🇺🇸
TPI-Abuse
2026-09-04 15:22:19
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.102.20.82 (82.20.102.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.102.20.82 (82.20.102.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 11:22:15.333025 2026] [security2:error] [pid 12837:tid 12837] [client 34.102.20.82:53378] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.maleein.com"] [uri "/.env.backup"] [unique_id "apriJz4SzdwMpKuLRFTEnAAAAD8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
spot
2026-09-04 14:46:46
(10 hours ago)
34.102.20.82 - - [04/Sep/2026:15:46:30 +0100] "GET /wp-config.php~ HTTP/1.1" 404 4659 "-" "crusader- ...
show more
34.102.20.82 - - [04/Sep/2026:15:46:30 +0100] "GET /wp-config.php~ HTTP/1.1" 404 4659 "-" "crusader-worker/1.0"
...
show less
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-04 14:09:34
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.102.20.82 (82.20.102.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.102.20.82 (82.20.102.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 10:09:30.451446 2026] [security2:error] [pid 812634:tid 812634] [client 34.102.20.82:56218] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.hotelausland.com"] [uri "/.env"] [unique_id "aprRGm0AmiRGIDuZc0rHigAAAJU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
raph
2026-09-04 13:45:36
(11 hours ago)
[DOT FILES] crawler *.env*, .git*, .config*, etc.
Bad Web Bot
Web App Attack
🇳🇱
debestelapp
2026-09-04 12:55:11
(12 hours ago)
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 12:32:57
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.102.20.82 (82.20.102.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.102.20.82 (82.20.102.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 08:32:50.229960 2026] [security2:error] [pid 30109:tid 30109] [client 34.102.20.82:42900] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "goldeys.com"] [uri "/wp-config.php.bak"] [unique_id "apq6ciniiu6NzhxTl3hqwgAAAEo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
Hazzard
2026-09-04 12:21:54
(12 hours ago)
(mod_security) mod_security triggered on hostname [redacted]): (CF_ENABLE)
SQL Injection
🇬🇧
SilverZippo
2026-09-04 12:13:27
(12 hours ago)
Web App Attack
Web App Attack
🇬🇧
cg-design.co.uk
2026-09-04 11:47:19
(13 hours ago)
(mod_security) mod_security triggered on hostname [redacted] 34.102.20.82 (US/United States/82.20.10 ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.102.20.82 (US/United States/82.20.102.34.bc.googleusercontent.com)
show less
SQL Injection
🇳🇱
i-turnradio.nl
2026-09-04 11:46:00
(13 hours ago)
2026-09-04 @ 13:46:00 (CET) ~ Blocked for trying to access: /.env.example
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 10:56:05
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.102.20.82 (82.20.102.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.102.20.82 (82.20.102.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 06:56:00.388845 2026] [security2:error] [pid 8023:tid 8023] [client 34.102.20.82:39074] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bobbyunser.com"] [uri "/.env.save"] [unique_id "apqjwP46UU-ZM8vTKP8ECwAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 10:06:36
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.102.20.82 (82.20.102.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.102.20.82 (82.20.102.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 06:06:29.993098 2026] [security2:error] [pid 5290:tid 5290] [client 34.102.20.82:46028] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.lynetteharris.net"] [uri "/.env.prod"] [unique_id "apqYJdJV1zqeM-zZEnBLXQAAACM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-04 09:43:00
(15 hours ago)
Malicious web scanning
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 09:33:59
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.102.20.82 (82.20.102.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.102.20.82 (82.20.102.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 05:33:54.571640 2026] [security2:error] [pid 7352:tid 7352] [client 34.102.20.82:36480] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "puckerbuttbikini.com"] [uri "/.env.production"] [unique_id "apqQgmEkBIt3si0MKFrASAAAACI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
Apache
2026-09-04 08:40:47
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.102.20.82 (US/United States/82.20.102.34.bc. ...
show more
(mod_security) mod_security (id:210492) triggered by 34.102.20.82 (US/United States/82.20.102.34.bc.googleusercontent.com): 5 in the last 300 secs (CF_ENABLE)
show less
Brute-Force
Web App Attack