🇺🇸
JustMeHere
2026-09-06 06:15:48
(6 days ago)
[Sun Sep 06 02:15:44.329909 2026] [security2:error] [pid 52851:tid 52976] [client 34.65.77.12:52186] ...
show more
[Sun Sep 06 02:15:44.329909 2026] [security2:error] [pid 52851:tid 52976] [client 34.65.77.12:52186] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:blocking_inbound_anomaly_score. [file "/etc/httpd/modsecurity.d/activated_rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "233"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 8)"] [ver "OWASP_CRS/4.15.0"] [tag "anomaly-evaluation"] [tag "OWASP_CRS"] [hostname "73.88.79.72"] [uri "/.env"] [unique_id "ap0FEA1L11jfIFSviomlywAAAEg"]
...
show less
Web App Attack
🇬🇧
openstrike.co.uk
2026-09-06 05:13:12
(6 days ago)
13 attacks on env grabbing URLs, PHP URLs:
GET /.env.backup HTTP/1.1
GET /wp-config.php.swp HTTP/1.1
Hacking
Web App Attack
🇩🇪
raph
2026-09-06 02:44:24
(6 days ago)
[DOT FILES] crawler *.env*, .git*, .config*, etc.
Bad Web Bot
Web App Attack
🇩🇪
NewGastroline
2026-09-06 01:34:10
(6 days ago)
Malicious request blocked by CrowdSec on gastro-prod1.boreus.de
Bad Web Bot
Web App Attack
🇩🇪
FeG Deutschland
2026-09-06 01:11:22
(6 days ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
🇬🇧
relianoid.com
2026-09-06 00:53:29
(6 days ago)
404 Errors Abuse detected by Relianoid OSS Load Balancer - relianoid.com
Web App Attack
🇺🇸
mw
2026-09-06 00:50:01
(6 days ago)
GET /.env.production HTTP/1.1
Web App Attack
🇩🇪
YF
2026-09-05 21:00:16
(6 days ago)
WordPress config file probe
Web App Attack
🇧🇾
lns.bz
2026-09-05 06:59:46
(1 week ago)
Too many 404 requests [BY]
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 15:14:36
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.65.77.12 (12.77.65.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.65.77.12 (12.77.65.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 11:14:30.229061 2026] [security2:error] [pid 31095:tid 31095] [client 34.65.77.12:37388] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.bikiniwatersports.com"] [uri "/.env.bak"] [unique_id "aprgVjMBQlKGbL_GMYwkQQAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
Apache
2026-09-04 14:55:47
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.65.77.12 (CH/Switzerland/12.77.65.34.bc.goog ...
show more
(mod_security) mod_security (id:210492) triggered by 34.65.77.12 (CH/Switzerland/12.77.65.34.bc.googleusercontent.com): 5 in the last 300 secs (CF_ENABLE)
show less
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 14:35:51
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.65.77.12 (12.77.65.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.65.77.12 (12.77.65.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 10:35:47.899584 2026] [security2:error] [pid 28778:tid 28778] [client 34.65.77.12:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "demondomain.com"] [uri "/.env.production"] [unique_id "aprXQ_pAFCxFrG2r-MmtQQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 14:10:58
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.65.77.12 (12.77.65.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.65.77.12 (12.77.65.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 10:10:54.486263 2026] [security2:error] [pid 3074853:tid 3074958] [client 34.65.77.12:48250] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.richardleeweatherman.com"] [uri "/.env.old"] [unique_id "aprRbhBOMVLn240jkbtetAAAAQM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
FD-IX
2026-09-04 14:08:04
(1 week ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 12:40:08
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.65.77.12 (12.77.65.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.65.77.12 (12.77.65.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 08:39:56.537952 2026] [security2:error] [pid 31784:tid 31784] [client 34.65.77.12:50976] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "safwalu.com"] [uri "/.env.dev"] [unique_id "apq8HAN-GWho6ofLmMUnDgAAACg"]
show less
Brute-Force
Bad Web Bot
Web App Attack