Anonymous
2026-08-01 17:35:03
(16 hours ago)
suspicious request in access.log
Web App Attack
๐ฉ๐ช
ger-stg-sifi1
2026-08-01 17:23:48
(16 hours ago)
(wordpress) Failed wordpress login using wp-login.php or xmlrpc.php
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-01 16:57:02
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.73.162.71 (71.162.73.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.73.162.71 (71.162.73.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 12:56:58.454416 2026] [security2:error] [pid 2512187:tid 2512187] [client 34.73.162.71:58630] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.anchordown.jbaydeliveries.com"] [uri "/.env.prod"] [unique_id "am4lWoaPX_PPXE7ofkXUhAAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-01 16:32:43
(17 hours ago)
Sensitive file access attempt
Hacking
๐บ๐ธ
mnsf
2026-08-01 16:05:27
(17 hours ago)
Scanning/Probing (14)
Brute-Force
Web App Attack
๐ฉ๐ช
XICTRON
2026-08-01 15:35:09
(18 hours ago)
ModSecurity rule violation detected by Fail2Ban
Web App Attack
๐ซ๐ท
masterguru
2026-08-01 15:31:33
(18 hours ago)
Restricted File Access Attempt. Matched phrase ".env" at REQUEST_FILENAME. (930130-193)
Hacking
Web App Attack
๐ฎ๐น
Inartis
2026-08-01 15:19:36
(18 hours ago)
34.73.162.71 - - [01/Aug/2026:17:19:34 +0200] "GET /.env.old HTTP/1.1" 403 4736 "-" "crusader-worker ...
show more
34.73.162.71 - - [01/Aug/2026:17:19:34 +0200] "GET /.env.old HTTP/1.1" 403 4736 "-" "crusader-worker/1.0"
34.73.162.71 - - [01/Aug/2026:17:19:35 +0200] "GET /.env.local HTTP/1.1" 302 453 "-" "crusader-worker/1.0"
34.73.162.71 - - [01/Aug/2026:17:19:35 +0200] "GET /.env HTTP/1.1" 302 441 "-" "crusader-worker/1.0"
...
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-01 15:11:17
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.73.162.71 (71.162.73.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.73.162.71 (71.162.73.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 11:11:10.789790 2026] [security2:error] [pid 142394:tid 142394] [client 34.73.162.71:58082] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "nrvoutdoors.com"] [uri "/.env.old"] [unique_id "am4MjpiFoqmFI287nf2gBQAAACE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ฆ
polycoda
2026-08-01 14:57:05
(18 hours ago)
AutoBlock: ๐ฏ Vulnerability Scanner (Non Decay-Based)
Hacking
Web App Attack
๐ซ๐ท
masterguru
2026-08-01 14:51:11
(18 hours ago)
Restricted File Access Attempt. Matched phrase ".env" at REQUEST_FILENAME. (930130-201)
Hacking
Web App Attack
๐ซ๐ท
dwmp
2026-08-01 14:27:36
(19 hours ago)
[01/Aug/2026:16:27:35.990525 +0200] am4CV31mAkoibV9Tv7W5NQAAAFI 34.73.162.71 52052 38.242.227.117 70 ...
show more
[01/Aug/2026:16:27:35.990525 +0200] am4CV31mAkoibV9Tv7W5NQAAAFI 34.73.162.71 52052 38.242.227.117 7081
[01/Aug/2026:16:27:35.990823 +0200] am4CVwe9srC7DFKRoHL5SQAAABY 34.73.162.71 52038 38.242.227.117 7081
[01/Aug/2026:16:27:35.991079 +0200] am4CV31mAkoibV9Tv7W5NgAAAEo 34.73.162.71 52044 38.242.227.117 7081
...
show less
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2026-08-01 14:19:04
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.73.162.71 (71.162.73.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.73.162.71 (71.162.73.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 10:18:57.103301 2026] [security2:error] [pid 2017868:tid 2017868] [client 34.73.162.71:37250] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.recreationwebsites.brushmileage.org"] [uri "/.env.dev"] [unique_id "am4AUXiwEW3LWzLvyBWV-wAAAHA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
4server
2026-08-01 14:15:39
(19 hours ago)
[SatAug0116:15:35.8836292026][security2:error][pid3806177:tid3806405][client34.73.162.71:0]ModSecuri ...
show more
[SatAug0116:15:35.8836292026][security2:error][pid3806177:tid3806405][client34.73.162.71:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\".env\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"365\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"www.copertureamovibili.ch.81-17-25-250.cpanel.site\"][uri\"/.env.save\"][unique_id\"am3_h-zNqjShiI6UbOJKTAAAAUY\"]
show less
Hacking
Web App Attack
๐ฌ๐ง
consul.to
2026-08-01 13:32:39
(20 hours ago)
Web attack/malicious scanning detected
Web App Attack