๐ณ๐ฑ
maxxsense
2026-06-09 20:12:47
(1 hour ago)
(mod_security) mod_security triggered on hostname [redacted] 34.80.148.53 (TW/Taiwan/53.148.80.34.bc ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.80.148.53 (TW/Taiwan/53.148.80.34.bc.googleusercontent.com)
show less
SQL Injection
๐ท๐บ
andrey volobuev
2026-06-09 19:55:03
(2 hours ago)
[09/Jun/2026:22:54:59 +0300] - 404 404 - GET https navidrome.bebesh.ru "/app/.env.bak" [Client 34.80 ...
show more
[09/Jun/2026:22:54:59 +0300] - 404 404 - GET https navidrome.bebesh.ru "/app/.env.bak" [Client 34.80.148.53] [Length 43] [Gzip -] [Sent-to 192.168.1.136] "Mozilla/5.0 (Linux; Android 9; moto x4) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.157 Mobile Safari/537.36" "-"
[09/Jun/2026:22:55:00 +0300] - 404 404 - GET https navidrome.bebesh.ru "/app/.env.dev" [Client 34.80.148.53] [Length 43] [Gzip -] [Sent-to 192.168.1.136] "Mozilla/5.0 (Linux; Android 7.1.1; Moto E (4) Plus) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/76.0.3809.111 Mobile Safari/537.36" "-"
[09/Jun/2026:22:55:00 +0300] - 404 404 - GET https navidrome.bebesh.ru "/api/.env.staging" [Client 34.80.148.53] [Length 43] [Gzip -] [Sent-to 192.168.1.136] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/76.0.3798.0 Safari/537.36" "-"
[09/Jun/2026:22:55:00 +0300] - 404 404 - GET https navidrome.bebesh.ru "/api/.env.prod" [Client 34.80.148.53] [Length 43] [Gzip -] [Sent-to 192.168.
...
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-09 18:37:24
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.80.148.53 (53.148.80.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.80.148.53 (53.148.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 14:37:15.144941 2026] [security2:error] [pid 14143:tid 14143] [client 34.80.148.53:53026] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.aares2026.net.aares2025.net"] [uri "/.env.backup.txt"] [unique_id "aihdW5UQ3aBSjha1pk_ZEgAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-09 16:42:24
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.80.148.53 (53.148.80.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.80.148.53 (53.148.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 12:42:16.691436 2026] [security2:error] [pid 32064:tid 32064] [client 34.80.148.53:43270] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.geckoturner.chezlubacov.xyz"] [uri "/.env.backup.txt"] [unique_id "aihCaKxbSr0izke9FRxcFgAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฑ๐ป
garmtech.com
2026-06-09 13:58:15
(8 hours ago)
IM360 WAF: Direct access to sensitive file or dotfile MV:/.env.production
Web App Attack
๐ซ๐ท
dynamix
2026-06-09 12:52:43
(9 hours ago)
Multiple WAF Violations
Web App Attack
๐น๐ท
baku.hosting
2026-06-09 11:51:57
(10 hours ago)
CSF Auto Report: (mod_security) mod_security (id:949110) triggered by 34.80.148.53 (TW/Taiwan/53.148 ...
show more
CSF Auto Report: (mod_security) mod_security (id:949110) triggered by 34.80.148.53 (TW/Taiwan/53.148.80.34.bc.googleusercontent.com): 5 in the last 3600 secs
show less
Brute-Force
Web App Attack
๐ณ๐ฑ
Cloud86 B.V.
2026-06-09 11:26:05
(10 hours ago)
categories: DDoS Attack
DDoS Attack
๐บ๐ธ
TPI-Abuse
2026-06-09 09:10:31
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.80.148.53 (53.148.80.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.80.148.53 (53.148.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 05:10:26.117122 2026] [security2:error] [pid 28211:tid 28231] [client 34.80.148.53:40450] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "giogalati.com"] [uri "/.env.uat"] [unique_id "aifYguXAiqikUZJVUsXhVgAAAZA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-09 08:46:24
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.80.148.53 (53.148.80.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.80.148.53 (53.148.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 04:46:17.984622 2026] [security2:error] [pid 11575:tid 11575] [client 34.80.148.53:57888] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.comunitatregantsangles.com.zentinex.com"] [uri "/.env.local"] [unique_id "aifS2YoH27KTr40LelUvDgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-09 08:44:48
(13 hours ago)
Aggressive web scan
Web App Attack
๐ฉ๐ช
updown.io
2026-06-09 07:26:24
(14 hours ago)
{"level":"info","ts":1780989983.1390808,"logger":"http.log.access.log1","msg":"handled request","req ...
show more
{"level":"info","ts":1780989983.1390808,"logger":"http.log.access.log1","msg":"handled request","request":{"remote_ip":"34.80.148.53","remote_port":"51820","client_ip":"34.80.148.53","proto":"HTTP/1.1","method":"GET","host":"c7402a95-6fc9-4756-b4e6-fa6c7eeb29c6.random.159.89.98.98.nip.io","uri":"/.env.local","headers":{"Accept-Encoding":["gzip"],"Connection":["close"],"User-Agent":["Mozilla/5.0 (compatible; Konqueror/4.1; OpenBSD) KHTML/4.1.4 (like Gecko)"],"Accept-Charset":["utf-8"]}},"bytes_read":0,"user_id":"","duration":0.000062188,"size":0,"status":308,"resp_headers":{"Server":["Caddy"],"Connection":["close"],"Location":["https://c7402a95-6fc9-4756-b4e6-fa6c7eeb29c6.random.159.89.98.98.nip.io/.env.local"],"Content-Type":[]}}
{"level":"info","ts":1780989983.171375,"logger":"http.log.access.log1","msg":"handled request","request":{"remote_ip":"34.80.148.53","remote_port":"51834","client_ip":"34.80.148.53","proto":"HTTP/1.1","method":"GET","host":"c7402a95-6fc9-4756-b4e6-fa6c7eeb29c6
...
show less
DDoS Attack
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-09 05:22:05
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.80.148.53 (53.148.80.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.80.148.53 (53.148.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 01:22:01.991234 2026] [security2:error] [pid 19204:tid 19204] [client 34.80.148.53:54130] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.pbrmb1.org"] [uri "/.env.development.local"] [unique_id "aiei-VFZK50RrJWtv9xp_AAAACE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
debestelapp
2026-06-08 22:30:08
(23 hours ago)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-08 17:28:51
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.80.148.53 (53.148.80.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.80.148.53 (53.148.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 08 13:28:43.250410 2026] [security2:error] [pid 29826:tid 29826] [client 34.80.148.53:41874] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.vid.com"] [uri "/.env.docker"] [unique_id "aib7ywAah_8MyU7_M2j55QAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack