Anonymous
2026-09-01 11:09:40
(3 hours ago)
GET /.env HTTP/1.1
...
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-01 11:03:26
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.7.172.173 (173.172.7.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.7.172.173 (173.172.7.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 07:03:19.934475 2026] [security2:error] [pid 20082:tid 20177] [client 34.7.172.173:53338] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.jomega.org"] [uri "/.env.bak"] [unique_id "apaw90zo3XFLOK5zIgB_EAAAAFQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
bescared
2026-09-01 11:00:54
(3 hours ago)
F2B - Malicious activity detected. URL Probing. -151302cd-
Hacking
Bad Web Bot
Web App Attack
π©πͺ
Petros Stefanakis
2026-09-01 11:00:40
(3 hours ago)
(mod_security) mod_security triggered on hostname [redacted] 34.7.172.173 (173.172.7.34.bc.googleuse ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.7.172.173 (173.172.7.34.bc.googleusercontent.com)
show less
SQL Injection
π±π»
garmtech.com
2026-09-01 10:56:12
(3 hours ago)
Attempted access to sensitive endpoint (/.env.prod) detected. Automated scan or unauthorized probing ...
show more
Attempted access to sensitive endpoint (/.env.prod) detected. Automated scan or unauthorized probing.
show less
Web App Attack
π«π·
masterguru
2026-09-01 09:33:03
(4 hours ago)
Restricted File Access Attempt. Matched phrase ".env" at REQUEST_FILENAME. (930130-197)
Hacking
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-01 08:32:05
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.7.172.173 (173.172.7.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.7.172.173 (173.172.7.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 04:31:58.539802 2026] [security2:error] [pid 15776:tid 15776] [client 34.7.172.173:43390] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "microdot.net"] [uri "/wp-config.php.bak"] [unique_id "apaNfg8wUXndFr9f2KxCHQAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
raph
2026-09-01 08:18:48
(6 hours ago)
[DOT FILES] crawler *.env*, .git*, .config*, etc.
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-01 08:16:09
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.7.172.173 (173.172.7.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.7.172.173 (173.172.7.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 04:16:01.832041 2026] [security2:error] [pid 3950:tid 3950] [client 34.7.172.173:58034] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "arogun.org"] [uri "/.env.dev"] [unique_id "apaJwfJ8zrrN7HhtcLYQIAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
gadix
2026-09-01 07:51:04
(6 hours ago)
[01/Sep/2026:09:51:01.791267 +0200] apaD5Q3hz6Imf7R6BX8mvwAAABU 34.7.172.173 32958 127.0.0.1 7081
[0 ...
show more
[01/Sep/2026:09:51:01.791267 +0200] apaD5Q3hz6Imf7R6BX8mvwAAABU 34.7.172.173 32958 127.0.0.1 7081
[01/Sep/2026:09:51:01.793278 +0200] apaD5TWwSoaWv5pLP3A1dwAAAAA 34.7.172.173 32974 127.0.0.1 7081
[01/Sep/2026:09:51:01.795371 +0200] apaD5dNV9h206aU8rzY6IwAAABQ 34.7.172.173 32978 127.0.0.1 7081
...
show less
Web App Attack
π¬π§
Apache
2026-09-01 07:45:40
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.7.172.173 (173.172.7.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.7.172.173 (173.172.7.34.bc.googleusercontent.com): 5 in the last 300 secs (CF_ENABLE)
show less
Brute-Force
Web App Attack
π©πͺ
SCHAPPY
2026-09-01 07:24:21
(7 hours ago)
Brute-force attack to non-existent web resources, HTTP code 404.
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-01 07:06:47
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.7.172.173 (173.172.7.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.7.172.173 (173.172.7.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 03:06:41.184891 2026] [security2:error] [pid 11262:tid 11289] [client 34.7.172.173:55322] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mirrorsimage.com"] [uri "/.env.local"] [unique_id "apZ5gZ71TID858fczemZCwAAAVQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-01 06:43:00
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.7.172.173 (173.172.7.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.7.172.173 (173.172.7.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 02:42:52.294423 2026] [security2:error] [pid 12043:tid 12043] [client 34.7.172.173:36656] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "swampoodlegrounds.com"] [uri "/wp-config.php~"] [unique_id "apZz7B-y80a3CISvaKgvSwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-01 05:05:45
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.7.172.173 (173.172.7.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.7.172.173 (173.172.7.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 01:05:37.560708 2026] [security2:error] [pid 717:tid 717] [client 34.7.172.173:49882] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.lakewyliehairsalon.com"] [uri "/.env.production"] [unique_id "apZdIWVxgt_VDvuuSEuRPwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack