🇲🇽
octageeks.com
2026-08-02 04:10:48
(1 month ago)
Wordpress malicious attack:[octablocked]
Web App Attack
🇺🇸
TPI-Abuse
2026-08-01 17:31:11
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 34.96.173.77 (77.173.96.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.96.173.77 (77.173.96.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 13:31:06.561046 2026] [security2:error] [pid 916017:tid 916017] [client 34.96.173.77:54912] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bartholow.net"] [uri "/.env.dev"] [unique_id "am4tWol2rnBXttiUk9fx_AAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
IVski.com
2026-08-01 16:29:27
(1 month ago)
IVski WAF | Sensitive file probe detected - looking for .env
DDoS Attack
Bad Web Bot
🇺🇸
TPI-Abuse
2026-08-01 16:22:02
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 34.96.173.77 (77.173.96.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.96.173.77 (77.173.96.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 12:21:57.045971 2026] [security2:error] [pid 1855829:tid 1855829] [client 34.96.173.77:60186] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.sarawatt.powerastronomy.com"] [uri "/.env"] [unique_id "am4dJdlVRW5YOg8nz9LcvAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
masterguru
2026-08-01 15:39:41
(1 month ago)
Restricted File Access Attempt. Matched phrase ".env" at REQUEST_FILENAME. (930130-193)
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-08-01 15:31:16
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 34.96.173.77 (77.173.96.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.96.173.77 (77.173.96.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 11:31:10.807339 2026] [security2:error] [pid 2172015:tid 2172015] [client 34.96.173.77:48136] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "slmd.me"] [uri "/.env.dev"] [unique_id "am4RPlu026lGpKrthpmEFgAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-01 15:30:05
(1 month ago)
suspicious request in access.log
Web App Attack
🇩🇪
big-cloud.nl
2026-08-01 15:26:28
(1 month ago)
Try to access /.env
Web App Attack
🇫🇷
masterguru
2026-08-01 15:11:53
(1 month ago)
Restricted File Access Attempt. Matched phrase ".env" at REQUEST_FILENAME. (930130-201)
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-08-01 14:54:03
(1 month ago)
(mod_security) mod_security (id:949110) triggered by 34.96.173.77 (77.173.96.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:949110) triggered by 34.96.173.77 (77.173.96.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 10:53:59.789255 2026] [security2:error] [pid 2055687:tid 2055687] [client 34.96.173.77:47400] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "cescfoundation.org"] [uri "/.env.local"] [unique_id "am4IhzE3u31zA4lxAPg8igAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
e.fierstra
2026-08-01 14:32:10
(1 month ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-01 14:31:33
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 34.96.173.77 (77.173.96.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.96.173.77 (77.173.96.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 10:31:26.755342 2026] [security2:error] [pid 1857209:tid 1857209] [client 34.96.173.77:53246] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.firstclasstreatment.tijuanabible.org"] [uri "/.env"] [unique_id "am4DPnZIY-rAQQEDgW7yWgAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
Matthew Ping
2026-08-01 14:30:04
(1 month ago)
ModSecurity rule 949110 triggered on dedicated4785. Web application attack blocked by CSF/LFD.
Web App Attack
Hacking
🇫🇷
Nop Nop
2026-08-01 14:06:23
(1 month ago)
CrowdSec ban: crowdsecurity/http-sensitive-files
Port Scan
🇺🇸
TPI-Abuse
2026-08-01 13:48:08
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 34.96.173.77 (77.173.96.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.96.173.77 (77.173.96.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 09:48:01.237999 2026] [security2:error] [pid 2875242:tid 2875264] [client 34.96.173.77:47510] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.interactiveintermediaries.com.richardleeweatherman.com"] [uri "/.env.prod"] [unique_id "am35EcbMBn1nErInZotXzgAAARA"]
show less
Brute-Force
Bad Web Bot
Web App Attack