🇺🇸
TPI-Abuse
2026-09-06 03:52:52
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.86.166.211 (211.166.86.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.86.166.211 (211.166.86.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 23:52:46.374165 2026] [security2:error] [pid 11165:tid 11169] [client 34.86.166.211:38388] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.aqutar.com"] [uri "/.env.old"] [unique_id "apzjjv1pRt8N7QnZBIknsAAAAEE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
LRob
2026-09-06 03:36:25
(2 hours ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /.env.local (+10 more) | 2026-09-06 03:36 UTC
show less
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 03:24:57
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.86.166.211 (211.166.86.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.86.166.211 (211.166.86.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 23:24:53.420980 2026] [security2:error] [pid 6720:tid 6720] [client 34.86.166.211:34834] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "santurri.net"] [uri "/.env"] [unique_id "apzdBQcbU5i54uLxWoz3MgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-06 03:02:31
(2 hours ago)
34.86.166.211 - - [06/Sep/2026:11:02:31 +0800] "GET /.env.dev HTTP/1.1" 404 196 "-" "crusader-worker ...
show more
34.86.166.211 - - [06/Sep/2026:11:02:31 +0800] "GET /.env.dev HTTP/1.1" 404 196 "-" "crusader-worker/1.0"
...
show less
Bad Web Bot
Web App Attack
🇺🇸
Aurealize
2026-09-06 03:00:40
(2 hours ago)
Automated Sensitive File discovery attempt detected by a Cloudflare WAF custom rule. Path: /.env.
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-06 02:44:36
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.86.166.211 (211.166.86.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.86.166.211 (211.166.86.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 22:44:30.641636 2026] [security2:error] [pid 9070:tid 9070] [client 34.86.166.211:45290] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "albioncapitalfund.com"] [uri "/.env.dev"] [unique_id "apzTjmhEuHhCaDC9bWCQ_AAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
maxpower
2026-09-06 02:29:01
(3 hours ago)
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 34.86.166.211 (US/United States/211.166. ...
show more
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 34.86.166.211 (US/United States/211.166.86.34.bc.googleusercontent.com): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 34.86.166.211 - - [06/Sep/2026:04:28:57 +0200] "GET /wp-config.php.bak HTTP/1.1" 403 146 "-" "crusader-worker/1.0" "-" host=spaziolaserpescara.it
show less
Port Scan
🇨🇭
4server
2026-09-06 02:19:19
(3 hours ago)
[SunSep0604:19:13.7520242026][security2:error][pid2866345:tid2866538][client34.86.166.211:0]ModSecur ...
show more
[SunSep0604:19:13.7520242026][security2:error][pid2866345:tid2866538][client34.86.166.211:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\"wp-config\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"610\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"studiokellybenessere.ch\"][uri\"/wp-config.php.bak\"][unique_id\"apzNoYqVXD4hywN1vDU71QAAAJA\"]
show less
Hacking
Web App Attack
🇬🇧
Aetherweb Ark
2026-09-06 02:08:39
(3 hours ago)
(mod_security) mod_security (id:949110) triggered by 34.86.166.211 (US/United States/211.166.86.34.b ...
show more
(mod_security) mod_security (id:949110) triggered by 34.86.166.211 (US/United States/211.166.86.34.bc.googleusercontent.com): N in the last X secs
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 00:48:22
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.86.166.211 (211.166.86.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.86.166.211 (211.166.86.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 20:48:18.210461 2026] [security2:error] [pid 23815:tid 23815] [client 34.86.166.211:35616] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.buckinghambar.com"] [uri "/.env.local"] [unique_id "apy4Usb7KVVDu2mNj3GClQAAAC8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-06 00:40:45
(5 hours ago)
Web application attack detected.
Web App Attack
🇺🇸
helios.live
2026-09-06 00:22:36
(5 hours ago)
2026/09/06 00:22:36 [error] 3738676#3738676: *2297144 access forbidden by rule, client: 34.86.166.21 ...
show more
2026/09/06 00:22:36 [error] 3738676#3738676: *2297144 access forbidden by rule, client: 34.86.166.211, server: kocerroxy.com, request: "GET /.env.production HTTP/1.1", host: "kocerroxy.com"
2026/09/06 00:22:36 [error] 3738676#3738676: *2297144 access forbidden by rule, client: 34.86.166.211, server: kocerroxy.com, request: "GET /.env.save HTTP/1.1", host: "kocerroxy.com"
2026/09/06 00:22:36 [error] 3738678#3738678: *2297148 access forbidden by rule, client: 34.86.166.211, server: kocerroxy.com, request: "GET /.env.local HTTP/1.1", host: "kocerroxy.com"
2026/09/06 00:22:36 [error] 3738675#3738675: *2297143 access forbidden by rule, client: 34.86.166.211, server: kocerroxy.com, request: "GET /.env.dev HTTP/1.1", host: "kocerroxy.com"
2026/09/06 00:22:36 [error] 3738675#3738675: *2297146 access forbidden by rule, client: 34.86.166.211, server: kocerroxy.com, request: "GET /.env.example HTTP/1.1", host: "kocerroxy.com"
...
show less
Web App Attack
Anonymous
2026-09-06 00:18:07
(5 hours ago)
GET /.env.prod HTTP/1.1
...
Web App Attack
🇫🇷
✨
2026-09-06 00:12:10
(5 hours ago)
Domain : obs.bitsa.uk
Rule : env
2026-09-06 00:10:10 ***hidden-privacy*** GET /.env.bak - 443 - 34.8 ...
show more
Domain : obs.bitsa.uk
Rule : env
2026-09-06 00:10:10 ***hidden-privacy*** GET /.env.bak - 443 - 34.86.166.211 HTTP/1.1 crusader-worker/1.0 - obs.bitsa.uk 404 0 2 1547 92 510 - -
show less
Hacking
SQL Injection
🇫🇷
dynamix
2026-09-06 00:08:21
(5 hours ago)
Multiple WAF Violations
Web App Attack