Anonymous
2026-08-01 17:24:40
(4 hours ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
π§π·
Halux
2026-08-01 17:19:54
(4 hours ago)
34.65.14.246 Probing protected path or service
Web App Attack
π©πͺ
FeG Deutschland
2026-08-01 17:18:11
(4 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-01 17:17:46
(4 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.65.14.246 (246.14.65.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.65.14.246 (246.14.65.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 13:17:37.916784 2026] [security2:error] [pid 848316:tid 848316] [client 34.65.14.246:47856] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.chick-p2.larryyang.net|F|2"] [data ".env.old"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.chick-p2.larryyang.net"] [uri "/.env.old"] [unique_id "am4qMZ5MQErZYtXzHpSKJwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-01 17:01:33
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.65.14.246 (246.14.65.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.65.14.246 (246.14.65.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 13:01:26.032426 2026] [security2:error] [pid 2518810:tid 2518810] [client 34.65.14.246:51548] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.planetezfind.timelord2067.com"] [uri "/.env.old"] [unique_id "am4mZtiKMCbk0sMmq8CmbgAAACU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
agenciahypelab.com.br
2026-08-01 16:30:53
(4 hours ago)
WordPress login brute-force detectado e bloqueado pelo CSF/LFD. Trigger: LF_TRIGGER
Brute-Force
SSH
π³π±
e.fierstra
2026-08-01 16:00:05
(5 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
Anonymous
2026-08-01 15:28:03
(5 hours ago)
Bot / scanning and/or hacking attempts: GET /.env.production HTTP/1.1, GET /.env HTTP/1.1, GET /.env ...
show more
Bot / scanning and/or hacking attempts: GET /.env.production HTTP/1.1, GET /.env HTTP/1.1, GET /.env.dev HTTP/1.1, GET /.env.prod HTTP/1.1, GET /.env.old HTTP/1.1, GET /.env.example HTTP/1.1, GET /.env.backup HTTP/1.1, GET /.env.local HTTP/1.1, GET /.env.bak HTTP/1.1, GET /.env.save HTTP/1.1
show less
Hacking
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-01 15:14:20
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.65.14.246 (246.14.65.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.65.14.246 (246.14.65.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 11:14:16.324059 2026] [security2:error] [pid 541784:tid 541784] [client 34.65.14.246:34878] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.cuneyt.kircali.net"] [uri "/.env.bak"] [unique_id "am4NSNJDISA2D6DxSoVOIwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π΅π±
itsvic.dev
2026-08-01 15:01:12
(6 hours ago)
34.65.14.246 - - [01/Aug/2026:15:01:11 +0000] "ha.itsvic.dev" "GET /.env.local HTTP/1.1" 404 14 "-" ...
show more
34.65.14.246 - - [01/Aug/2026:15:01:11 +0000] "ha.itsvic.dev" "GET /.env.local HTTP/1.1" 404 14 "-" "crusader-worker/1.0"
34.65.14.246 - - [01/Aug/2026:15:01:11 +0000] "ha.itsvic.dev" "GET /.env.backup HTTP/1.1" 404 14 "-" "crusader-worker/1.0"
34.65.14.246 - - [01/Aug/2026:15:01:11 +0000] "ha.itsvic.dev" "GET /.env.dev HTTP/1.1" 404 14 "-" "crusader-worker/1.0"
...
show less
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-01 14:13:24
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.65.14.246 (246.14.65.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.65.14.246 (246.14.65.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 10:13:19.059868 2026] [security2:error] [pid 709687:tid 709687] [client 34.65.14.246:57736] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "marshallcurry.com"] [uri "/.env.old"] [unique_id "am3-_-cGrW4mS_TkCGT5AwAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π±π»
garmtech.com
2026-08-01 13:53:43
(7 hours ago)
Attempted access to sensitive endpoint (/.env) detected. Automated scan or unauthorized probing.
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-01 13:33:15
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.65.14.246 (246.14.65.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.65.14.246 (246.14.65.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 09:33:07.041380 2026] [security2:error] [pid 561613:tid 561628] [client 34.65.14.246:51578] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.reclaimingspirituality.aafm.us"] [uri "/.env.backup"] [unique_id "am31k4uaOtnbGhbsEq13GQAAAE0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
WeCloudit-Anti-Abuse
2026-08-01 13:22:18
(8 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
πΊπΈ
TPI-Abuse
2026-08-01 13:16:46
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.65.14.246 (246.14.65.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.65.14.246 (246.14.65.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 09:16:42.355319 2026] [security2:error] [pid 1741:tid 1741] [client 34.65.14.246:36626] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.andrewweigel.andrew.weigel.name"] [uri "/.env.production"] [unique_id "am3xuvtVxKp7XCb7e5lGaAAAADA"]
show less
Brute-Force
Bad Web Bot
Web App Attack