๐บ๐ธ
TPI-Abuse
2026-08-31 23:12:49
(10 minutes ago)
(mod_security) mod_security (id:210492) triggered by 34.65.152.141 (141.152.65.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.65.152.141 (141.152.65.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 19:12:44.958007 2026] [security2:error] [pid 8570:tid 8570] [client 34.65.152.141:52014] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "burnshieldmena.com"] [uri "/.env.old"] [unique_id "apYKbBEci8eWEANGyX5-TwAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
janbro
2026-08-31 22:44:32
(39 minutes ago)
Automated attempt to access sensitive configuration files.
Port Scan
Hacking
Web App Attack
๐ณ๐ฑ
Roderic
2026-08-31 22:43:46
(40 minutes ago)
(mod_security) mod_security triggered on hostname [redacted])
SQL Injection
๐บ๐ธ
TPI-Abuse
2026-08-31 22:39:11
(44 minutes ago)
(mod_security) mod_security (id:210492) triggered by 34.65.152.141 (141.152.65.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.65.152.141 (141.152.65.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 18:39:06.639274 2026] [security2:error] [pid 16384:tid 16384] [client 34.65.152.141:38314] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bentonflybox.com"] [uri "/wp-config.php.swp"] [unique_id "apYCih7wC_C6Q0y9XQrGwwAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
VHosting
2026-08-31 22:20:04
(1 hour ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-31 22:18:56
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.65.152.141 (141.152.65.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.65.152.141 (141.152.65.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 18:18:49.409732 2026] [security2:error] [pid 10280:tid 10280] [client 34.65.152.141:45904] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.babycatkhalil.com"] [uri "/.env.prod"] [unique_id "apX9ybuyiIDTflUpGmJlCAAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
boxed-it
2026-08-31 22:10:50
(1 hour ago)
GET /.env (Tarpitted for 2m10s, wasted 7.73kB)
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-08-31 22:05:51
(1 hour ago)
[01/Sep/2026:01:05:50 +0300] -- 34.65.152.141 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.env ...
show more
[01/Sep/2026:01:05:50 +0300] -- 34.65.152.141 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.env.prod HTTP/1.1
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
raph
2026-08-31 21:54:06
(1 hour ago)
[Wordpress] crawler /wp-admin/*, /wp-content/*, etc.
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-31 21:46:38
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.65.152.141 (141.152.65.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.65.152.141 (141.152.65.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 17:46:34.369756 2026] [security2:error] [pid 29495:tid 29495] [client 34.65.152.141:56628] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "anthearodgers.com"] [uri "/.env"] [unique_id "apX2Oh_ZroqbSUG7iCutdwAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ธ๐ช
vaia.cloud
2026-08-31 21:45:03
(1 hour ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-08-31 21:34:20
(1 hour ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
๐ณ๐ฑ
e.fierstra
2026-08-31 16:26:28
(6 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack