๐บ๐ธ
TPI-Abuse
2026-09-04 14:09:49
(4 weeks ago)
(mod_security) mod_security (id:210492) triggered by 34.65.223.223 (223.223.65.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.65.223.223 (223.223.65.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 10:09:42.487394 2026] [security2:error] [pid 812634:tid 812634] [client 34.65.223.223:34310] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.premiumenterprisessolution.com"] [uri "/.env.old"] [unique_id "aprRJm0AmiRGIDuZc0rHlgAAAJU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-04 13:26:55
(4 weeks ago)
(mod_security) mod_security (id:210492) triggered by 34.65.223.223 (223.223.65.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.65.223.223 (223.223.65.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 09:26:48.806566 2026] [security2:error] [pid 19608:tid 19608] [client 34.65.223.223:55166] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sparler.com"] [uri "/.env.example"] [unique_id "aprHGMfe3kv0d_olkLoB8gAAACQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-09-04 10:37:55
(4 weeks ago)
Restricted File Access Attempt. Matched phrase ".env" at REQUEST_FILENAME. (930130-201)
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-04 10:21:00
(4 weeks ago)
(mod_security) mod_security (id:210492) triggered by 34.65.223.223 (223.223.65.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.65.223.223 (223.223.65.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 06:20:53.422527 2026] [security2:error] [pid 16197:tid 16197] [client 34.65.223.223:37440] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "pacc.gormish.org"] [uri "/.env.old"] [unique_id "apqbhcwFJkVYLV8aZl3YUQAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Viveronese
2026-09-04 10:11:47
(4 weeks ago)
Wordpress vulnerability scanning
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-04 10:00:58
(4 weeks ago)
(mod_security) mod_security (id:210492) triggered by 34.65.223.223 (223.223.65.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.65.223.223 (223.223.65.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 06:00:54.276571 2026] [security2:error] [pid 22913:tid 22913] [client 34.65.223.223:58290] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.frontlinefirestop.com"] [uri "/wp-config.php~"] [unique_id "apqW1rukwHskckHj6cWwFAAAACI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
Aetherweb Ark
2026-09-04 09:53:05
(4 weeks ago)
(mod_security) mod_security (id:949110) triggered by 34.65.223.223 (CH/Switzerland/223.223.65.34.bc. ...
show more
(mod_security) mod_security (id:949110) triggered by 34.65.223.223 (CH/Switzerland/223.223.65.34.bc.googleusercontent.com): N in the last X secs
show less
Web App Attack
๐น๐ผ
kk_it_man
2026-09-04 09:23:03
(4 weeks ago)
ET INFO Request to Hidden Environment File - Inbound
ET WEB_SERVER Tilde in URI - potential .php~ ...
show more
ET INFO Request to Hidden Environment File - Inbound
ET WEB_SERVER Tilde in URI - potential .php~ source disclosure vulnerability
GPL WEB_SERVER 403 Forbidden
show less
Port Scan
๐ณ๐ฑ
MyGlobalFlowers
2026-09-04 08:39:26
(4 weeks ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-04 08:19:09
(4 weeks ago)
(mod_security) mod_security (id:210492) triggered by 34.65.223.223 (223.223.65.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.65.223.223 (223.223.65.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 04:19:01.661923 2026] [security2:error] [pid 15785:tid 15785] [client 34.65.223.223:33170] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.garrettkirkland.com"] [uri "/.env.local"] [unique_id "app-9XFsUd_vfPMfLfc92QAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
delabiemedia.be
2026-09-04 08:07:10
(4 weeks ago)
34.65.223.223 - - [04/Sep/2026:10:07:04 +0200] "GET /wp-config.php.bak HTTP/1.1" 404 162 "-" "crusad ...
show more
34.65.223.223 - - [04/Sep/2026:10:07:04 +0200] "GET /wp-config.php.bak HTTP/1.1" 404 162 "-" "crusader-worker/1.0"
34.65.223.223 - - [04/Sep/2026:10:07:04 +0200] "GET /wp-config.php.swp HTTP/1.1" 404 162 "-" "crusader-worker/1.0"
...
show less
Web App Attack
๐ฉ๐ช
raph
2026-09-04 08:00:54
(4 weeks ago)
[DOT FILES] crawler *.env*, .git*, .config*, etc.
Bad Web Bot
Web App Attack
๐จ๐ญ
zynex
2026-09-04 07:52:37
(4 weeks ago)
URL Probing: /.env
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-04 06:59:47
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 34.65.223.223 (223.223.65.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.65.223.223 (223.223.65.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 02:59:41.472519 2026] [security2:error] [pid 28764:tid 28764] [client 34.65.223.223:36352] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.innolympics.com"] [uri "/.env.old"] [unique_id "appsXSAHdZTmk5JguVwGeQAAACs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
zenmorro
2026-09-04 06:42:46
(1 month ago)
Honeypot hit (truenas:444) โ scanner-path: /actuator/env. Automated report from honeypot infrastruct ...
show more
Honeypot hit (truenas:444) โ scanner-path: /actuator/env. Automated report from honeypot infrastructure
show less
Port Scan
Web App Attack