Anonymous
2026-08-01 17:31:56
(5 hours ago)
[Sat Aug 01 19:31:56.347996 2026] [authz_core:error] [pid 116043] [client 34.50.78.216:50528] AH0163 ...
show more
[Sat Aug 01 19:31:56.347996 2026] [authz_core:error] [pid 116043] [client 34.50.78.216:50528] AH01630: client denied by server configuration: /var/www/html/portfolio/public/.env.example
[Sat Aug 01 19:31:56.352441 2026] [authz_core:error] [pid 118262] [client 34.50.78.216:50484] AH01630: client denied by server configuration: /var/www/html/portfolio/public/.env.backup
[Sat Aug 01 19:31:56.354951 2026] [authz_core:error] [pid 116028] [client 34.50.78.216:50492] AH01630: client denied by server configuration: /var/www/html/portfolio/public/.env.dev
[Sat Aug 01 19:31:56.357995 2026] [authz_core:error] [pid 116029] [client 34.50.78.216:50468] AH01630: client denied by server configuration: /var/www/html/portfolio/public/.env.bak
[Sat Aug 01 19:31:56.361627 2026] [authz_core:error] [pid 116033] [client 34.50.78.216:50520] AH01630: client denied by server configuration: /var/www/html/portfolio/public/.env
...
show less
Web App Attack
Anonymous
2026-08-01 17:31:04
(5 hours ago)
Bot / scanning and/or hacking attempts: GET /.env.example HTTP/1.1, GET /.env.old HTTP/1.1
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-01 17:29:19
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.50.78.216 (216.78.50.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.50.78.216 (216.78.50.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 13:29:14.578607 2026] [security2:error] [pid 2194412:tid 2194412] [client 34.50.78.216:33640] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.wisewerks.com"] [uri "/.env.local"] [unique_id "am4s6lHNRYcXrhc3_hMJ_gAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-01 17:04:55
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.50.78.216 (216.78.50.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.50.78.216 (216.78.50.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 13:04:50.130744 2026] [security2:error] [pid 2129535:tid 2129535] [client 34.50.78.216:33336] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "renperfco.com"] [uri "/.env.backup"] [unique_id "am4nMvCuxywCLA0fOubZ2AAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
enjoyably
2026-08-01 17:04:02
(5 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-08-01 16:43:16
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.50.78.216 (216.78.50.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.50.78.216 (216.78.50.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 12:43:10.351528 2026] [security2:error] [pid 492929:tid 492929] [client 34.50.78.216:45324] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "fitzcosound.com"] [uri "/.env.prod"] [unique_id "am4iHjDkJGcdw8jjSTveYAAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-01 16:42:59
(5 hours ago)
2026/08/01 13:42:59 [error] 2768715#2768715: *96293 access forbidden by rule, client: 34.50.78.216, ...
show more
2026/08/01 13:42:59 [error] 2768715#2768715: *96293 access forbidden by rule, client: 34.50.78.216, server: chat.sorotop.com.br, request: "GET /.env.local HTTP/1.1", host: "chat.sorotop.com.br"
2026/08/01 13:42:59 [error] 2768715#2768715: *96294 access forbidden by rule, client: 34.50.78.216, server: chat.sorotop.com.br, request: "GET /.env.example HTTP/1.1", host: "chat.sorotop.com.br"
2026/08/01 13:42:59 [error] 2768714#2768714: *96295 access forbidden by rule, client: 34.50.78.216, server: chat.sorotop.com.br, request: "GET /.env.dev HTTP/1.1", host: "chat.sorotop.com.br"
...
show less
Port Scan
Anonymous
2026-08-01 16:22:59
(6 hours ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
๐ท๐บ
DZBOT
2026-08-01 15:50:17
(6 hours ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
๐ซ๐ฎ
paissangroup
2026-08-01 15:49:49
(6 hours ago)
Multiple WAF Violations
Web App Attack
๐ฌ๐ง
Apache
2026-08-01 15:46:00
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.50.78.216 (ID/Indonesia/216.78.50.34.bc.goog ...
show more
(mod_security) mod_security (id:210492) triggered by 34.50.78.216 (ID/Indonesia/216.78.50.34.bc.googleusercontent.com): 5 in the last 300 secs (CF_ENABLE)
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-01 15:43:10
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.50.78.216 (216.78.50.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.50.78.216 (216.78.50.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 11:43:02.889219 2026] [security2:error] [pid 2343371:tid 2343371] [client 34.50.78.216:47054] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "harrisconcepts.com.coastalpirates.com"] [uri "/.env.old"] [unique_id "am4UBkB-OzAte2fFbCgtCgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Baking333
2026-08-01 15:40:04
(6 hours ago)
[redacted] 34.50.78.216 - - [01/Aug/2026:16:40:01 +0100] "GET /.[redacted] HTTP/1.1" 302 6763 0/2251 ...
show more
[redacted] 34.50.78.216 - - [01/Aug/2026:16:40:01 +0100] "GET /.[redacted] HTTP/1.1" 302 6763 0/225137 "-" "crusader-worker/1.0" [redacted] 34.50.78.216 - - [01/Aug/2026:16:40:01 +0100] "GET /.[redacted] HTTP/1.1" 302 6763 0/394282 "-" "crusader-worker/1.0"
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
iNetWorker
2026-08-01 15:35:28
(7 hours ago)
trolling for resource vulnerabilities
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-01 15:23:05
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.50.78.216 (216.78.50.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.50.78.216 (216.78.50.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 11:23:00.141985 2026] [security2:error] [pid 1228789:tid 1228789] [client 34.50.78.216:34430] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.app.fourminutedecision.com"] [uri "/.env.dev"] [unique_id "am4PVKBmkBB1YnTZ7Lu5GwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack