๐บ๐ธ
craudiovizai
2026-09-22 18:30:34
(1 hour ago)
Automated honeypot detection. blocked ip against a Next.js application. Paths: /.env.bak, /actuator/ ...
show more
Automated honeypot detection. blocked ip against a Next.js application. Paths: /.env.bak, /actuator/env. Blocked at the edge.
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-22 16:53:47
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.65.116.235 (235.116.65.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.65.116.235 (235.116.65.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 12:53:43.143615 2026] [security2:error] [pid 3921:tid 3921] [client 34.65.116.235:40876] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sarahgrammer.com"] [uri "/.env.old"] [unique_id "arKyl5GEEiVOACivNlW-pAAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
nyt
2026-09-22 15:16:50
(4 hours ago)
Sensitive File Probe
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 14:57:59
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.65.116.235 (235.116.65.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.65.116.235 (235.116.65.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 10:57:54.847020 2026] [security2:error] [pid 7933:tid 7970] [client 34.65.116.235:37852] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.transiit.org"] [uri "/.env.dev"] [unique_id "arKXcqYtTkFWwP-GXBfUpQAAAQY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-22 14:52:19
(5 hours ago)
(mod_security) mod_security triggered on hostname [redacted])
SQL Injection
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-09-22 14:50:15
(5 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-22 13:32:47
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.65.116.235 (235.116.65.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.65.116.235 (235.116.65.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 09:32:40.312264 2026] [security2:error] [pid 7665:tid 7665] [client 34.65.116.235:48644] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "gunningphysio.com"] [uri "/.env.local"] [unique_id "arKDeHAaQoztK1Ts8jWRhQAAADI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
mondor.ro
2026-09-22 13:17:20
(6 hours ago)
Cluster member 148.251.176.225 (DE/Germany/antares.webyouridea.ro) said, DENY 34.65.116.235, Reason: ...
show more
Cluster member 148.251.176.225 (DE/Germany/antares.webyouridea.ro) said, DENY 34.65.116.235, Reason:[(mod_security) mod_security (id:210492) triggered by 34.65.116.235 (CH/Switzerland/235.116.65.34.bc.googleusercontent.com): 3 in the last 3600 secs]; Ports: *; Direction: inout; Trigger: LF_CLUSTER; Logs:
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-09-22 13:10:36
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.65.116.235 (235.116.65.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.65.116.235 (235.116.65.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 09:10:31.481843 2026] [security2:error] [pid 721915:tid 721915] [client 34.65.116.235:47666] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "flatontaylor.com"] [uri "/.env"] [unique_id "arJ-R8nyD6iUMiF-LpN8gQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-22 13:05:20
(7 hours ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
๐ณ๐ฑ
Alt255
2026-09-22 12:14:23
(7 hours ago)
[ti-03tr] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-03tr] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 34.65.116.235 - - [22/Sep/2026:14:14:01 +0200] "GET /.env.local HTTP/1.1" 403 6267 "-" "crusader-worker/1.0"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 11:42:58
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.65.116.235 (235.116.65.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.65.116.235 (235.116.65.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 07:42:52.957435 2026] [security2:error] [pid 28175:tid 28175] [client 34.65.116.235:45890] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cookwithjohnnyb.com.burlison.com"] [uri "/.env.dev"] [unique_id "arJpvO40VGg-N6VM3VXTdgAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-09-22 11:34:40
(8 hours ago)
Multiple WAF Violations
Web App Attack
๐ฟ๐ฆ
conure.sh
2026-09-22 11:22:34
(8 hours ago)
csagent: score 19.9: secrets grab x1, wp-config backup grab x1; 1 domain(s) in 1s
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 10:58:08
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.65.116.235 (235.116.65.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.65.116.235 (235.116.65.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 06:58:04.155366 2026] [security2:error] [pid 11500:tid 11500] [client 34.65.116.235:48240] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.diarrheawolves.com"] [uri "/.env.bak"] [unique_id "arJfPPEWZLUtq0rASciqcQAAACM"]
show less
Brute-Force
Bad Web Bot
Web App Attack