๐บ๐ธ
TPI-Abuse
2026-08-01 17:12:42
(11 minutes ago)
(mod_security) mod_security (id:210492) triggered by 34.52.208.230 (230.208.52.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.52.208.230 (230.208.52.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 13:12:35.463527 2026] [security2:error] [pid 2261292:tid 2261292] [client 34.52.208.230:33664] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "thewritekellys.com"] [uri "/.env.local"] [unique_id "am4pAz6DiN1iL3hcVs-5HAAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
big-cloud.nl
2026-08-01 17:05:22
(19 minutes ago)
Try to access /.env
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-01 16:41:09
(43 minutes ago)
(mod_security) mod_security (id:210492) triggered by 34.52.208.230 (230.208.52.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.52.208.230 (230.208.52.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 12:40:59.848345 2026] [security2:error] [pid 3008774:tid 3008774] [client 34.52.208.230:35362] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "partners.imagineyourphotos.com"] [uri "/.env.old"] [unique_id "am4hm2w0jdxrBEwl3pI6GwAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
alferez
2026-08-01 16:13:28
(1 hour ago)
Searching .(env|sql|zip|tar|rar) files
Hacking
Exploited Host
Web App Attack
๐บ๐ธ
paulo.apoloni
2026-08-01 16:09:22
(1 hour ago)
34.52.208.230 - - [01/Aug/2026:13:09:21 -0300] "GET /.env.production HTTP/1.1" 404 22 "-" "crusader- ...
show more
34.52.208.230 - - [01/Aug/2026:13:09:21 -0300] "GET /.env.production HTTP/1.1" 404 22 "-" "crusader-worker/1.0"
34.52.208.230 - - [01/Aug/2026:13:09:21 -0300] "GET /.env.local HTTP/1.1" 404 22 "-" "crusader-worker/1.0"
34.52.208.230 - - [01/Aug/2026:13:09:21 -0300] "GET /.env.example HTTP/1.1" 404 22 "-" "crusader-worker/1.0"
34.52.208.230 - - [01/Aug/2026:13:09:21 -0300] "GET /.env.dev HTTP/1.1" 404 22 "-" "crusader-worker/1.0"
34.52.208.230 - - [01/Aug/2026:13:09:21 -0300] "GET /.env.prod HTTP/1.1" 404 22 "-" "crusader-worker/1.0"
...
show less
Web App Attack
Anonymous
2026-08-01 15:52:38
(1 hour ago)
Reported from Nginx log analysis 11. Log: 34.52.208.230 - - [01/Aug/2026:xx:xx:xx 0200] "GET /.env. ...
show more
Reported from Nginx log analysis 11. Log: 34.52.208.230 - - [01/Aug/2026:xx:xx:xx 0200] "GET /.env.example HTTP/1.1" xxx xxx "-" "crusader-worker/1.0" "-" "BE Belgium Brussels" "AS396982" "Google LLC" | 34.52.208.230 - - [01/Aug/2026:xx:xx:xx 0200] "GET /.env.bak HTTP/1.1" xxx xxx "-" "crusader-worker/1.0" "-" "BE Belgium Brussels" "AS396982" "Google LLC" | 34.52.208.230 - - [01/Aug/2026:xx:xx:xx 0200] "GET /.env.old HTTP/1.1" xxx xxx "-" "crusader-worker/1.0" "-" "BE Belgium Brussels" "AS396982" "Google LLC" | 34.52.208.230 - - [01/Aug/2026:xx:xx:xx 0200] "GET /.env.save HTTP/1.1" xxx xxx "-" "crusader-worker/1.0" "-" "BE Belgium Brussels" "AS396982" "Google LLC" | 34.52.208.230 - - [01/Aug/2026:xx:xx:xx 0200] "GET /.env.dev HTTP/1.1" xxx xxx "-" "crusader-worker/1.0" "-" "BE Belgium Brussels" "AS396982" "Google LLC"
show less
Port Scan
Brute-Force
SSH
Anonymous
2026-08-01 15:00:36
(2 hours ago)
IP banned by Fail2Ban in jail nginx-abusive-ips
Web App Attack
Brute-Force
Bad Web Bot
๐ซ๐ท
dynamix
2026-08-01 14:52:44
(2 hours ago)
Multiple WAF Violations
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-08-01 14:17:14
(3 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-08-01 14:13:26
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.52.208.230 (230.208.52.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.52.208.230 (230.208.52.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 10:13:18.659172 2026] [security2:error] [pid 2251093:tid 2251093] [client 34.52.208.230:50328] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "southshorestreetrods.com.nashes.net"] [uri "/.env.old"] [unique_id "am3-_h-56l7dNCTLQu-mzwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
zynex
2026-08-01 13:57:23
(3 hours ago)
URL Probing: /.env
Web App Attack
๐ธ๐ช
vaia.cloud
2026-08-01 13:50:08
(3 hours ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-01 13:44:58
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.52.208.230 (230.208.52.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.52.208.230 (230.208.52.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 09:44:50.270033 2026] [security2:error] [pid 297898:tid 297898] [client 34.52.208.230:48196] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.karohali.chevronparkett.com"] [uri "/.env.production"] [unique_id "am34UmwrAja8EyBjspi80wAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-08-01 13:37:56
(3 hours ago)
Restricted File Access Attempt. Matched phrase ".env" at REQUEST_FILENAME. (930130-193)
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-01 13:03:02
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.52.208.230 (230.208.52.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.52.208.230 (230.208.52.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 09:02:55.258675 2026] [security2:error] [pid 1108641:tid 1108641] [client 34.52.208.230:43862] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.williambarfoot.com.lakesidedetectiveagency.com"] [uri "/.env.save"] [unique_id "am3uf3tZBQDKivAdBzg4tgAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack