๐บ๐ธ
TPI-Abuse
2026-09-01 12:08:37
(51 minutes ago)
(mod_security) mod_security (id:210492) triggered by 34.84.43.8 (8.43.84.34.bc.googleusercontent.com ...
show more
(mod_security) mod_security (id:210492) triggered by 34.84.43.8 (8.43.84.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 08:08:29.521503 2026] [security2:error] [pid 5855:tid 5855] [client 34.84.43.8:42914] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "debhill.com"] [uri "/.env.backup"] [unique_id "apbAPXo6gWog4crWxBwy5wAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 11:00:25
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.84.43.8 (8.43.84.34.bc.googleusercontent.com ...
show more
(mod_security) mod_security (id:210492) triggered by 34.84.43.8 (8.43.84.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 07:00:19.150612 2026] [security2:error] [pid 18731:tid 18731] [client 34.84.43.8:59246] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.nuegrapes.com"] [uri "/.env.save"] [unique_id "apawQw27mJyI9fsI77UFDwAAAHU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
ivanbiagi7
2026-09-01 10:39:01
(2 hours ago)
Wazuh detected repeated HTTP client errors consistent with automated web probing. Wazuh rule=31151.
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-09-01 10:13:27
(2 hours ago)
[01/Sep/2026:13:13:27 +0300] -- 34.84.43.8 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET /.en ...
show more
[01/Sep/2026:13:13:27 +0300] -- 34.84.43.8 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET /.env HTTP/1.1
show less
Bad Web Bot
Web App Attack
๐ณ๐ฑ
prinsbert
2026-09-01 09:15:25
(3 hours ago)
Hit honeypot route /.env.prod
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 08:48:42
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.84.43.8 (8.43.84.34.bc.googleusercontent.com ...
show more
(mod_security) mod_security (id:210492) triggered by 34.84.43.8 (8.43.84.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 04:48:34.769301 2026] [security2:error] [pid 12468:tid 12468] [client 34.84.43.8:58578] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "scrunchiebuttbikini.com"] [uri "/wp-config.php.bak"] [unique_id "apaRYtaRT0L1EXu4qt2RAwAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
tsZero
2026-09-01 07:54:58
(5 hours ago)
Scan example: path=/.env status=200
Hacking
๐ฉ๐ช
LRob
2026-09-01 07:06:20
(5 hours ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /.env.local (+10 more) | 2026-09-01 07:06 UTC
show less
Hacking
Web App Attack
๐จ๐ญ
4server
2026-09-01 06:44:17
(6 hours ago)
[TueSep0108:44:12.1900542026][security2:error][pid2151759:tid2152459][client34.84.43.8:0]ModSecurity ...
show more
[TueSep0108:44:12.1900542026][security2:error][pid2151759:tid2152459][client34.84.43.8:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\".env\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"610\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"swisservers.com\"][uri\"/.env.example\"][unique_id\"apZ0PH8nl7K7p4cUrx-GngAAAco\"]
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 06:40:26
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.84.43.8 (8.43.84.34.bc.googleusercontent.com ...
show more
(mod_security) mod_security (id:210492) triggered by 34.84.43.8 (8.43.84.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 02:40:18.095254 2026] [security2:error] [pid 25065:tid 25065] [client 34.84.43.8:58994] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "teapartytaxes.com"] [uri "/.env.old"] [unique_id "apZzUtOwrdt5VwLsOfKvcgAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 06:23:28
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.84.43.8 (8.43.84.34.bc.googleusercontent.com ...
show more
(mod_security) mod_security (id:210492) triggered by 34.84.43.8 (8.43.84.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 02:23:24.067009 2026] [security2:error] [pid 9184:tid 9184] [client 34.84.43.8:48670] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "liyatalton.com"] [uri "/.env.backup"] [unique_id "apZvXPt7xKnKU8e2epGKgwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-01 06:07:02
(6 hours ago)
Automated web scanner. Requested suspicious paths: /storage/logs/laravel.log | /.env.old | /actuator ...
show more
Automated web scanner. Requested suspicious paths: /storage/logs/laravel.log | /.env.old | /actuator/configprops | /crusader-404-probe | /.env.prod | /.env.example | /actuator/env | /.env.bak | /.env.local | /.env.save | /.env.dev | /.env.production | /env | /_ignition/health-check | /.env.backup | /.env. UTC: 2026-09-01 05:14:31.
show less
Web App Attack
๐ฉ๐ช
raph
2026-09-01 05:26:30
(7 hours ago)
[DOT FILES] crawler *.env*, .git*, .config*, etc.
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 05:13:52
(7 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.84.43.8 (8.43.84.34.bc.googleusercontent.com ...
show more
(mod_security) mod_security (id:210730) triggered by 34.84.43.8 (8.43.84.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 01:13:44.379980 2026] [security2:error] [pid 9176:tid 9176] [client 34.84.43.8:35470] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||efsews.com|F|2"] [data ".log"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "efsews.com"] [uri "/storage/logs/laravel.log"] [unique_id "apZfCEg9y-u-iVWGR1UgVAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ฐ
ScamAware
2026-09-01 04:34:28
(8 hours ago)
Detected by Cloudflare Security Events via WordPress automation. Detection: sensitive_files (Sensiti ...
show more
Detected by Cloudflare Security Events via WordPress automation. Detection: sensitive_files (Sensitive files, source control, config, and backups). Hits from same IP in last 60 minutes: 20. Unique request paths counted internally: 20. Cloudflare action: block. Cloudflare source: firewallCustom.
show less
Web App Attack