๐ฉ๐ช
4server
2026-08-01 17:16:44
(33 seconds ago)
[SatAug0119:16:41.1076042026][security2:error][pid1782671:tid1782793][client34.87.37.13:0]ModSecurit ...
show more
[SatAug0119:16:41.1076042026][security2:error][pid1782671:tid1782793][client34.87.37.13:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:5\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.10\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"bicycleambulance.ch.136-243-54-122.cpanel.site\"][uri\"/.env.production\"][unique_id\"am4p-ePh1eB7fpeKLkrRMQAAANY\"]
show less
Port Scan
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-01 16:43:20
(33 minutes ago)
(mod_security) mod_security (id:210492) triggered by 34.87.37.13 (13.37.87.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.87.37.13 (13.37.87.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 12:43:12.588298 2026] [security2:error] [pid 2498367:tid 2498367] [client 34.87.37.13:43286] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.corona-schutzkonzept.vjrott.com"] [uri "/.env.backup"] [unique_id "am4iIEtV43vLYvoRTS8hoAAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-01 15:52:32
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.87.37.13 (13.37.87.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.87.37.13 (13.37.87.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 11:52:25.601372 2026] [security2:error] [pid 1940191:tid 1940191] [client 34.87.37.13:41144] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.dropzllc.directnic-support.rocks"] [uri "/.env.dev"] [unique_id "am4WOXkavoUYzhkLo4XRDAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
ghostwarriors
2026-08-01 15:50:10
(1 hour ago)
Webpage scraping
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-08-01 15:09:54
(2 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-08-01 14:50:35
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.87.37.13 (13.37.87.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.87.37.13 (13.37.87.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 10:50:29.668225 2026] [security2:error] [pid 901013:tid 901018] [client 34.87.37.13:41146] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.wintechltd.com"] [uri "/.env.dev"] [unique_id "am4HtcmyhF6OCaa2rrPsQwAAAMM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-01 14:40:02
(2 hours ago)
| Suspicious URL access.
Web App Attack
Hacking
SQL Injection
๐ธ๐ช
vaia.cloud
2026-08-01 14:35:03
(2 hours ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-01 14:17:08
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.87.37.13 (13.37.87.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.87.37.13 (13.37.87.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 10:17:04.270179 2026] [security2:error] [pid 3762:tid 3762] [client 34.87.37.13:44796] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.visitors.oxfordgliding.com"] [uri "/.env.dev"] [unique_id "am3_4GJG48ugu3Jf41GnTgAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-08-01 13:51:54
(3 hours ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-01 13:44:27
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.87.37.13 (13.37.87.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.87.37.13 (13.37.87.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 09:44:20.387909 2026] [security2:error] [pid 2384163:tid 2384163] [client 34.87.37.13:41692] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "shawnlayne.com"] [uri "/.env.local"] [unique_id "am34NKqBaZoOSYksZQCW7wAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-01 13:24:22
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.87.37.13 (13.37.87.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.87.37.13 (13.37.87.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 09:24:16.720951 2026] [security2:error] [pid 2045321:tid 2045321] [client 34.87.37.13:36884] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ucommsi.com"] [uri "/.env.backup"] [unique_id "am3zgHO3J2YrqDx4sNuQ1QAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
paissangroup
2026-08-01 13:23:54
(3 hours ago)
Multiple WAF Violations
Web App Attack
๐ซ๐ฎ
inlink.ltd
2026-08-01 13:16:36
(4 hours ago)
dot file probe
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-01 12:57:51
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.87.37.13 (13.37.87.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.87.37.13 (13.37.87.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 08:57:45.371047 2026] [security2:error] [pid 1104326:tid 1104326] [client 34.87.37.13:35120] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "web229.dnchosting.com"] [uri "/.env"] [unique_id "am3tSZFZZ7aJ_V60z8VDeAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack