π©πͺ
4server
2026-08-01 17:15:24
(2 hours ago)
[SatAug0119:15:21.2823612026][security2:error][pid1782669:tid1782754][client34.96.244.144:0]ModSecur ...
show more
[SatAug0119:15:21.2823612026][security2:error][pid1782669:tid1782754][client34.96.244.144:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:5\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.10\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"www.esengineering.ch.136-243-54-122.cpanel.site\"][uri\"/.env.example\"][unique_id\"am4pqTQwJHFe_rvA3yaNKQAAAJc\"]
show less
Port Scan
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-01 17:10:37
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.96.244.144 (144.244.96.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.96.244.144 (144.244.96.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 13:10:29.261643 2026] [security2:error] [pid 2022425:tid 2022425] [client 34.96.244.144:60890] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.celestialworks.click"] [uri "/.env.example"] [unique_id "am4ohQ2bAVfSV7Ok8PLt7gAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
Jarda_H
2026-08-01 16:59:33
(2 hours ago)
http-sensitive-files
Web App Attack
πͺπΈ
alferez
2026-08-01 16:59:29
(2 hours ago)
Searching .(env|sql|zip|tar|rar) files
Hacking
Exploited Host
Web App Attack
Anonymous
2026-08-01 16:30:03
(3 hours ago)
suspicious request in access.log
Web App Attack
π«π·
dynamix
2026-08-01 16:29:33
(3 hours ago)
Multiple WAF Violations
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-01 16:27:31
(3 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.96.244.144 (144.244.96.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.96.244.144 (144.244.96.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 12:27:28.566181 2026] [security2:error] [pid 2401893:tid 2401893] [client 34.96.244.144:58012] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.pine.rustyog.net|F|2"] [data ".env.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.pine.rustyog.net"] [uri "/.env.bak"] [unique_id "am4ecCeEqOMUrTLDUlnQcAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
kosada.com
2026-08-01 16:18:04
(3 hours ago)
Web vulnerability probing: /.env.old
Web App Attack
π³π±
e.fierstra
2026-08-01 16:16:08
(3 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-01 15:47:35
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.96.244.144 (144.244.96.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.96.244.144 (144.244.96.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 11:47:29.198755 2026] [security2:error] [pid 2162046:tid 2162046] [client 34.96.244.144:35746] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "matterofbritain.com"] [uri "/.env.production"] [unique_id "am4VESiAAufGWh4A3OnQygAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π¬π§
Aetherweb Ark
2026-08-01 15:42:45
(4 hours ago)
(mod_security) mod_security (id:949110) triggered by 34.96.244.144 (HK/Hong Kong/144.244.96.34.bc.go ...
show more
(mod_security) mod_security (id:949110) triggered by 34.96.244.144 (HK/Hong Kong/144.244.96.34.bc.googleusercontent.com): N in the last X secs
show less
Web App Attack
πΊπΈ
lnklnx
2026-08-01 14:50:13
(4 hours ago)
nextcloud.lnklnx.com:443 34.96.244.144 - - [01/Aug/2026:09:50:10 -0500] "GET /.env.old HTTP/1.1" 404 ...
show more
nextcloud.lnklnx.com:443 34.96.244.144 - - [01/Aug/2026:09:50:10 -0500] "GET /.env.old HTTP/1.1" 404 10663 "-" "crusader-worker/1.0"
...
show less
Web App Attack
π΅π±
lns.bz
2026-08-01 14:31:36
(5 hours ago)
Web app attack [PL.Lu]
Exploited Host
Web App Attack
π«π·
masterguru
2026-08-01 14:27:52
(5 hours ago)
Restricted File Access Attempt. Matched phrase ".env" at REQUEST_FILENAME. (930130-197)
Hacking
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-01 14:04:00
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.96.244.144 (144.244.96.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.96.244.144 (144.244.96.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 10:03:51.927353 2026] [security2:error] [pid 2311253:tid 2311253] [client 34.96.244.144:49222] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.buyhealthy.net"] [uri "/.env.example"] [unique_id "am38x2Z8Z2tpDyKGQURrKwAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack