🇺🇸
TPI-Abuse
2026-09-01 13:46:16
(20 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.106.72.61 (61.72.106.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.106.72.61 (61.72.106.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 09:46:11.637988 2026] [security2:error] [pid 8121:tid 8121] [client 34.106.72.61:34116] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.feaverslane.com"] [uri "/wp-config.php~"] [unique_id "apbXI0svjn5NHV3CTXhNCAAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-01 13:45:15
(20 hours ago)
Observed scanned 12 known-sensitive endpoint(s), e.g.: /, /%2eenv, /.ENV, /.env, /.env.bak, /.env.ol ...
show more
Observed scanned 12 known-sensitive endpoint(s), e.g.: /, /%2eenv, /.ENV, /.env, /.env.bak, /.env.old
show less
Bad Web Bot
Web App Attack
🇷🇸
Smel
2026-09-01 13:33:03
(20 hours ago)
Unauthorized Probe/Connection, Hack -
Port Scan
Hacking
🇺🇸
Lee Daniel
2026-09-01 12:44:56
(21 hours ago)
34.106.72.61 - - [01/Sep/2026:08:44:56 -0400] "GET /.env HTTP/1.1" 403 6275 "-" "crusader-worker/1.0 ...
show more
34.106.72.61 - - [01/Sep/2026:08:44:56 -0400] "GET /.env HTTP/1.1" 403 6275 "-" "crusader-worker/1.0"
...
show less
DDoS Attack
Web Spam
Email Spam
Port Scan
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-01 12:19:07
(21 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.106.72.61 (61.72.106.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.106.72.61 (61.72.106.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 08:19:03.841649 2026] [security2:error] [pid 25765:tid 25765] [client 34.106.72.61:47256] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "scala-global.com"] [uri "/.env.example"] [unique_id "apbCtycnpz5rsSvz_82tSAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
FD-IX
2026-09-01 11:06:28
(23 hours ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-01 10:50:32
(23 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.106.72.61 (61.72.106.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.106.72.61 (61.72.106.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 06:50:25.289753 2026] [security2:error] [pid 23383:tid 23383] [client 34.106.72.61:48910] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "oshadega.com"] [uri "/wp-config.php~"] [unique_id "apat8VK3yttEKgWel8QmcwAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
FeG Deutschland
2026-09-01 09:55:58
(1 day ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 1247
Exploited Host
Web App Attack
🇳🇱
enpepet
2026-09-01 09:47:15
(1 day ago)
GENERAL: parametres: [url:env=] UA:crusader-worker/1.0 URL:/.env.old
Port Scan
Hacking
Brute-Force
Bad Web Bot
🇩🇪
Marc
2026-09-01 09:40:19
(1 day ago)
34.106.72.61 - - [01/Sep/2026:11:40:18 +0200] "GET /.env.production HTTP/1.1" 404 4616 "-" "crusader ...
show more
34.106.72.61 - - [01/Sep/2026:11:40:18 +0200] "GET /.env.production HTTP/1.1" 404 4616 "-" "crusader-worker/1.0" 34.106.72.61 - - [01/Sep/2026:11:40:18 +0200] "GET /actuator/env HTTP/1.1" 404 4617 "-" "crusader-worker/1.0" 34.106.72.61 - - [01/Sep/2026:11:40:18 +0200] "GET /env HTTP/1.1" 404 4617 "-" "crusader-worker/1.0"
show less
Brute-Force
🇩🇪
ddobko
2026-09-01 09:39:38
(1 day ago)
Bad Web Bot
Web App Attack
🇸🇪
vaia.cloud
2026-09-01 07:15:04
(1 day ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
🇬🇧
Aetherweb Ark
2026-09-01 06:41:38
(1 day ago)
(mod_security) mod_security (id:949110) triggered by 34.106.72.61 (US/United States/61.72.106.34.bc. ...
show more
(mod_security) mod_security (id:949110) triggered by 34.106.72.61 (US/United States/61.72.106.34.bc.googleusercontent.com): N in the last X secs
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-01 06:03:24
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.106.72.61 (61.72.106.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.106.72.61 (61.72.106.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 02:03:16.115032 2026] [security2:error] [pid 17159:tid 17159] [client 34.106.72.61:33394] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.joepaladino.com"] [uri "/.env"] [unique_id "apZqpL6MXTQazbRpTZ4rkAAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
openstrike.co.uk
2026-09-01 05:13:51
(1 day ago)
13 attacks on PHP URLs, env grabbing URLs:
GET /wp-config.php~ HTTP/1.1
GET /.env.save HTTP/1.1
Web App Attack
Hacking