๐บ๐ธ
TPI-Abuse
2026-08-01 17:30:05
(8 minutes ago)
(mod_security) mod_security (id:210492) triggered by 34.81.236.234 (234.236.81.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.81.236.234 (234.236.81.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 13:29:55.394944 2026] [security2:error] [pid 2875242:tid 2875271] [client 34.81.236.234:51828] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "barnetts.us"] [uri "/.env"] [unique_id "am4tE8bMBn1nErInZouBFAAAARc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Lino Project
2026-08-01 17:08:00
(30 minutes ago)
CrowdSec abuse IP report (host SRV-2) Scenario: crowdsecurity/http-sensitive-files
Hacking
Anonymous
2026-08-01 16:35:04
(1 hour ago)
Bot / scanning and/or hacking attempts: GET /.env.old HTTP/1.1
Hacking
Web App Attack
๐ฉ๐ช
IVski
2026-08-01 16:16:47
(1 hour ago)
IVski WAF | Multiple 403 Forbidden responses detected from this IP. Likely automated scanning.
DDoS Attack
Bad Web Bot
๐ฉ๐ช
4server
2026-08-01 16:05:09
(1 hour ago)
[SatAug0118:05:04.9333542026][security2:error][pid1714437:tid1714465][client34.81.236.234:0]ModSecur ...
show more
[SatAug0118:05:04.9333542026][security2:error][pid1714437:tid1714465][client34.81.236.234:0]ModSecurity:Accessdeniedwithcode403\(phase2\).Stringmatchwithin\".asa/.asax/.ascx/.backup/.bak/.bat/.cdx/.cer/.cfg/.cmd/.com/.config/.conf/.cs/.csproj/.csr/.dat/.db/.dbf/.dll/.dos/.htr/.htw/.ida/.idc/.idq/.inc/.ini/.key/.licx/.lnk/.log/.mdb/.old/.pass/.pdb/.pol/.printer/.pwd/.rdb/.resources/.resx/.sql/.swp/.sys/.vb/.vbs/.vbproj/.vsdisco/.webinfo/.xsx/\"atTX:extension.[file\"/etc/apache2/conf.d/modsec_rules/00_asl_zz_strict.conf\"][line\"91\"][id\"390716\"][rev\"2\"][msg\"Atomicorp.comWAFRules:URLfileextensionisrestrictedbypolicy\"][data\".backup\"][severity\"ERROR\"][hostname\"laumeiconsulting.com.136-243-54-122.cpanel.site\"][uri\"/.env.backup\"][unique_id\"am4ZMHdWcxaWKzJ1yPUumwAAABA\"]
show less
Port Scan
Brute-Force
Web App Attack
๐ฉ๐ช
Skyrider
2026-08-01 16:00:46
(1 hour ago)
crowdsecurity/http-sensitive-files
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-01 15:20:00
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.81.236.234 (234.236.81.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.81.236.234 (234.236.81.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 11:19:54.455194 2026] [security2:error] [pid 909953:tid 909953] [client 34.81.236.234:57994] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "financesf.com"] [uri "/.env.production"] [unique_id "am4OmsU1a7GfMRfQ9VzSmQAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
NXTwoThou
2026-08-01 15:16:11
(2 hours ago)
/.env.save
Web App Attack
๐บ๐ธ
MatCat
2026-08-01 15:05:06
(2 hours ago)
Banned by fail2ban: apache-webprobe
Port Scan
Bad Web Bot
๐ซ๐ท
Catalin Negru
2026-08-01 14:57:44
(2 hours ago)
Recidive ban by fail2ban on server.blackbit.ro
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-08-01 14:32:49
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.81.236.234 (234.236.81.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.81.236.234 (234.236.81.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 10:32:43.603021 2026] [security2:error] [pid 653963:tid 653963] [client 34.81.236.234:60842] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.catherineseress.com"] [uri "/.env.example"] [unique_id "am4Di5J764f6uZeMypOlowAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-01 14:10:11
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.81.236.234 (234.236.81.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.81.236.234 (234.236.81.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 10:10:03.488776 2026] [security2:error] [pid 25865:tid 25865] [client 34.81.236.234:58576] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sterlingandtime.com"] [uri "/.env.example"] [unique_id "am3-O0N04fQB17q1oUUTzQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
gadix
2026-08-01 14:03:44
(3 hours ago)
[01/Aug/2026:16:03:44.532025 +0200] am38wA6KoEaDlOLbORfl3AAAAIg 34.81.236.234 43210 127.0.0.1 7081
[ ...
show more
[01/Aug/2026:16:03:44.532025 +0200] am38wA6KoEaDlOLbORfl3AAAAIg 34.81.236.234 43210 127.0.0.1 7081
[01/Aug/2026:16:03:44.532784 +0200] am38wA6KoEaDlOLbORfl3QAAAJg 34.81.236.234 43258 127.0.0.1 7081
[01/Aug/2026:16:03:44.533493 +0200] am38wA6KoEaDlOLbORfl3gAAAIA 34.81.236.234 43224 127.0.0.1 7081
...
show less
Web App Attack
๐ฉ๐ช
webanyone
2026-08-01 13:46:05
(3 hours ago)
WAF repeated trigger detected by Fail2Ban in plesk-modsecurity jail
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-01 13:26:13
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.81.236.234 (234.236.81.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.81.236.234 (234.236.81.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 09:26:08.813773 2026] [security2:error] [pid 1965481:tid 1965481] [client 34.81.236.234:53348] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "michaelsabbey.com"] [uri "/.env.local"] [unique_id "am3z8DS3qxVmx7oNS-Eh9QAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack