🇸🇪
vaia.cloud
2026-09-08 22:40:01
(10 hours ago)
crowdsecurity/http-probing
Brute-Force
Web App Attack
🇿🇦
vanderhost
2026-09-08 20:16:17
(13 hours ago)
[Laravel HoneypotPlus] Automated report - Honeypot access detected on path: /config/secrets.yml via ...
show more
[Laravel HoneypotPlus] Automated report - Honeypot access detected on path: /config/secrets.yml via rule: /config
show less
Web App Attack
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-08 20:10:27
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.85.1.255 (255.1.85.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.85.1.255 (255.1.85.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 16:10:22.559400 2026] [security2:error] [pid 507:tid 507] [client 34.85.1.255:61406] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.cruanyes.com"] [uri "/@fs/root/.env"] [unique_id "aqBrrr-HvDSCzljsdWZGHgAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 19:39:45
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.85.1.255 (255.1.85.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.85.1.255 (255.1.85.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 15:39:42.106589 2026] [security2:error] [pid 18791:tid 18791] [client 34.85.1.255:37872] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.riser-astrology.com"] [uri "/@fs/.env.local"] [unique_id "aqBkfmNOStaWnD6N61DpjAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
Savvii
2026-09-08 19:20:54
(14 hours ago)
20 attempts against mh-misbehave-ban on redirect
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 18:54:48
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.85.1.255 (255.1.85.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.85.1.255 (255.1.85.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 14:54:41.368591 2026] [security2:error] [pid 21983:tid 21983] [client 34.85.1.255:24318] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.rongrapes.com"] [uri "/@fs/src/.env"] [unique_id "aqBZ8SJdkFHEE2uJRkQ-lgAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇸🇪
vaia.cloud
2026-09-08 18:35:01
(14 hours ago)
crowdsecurity/http-path-traversal-probing
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 18:13:41
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.85.1.255 (255.1.85.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.85.1.255 (255.1.85.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 14:13:36.191653 2026] [security2:error] [pid 13185:tid 13185] [client 34.85.1.255:49756] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.friendlyfarmforfun.com"] [uri "/@fs/.env.production"] [unique_id "aqBQUL8r9hbvIfBjCWsQOgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 17:19:52
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.85.1.255 (255.1.85.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.85.1.255 (255.1.85.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 13:19:48.107168 2026] [security2:error] [pid 30753:tid 30753] [client 34.85.1.255:39042] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.yuichiro.us"] [uri "/@fs/app/.env"] [unique_id "aqBDtHP_JS5Nex46xwMNoQAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇪🇸
beats
2026-09-08 17:19:29
(16 hours ago)
Reported by CrowdSec
Brute-Force
Bad Web Bot
Web App Attack
🇲🇾
Rizzy
2026-09-08 17:18:12
(16 hours ago)
Multiple WAF Violations
Brute-Force
Web App Attack
🇫🇷
dynamix
2026-09-08 16:51:47
(16 hours ago)
Multiple WAF Violations
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 16:39:52
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.85.1.255 (255.1.85.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.85.1.255 (255.1.85.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 12:39:46.323386 2026] [security2:error] [pid 1339:tid 1372] [client 34.85.1.255:52166] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.keetons.net.jameskeeton.com"] [uri "/@fs/.env"] [unique_id "aqA6UgrP3EOguvVEFYqziwAAAYQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 15:30:20
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.85.1.255 (255.1.85.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.85.1.255 (255.1.85.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 11:30:13.916089 2026] [security2:error] [pid 3585:tid 3585] [client 34.85.1.255:41292] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.lavozdemurcia.murciafm.com"] [uri "/@fs/.env"] [unique_id "aqAqBbWd2qYNwMfusGm8IQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇮🇹
VHosting
2026-09-08 15:05:03
(18 hours ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack