๐ซ๐ท
ELYAZ
2026-08-01 17:32:11
(6 hours ago)
(y3) Failed access -byebye- from 34.81.51.170 (TW/Taiwan/170.51.81.34.bc.googleusercontent.com): (C ...
show more
(y3) Failed access -byebye- from 34.81.51.170 (TW/Taiwan/170.51.81.34.bc.googleusercontent.com): (CF_ENABLE)
show less
Hacking
๐ฉ๐ช
Viveronese
2026-08-01 17:13:35
(7 hours ago)
HTTP vulnerability scanning
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-01 17:11:53
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.81.51.170 (170.51.81.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.81.51.170 (170.51.81.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 13:11:48.570431 2026] [security2:error] [pid 1342546:tid 1342546] [client 34.81.51.170:60610] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.pianissimo-pp.com.globalvillagecambodia.org"] [uri "/.env.production"] [unique_id "am4o1PeuXGIfcgYvR_fYKwAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-01 16:21:02
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.81.51.170 (170.51.81.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.81.51.170 (170.51.81.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 12:20:56.950550 2026] [security2:error] [pid 11979:tid 11979] [client 34.81.51.170:50386] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sjjcox.com"] [uri "/.env.prod"] [unique_id "am4c6FPxPiUvn6A8Gf6zJgAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
4server
2026-08-01 15:49:08
(8 hours ago)
[SatAug0117:49:04.6234262026][security2:error][pid1698921:tid1698960][client34.81.51.170:0]ModSecuri ...
show more
[SatAug0117:49:04.6234262026][security2:error][pid1698921:tid1698960][client34.81.51.170:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Patternmatch\"\(\?i\)\(\?:/\(\?:\^\|/\)\\\\\\\\.\(env\|git\|svn\|hg\|DS_Store\)\|/\(\?:wp-config\|\\\\\\\\.htaccess\|\\\\\\\\.htpasswd\)\|\\\\\\\\.\(\?:sql\|bak\|old\|log\)\$\)\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"156\"][id\"960720\"][msg\"Forbiddenfileaccessattempt\"][severity\"CRITICAL\"][hostname\"www.tecnospinasagl.ch.136-243-54-122.cpanel.site\"][uri\"/.env.old\"][unique_id\"am4VcC50bA2Ssuu5C6VF8AAAAEM\"]
show less
Port Scan
Brute-Force
Web App Attack
๐จ๐ฆ
SSH-Admin
2026-08-01 15:44:02
(8 hours ago)
Probing for Exploits on ns200
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-01 15:19:17
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.81.51.170 (170.51.81.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.81.51.170 (170.51.81.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 11:19:11.024425 2026] [security2:error] [pid 2134223:tid 2134223] [client 34.81.51.170:54062] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.live.cmabiblequizzing.org"] [uri "/.env.bak"] [unique_id "am4Ob7lPdtgRDlkNwyatrAAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
ger-stg-sifi1
2026-08-01 15:15:24
(9 hours ago)
(wordpress) Failed wordpress login using wp-login.php or xmlrpc.php
Web App Attack
๐ซ๐ฎ
YF
2026-08-01 15:00:55
(9 hours ago)
Environment file probe
Web App Attack
๐ฌ๐ง
myintarweb
2026-08-01 14:59:58
(9 hours ago)
34.81.51.170 - - [01/Aug/2026:15:59:57 +0100] 443 "GET /.env.prod HTTP/1.1" 404 31429 "-" "crusader- ...
show more
34.81.51.170 - - [01/Aug/2026:15:59:57 +0100] 443 "GET /.env.prod HTTP/1.1" 404 31429 "-" "crusader-worker/1.0"
34.81.51.170 - - [01/Aug/2026:15:59:57 +0100] 443 "GET /.env.backup HTTP/1.1" 404 31429 "-" "crusader-worker/1.0"
34.81.51.170 - - [01/Aug/2026:15:59:57 +0100] 443 "GET /.env.bak HTTP/1.1" 404 31429 "-" "crusader-worker/1.0"
34.81.51.170 - - [01/Aug/2026:15:59:57 +0100] 443 "GET /.env.dev HTTP/1.1" 404 31429 "-" "crusader-worker/1.0"
34.81.51.170 - - [01/Aug/2026:15:59:57 +0100] 443 "GET /.env.old HTTP/1.1" 404 31429 "-" "crusader-worker/1.0"
34.81.51.170 - - [01/Aug/2026:15:59:57 +0100] 443 "GET /.env.example HTTP/1.1" 404 31429 "-" "crusader-worker/1.0"
34.81.51.170 - - [01/Aug/2026:15:59:57 +0100] 443 "GET /.env.production HTTP/1.1" 404 31429 "-" "crusader-worker/1.0"
34.81.51.170 - - [01/Aug/2026:15:59:57 +0100] 443 "GET /.env.save HTTP/1.1" 404 31429 "-" "crusader-worker/1.0"
34.81.51.170 - - [01/Aug/2026:15:59:57 +0100] 443 "GET /.env.local HTTP/1.1" 404 31429 "-" "crus
...
show less
Hacking
Bad Web Bot
Web App Attack
Anonymous
2026-08-01 14:41:03
(9 hours ago)
Bot / scanning and/or hacking attempts: GET /.env.dev HTTP/1.1, GET /.env.prod HTTP/1.1, GET /.env.s ...
show more
Bot / scanning and/or hacking attempts: GET /.env.dev HTTP/1.1, GET /.env.prod HTTP/1.1, GET /.env.save HTTP/1.1
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-01 14:40:29
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.81.51.170 (170.51.81.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.81.51.170 (170.51.81.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 10:40:25.408904 2026] [security2:error] [pid 2875242:tid 2875259] [client 34.81.51.170:43344] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.icemakerparts.com.faimreps.com"] [uri "/.env.bak"] [unique_id "am4FWcbMBn1nErInZotmgQAAAQs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-01 14:40:23
(9 hours ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
๐ฉ๐ช
big-cloud.nl
2026-08-01 14:21:57
(10 hours ago)
Try to access /.env
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-01 13:52:52
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.81.51.170 (170.51.81.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.81.51.170 (170.51.81.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 09:52:47.123286 2026] [security2:error] [pid 465461:tid 465461] [client 34.81.51.170:55858] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.flashbackvintageandthrift.georgetownca.com"] [uri "/.env.bak"] [unique_id "am36L7aNw7zw8LYn1N0okgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack