.env.save"] [unique_id "apyiKZMTvtkyAw8CZcVZwgAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇷🇺
cnaize
2026-09-05 23:12:30
(13 hours ago)
Malicious activity blocked by Meds firewall
Port Scan
🇳🇱
e.fierstra
2026-09-05 23:00:10
(13 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 22:56:26
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.48.93.253 (253.93.48.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.48.93.253 (253.93.48.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 18:56:21.656013 2026] [security2:error] [pid 27279:tid 27279] [client 34.48.93.253:48014] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.globalmonitoringinc.com"] [uri "/.env.example"] [unique_id "apyeFYCQnLekjny97nYKYwAAAEM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-05 22:54:47
(13 hours ago)
Blocked by ModSec and CSF
Port Scan