๐บ๐ธ
TPI-Abuse
2026-08-01 17:32:53
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.101.81.19 (19.81.101.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.101.81.19 (19.81.101.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 13:32:48.704891 2026] [security2:error] [pid 2560891:tid 2560891] [client 34.101.81.19:56858] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.agingworkforcenews.com"] [uri "/.env"] [unique_id "am4twJpOm99i2tT5p7VFywAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-01 17:24:03
(16 hours ago)
Bot / scanning and/or hacking attempts: GET /.env.production HTTP/1.1
Hacking
Web App Attack
๐บ๐ธ
RH5
2026-08-01 17:21:55
(16 hours ago)
Restricted URL probing (/.env) (UTC 2026-08-01 17:21)
Web App Attack
๐ฉ๐ช
dbmwebdesign
2026-08-01 17:10:08
(16 hours ago)
WAF repeated trigger detected by Fail2Ban in plesk-modsecurity jail
Web App Attack
๐ธ๐ฌ
securejdprop
2026-08-01 16:34:40
(17 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files.
Hacking
Web App Attack
๐ฉ๐ช
s@ch@
2026-08-01 16:30:02
(17 hours ago)
Jail: plesk-modsecurity | Web application attack (Plesk ModSecurity)
Web App Attack
๐ซ๐ฎ
as211431.net
2026-08-01 16:24:41
(17 hours ago)
Triggered Cloudflare WAF (firewallCustom) from ID.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET metho ...
show more
Triggered Cloudflare WAF (firewallCustom) from ID.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET method)
Endpoint: /.env.prod
UA: crusader-worker/1.0
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-08-01 15:41:37
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.101.81.19 (19.81.101.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.101.81.19 (19.81.101.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 11:41:32.931660 2026] [security2:error] [pid 708458:tid 708475] [client 34.101.81.19:35512] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cornell61.org"] [uri "/.env"] [unique_id "am4TrB3PurNDA53-AL73nwAAAcI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
madaello
2026-08-01 15:29:01
(18 hours ago)
34.101.81.19 - - [01/Aug/2026:17:29:00 +0200] "GET /.env.local HTTP/1.1" 404 4616 "-" "crusader-work ...
show more
34.101.81.19 - - [01/Aug/2026:17:29:00 +0200] "GET /.env.local HTTP/1.1" 404 4616 "-" "crusader-worker/1.0"
34.101.81.19 - - [01/Aug/2026:17:29:00 +0200] "GET /.env.production HTTP/1.1" 404 4618 "-" "crusader-worker/1.0"
34.101.81.19 - - [01/Aug/2026:17:29:00 +0200] "GET /.env.backup HTTP/1.1" 404 4616 "-" "crusader-worker/1.0"
34.101.81.19 - - [01/Aug/2026:17:29:00 +0200] "GET /.env.old HTTP/1.1" 404 4616 "-" "crusader-worker/1.0"
34.101.81.19 - - [01/Aug/2026:17:29:00 +0200] "GET /.env.example HTTP/1.1" 404 4616 "-" "crusader-worker/1.0"
...
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-08-01 15:22:02
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.101.81.19 (19.81.101.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.101.81.19 (19.81.101.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 11:21:55.716159 2026] [security2:error] [pid 2881479:tid 2881479] [client 34.101.81.19:46930] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.jbccomputers.com.jbcllcnet.com"] [uri "/.env.bak"] [unique_id "am4PE5bSw_a-Qxm8lv8MCAAAACA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
clamehost.it
2026-08-01 15:17:53
(18 hours ago)
Automatic report - Brute Force attack using this IP address
Brute-Force
๐บ๐ธ
mnsf
2026-08-01 15:05:19
(18 hours ago)
Too many Status 40X (20)
Scanning/Probing (30)
Brute-Force
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-08-01 14:53:53
(19 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐จ๐ญ
4server
2026-08-01 14:40:38
(19 hours ago)
[SatAug0116:40:34.8970932026][security2:error][pid3886850:tid3887107][client34.101.81.19:0]ModSecuri ...
show more
[SatAug0116:40:34.8970932026][security2:error][pid3886850:tid3887107][client34.101.81.19:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\".env\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"365\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"xn--tda.pics.81-17-25-250.cpanel.site\"][uri\"/.env.prod\"][unique_id\"am4FYlkGFYywHyImrt4GPQAAARE\"]
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-01 14:25:12
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.101.81.19 (19.81.101.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.101.81.19 (19.81.101.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 10:25:07.664439 2026] [security2:error] [pid 2267885:tid 2267885] [client 34.101.81.19:34140] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "troop698.org"] [uri "/.env.old"] [unique_id "am4Bw1fEulvH6dELPFYHtAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack