๐ฉ๐ช
big-cloud.nl
2026-08-28 18:23:46
(21 minutes ago)
Try to access /.env
Web App Attack
๐บ๐ธ
rdpguard.com
2026-08-28 17:56:24
(48 minutes ago)
RdpGuard detected brute-force attempt on HTTP
Brute-Force
๐ท๐ด
iulianh
2026-08-28 17:52:20
(52 minutes ago)
80,443
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2026-08-28 17:42:21
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.85.252.56 (56.252.85.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.85.252.56 (56.252.85.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 13:42:16.968263 2026] [security2:error] [pid 20819:tid 20819] [client 34.85.252.56:33712] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "millergrain.com"] [uri "/.env.local"] [unique_id "apHIeBWYqBHalf5A43-s3AAAACs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
mondor.ro
2026-08-28 17:42:04
(1 hour ago)
Cluster member 148.251.176.225 (DE/Germany/antares.webyouridea.ro) said, DENY 34.85.252.56, Reason:[ ...
show more
Cluster member 148.251.176.225 (DE/Germany/antares.webyouridea.ro) said, DENY 34.85.252.56, Reason:[(mod_security) mod_security (id:210492) triggered by 34.85.252.56 (US/United States/56.252.85.34.bc.googleusercontent.com): 3 in the last 3600 secs]; Ports: *; Direction: inout; Trigger: LF_CLUSTER; Logs:
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-08-28 16:50:51
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.85.252.56 (56.252.85.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.85.252.56 (56.252.85.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 12:50:44.214981 2026] [security2:error] [pid 4652:tid 4652] [client 34.85.252.56:46314] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.argcreativegroup.com"] [uri "/.env"] [unique_id "apG8ZMdgV4l56QAPy6zg3wAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
entangled_mongoose
2026-08-28 16:26:17
(2 hours ago)
Probed /wp-config.php~.
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 16:24:14
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.85.252.56 (56.252.85.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.85.252.56 (56.252.85.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 12:24:06.615516 2026] [security2:error] [pid 11105:tid 11105] [client 34.85.252.56:42162] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "welleracore.com"] [uri "/.env.prod"] [unique_id "apG2JlGFJqf8rkmd6b_0FgAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 15:43:49
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.85.252.56 (56.252.85.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.85.252.56 (56.252.85.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 11:43:45.214019 2026] [security2:error] [pid 27689:tid 27689] [client 34.85.252.56:47346] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "avrknives.com"] [uri "/.env.backup"] [unique_id "apGssT1OJbj-YmIdUsyO5gAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 15:23:49
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.85.252.56 (56.252.85.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.85.252.56 (56.252.85.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 11:23:43.107142 2026] [security2:error] [pid 9374:tid 9381] [client 34.85.252.56:50542] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "hooknpatch.com"] [uri "/.env.local"] [unique_id "apGn_5KF69NIKd64TF7OjQAAAUU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-28 14:35:01
(4 hours ago)
suspicious request in access.log
Web App Attack
๐ซ๐ท
dynamix
2026-08-28 14:14:18
(4 hours ago)
Multiple WAF Violations
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-08-28 14:05:13
(4 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
Anonymous
2026-08-28 14:00:39
(4 hours ago)
[ns31.kdns.gr] httpd-config-scan: sites=www.blossombeauty.gr; logs=/var/log/httpd/domains/blossombea ...
show more
[ns31.kdns.gr] httpd-config-scan: sites=www.blossombeauty.gr; logs=/var/log/httpd/domains/blossombeauty.gr.log; samples=/.env.bak | /actuator/configprops | /.env.prod
show less
Hacking
Web App Attack
๐ซ๐ท
masterguru
2026-08-28 13:53:20
(4 hours ago)
Attempt to access a backup or working file. Pattern match "\\\\. (920500-193)
Hacking