๐จ๐ฆ
polycoda
2026-08-01 18:33:54
(9 hours ago)
AutoBlock: ๐ฏ Vulnerability Scanner (Non Decay-Based)
Hacking
Web App Attack
Anonymous
2026-08-01 17:40:03
(10 hours ago)
suspicious request in access.log
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-01 17:24:39
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.84.120.238 (238.120.84.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.84.120.238 (238.120.84.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 13:24:34.730917 2026] [security2:error] [pid 31874:tid 31874] [client 34.84.120.238:40694] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "lakewyliehairsalon.com"] [uri "/.env.dev"] [unique_id "am4r0oqB5m2SMshCHFPnfAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-01 17:15:05
(11 hours ago)
Try to connect to Port_Scan_443_stealth
Port Scan
๐ฉ๐ช
pscriptos
2026-08-01 17:03:09
(11 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
Anonymous
2026-08-01 16:53:51
(11 hours ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
๐ฒ๐พ
Rizzy
2026-08-01 16:42:23
(11 hours ago)
Multiple WAF Violations
Brute-Force
Web App Attack
๐ฉ๐ช
Bedios GmbH
2026-08-01 16:32:48
(11 hours ago)
Login credentials theft attempt
Hacking
๐บ๐ธ
TPI-Abuse
2026-08-01 16:23:04
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.84.120.238 (238.120.84.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.84.120.238 (238.120.84.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 12:22:56.374458 2026] [security2:error] [pid 1904549:tid 1904549] [client 34.84.120.238:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "hondabvi.com"] [uri "/.env.backup"] [unique_id "am4dYET65hetz-q6v-LsMwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
zynex
2026-08-01 16:06:25
(12 hours ago)
URL Probing: /.env
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-01 15:49:27
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.84.120.238 (238.120.84.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.84.120.238 (238.120.84.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 11:49:23.926881 2026] [security2:error] [pid 177978:tid 177978] [client 34.84.120.238:53532] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.amazingthailand.net.convoyforkids.com"] [uri "/.env.prod"] [unique_id "am4Vg4JBW_emR0l_sonSEQAAACc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-01 15:46:43
(12 hours ago)
34.84.120.238 - - [01/Aug/2026:15:46:43 +0000] "GET /.env.bak HTTP/1.1" 404 11664 "-" "crusader-work ...
show more
34.84.120.238 - - [01/Aug/2026:15:46:43 +0000] "GET /.env.bak HTTP/1.1" 404 11664 "-" "crusader-worker/1.0"
...
show less
Brute-Force
Web App Attack
๐บ๐ธ
jcbriar
2026-08-01 15:39:23
(12 hours ago)
Searching for vulnerable scripts
Hacking
Web App Attack
๐ณ๐ฟ
realstuffie
2026-08-01 15:11:58
(13 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-08-01 14:50:08
(13 hours ago)
(mod_security) mod_security (id:949110) triggered by 34.84.120.238 (238.120.84.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:949110) triggered by 34.84.120.238 (238.120.84.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 10:49:55.374896 2026] [security2:error] [pid 2046450:tid 2046450] [client 34.84.120.238:33854] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "mail.seenandlovedstrays.org"] [uri "/.env.old"] [unique_id "am4Hk2LGZcwEUlsErEaQqQAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack