🇺🇸
TPI-Abuse
2026-09-04 11:44:18
(11 minutes ago)
(mod_security) mod_security (id:210492) triggered by 34.124.135.202 (202.135.124.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.124.135.202 (202.135.124.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 07:44:10.275217 2026] [security2:error] [pid 11887:tid 11887] [client 34.124.135.202:36376] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.graduationnapkins.com"] [uri "/.env.backup"] [unique_id "apqvCq6hVP6bBpHyrO_VMwAAACM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 11:12:42
(42 minutes ago)
(mod_security) mod_security (id:210492) triggered by 34.124.135.202 (202.135.124.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.124.135.202 (202.135.124.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 07:12:38.521847 2026] [security2:error] [pid 1420:tid 1454] [client 34.124.135.202:39908] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "aafmorg.aafm.us"] [uri "/.env.save"] [unique_id "apqnppyWrnu_DsJunToU0wAAAJI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 08:29:44
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.124.135.202 (202.135.124.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.124.135.202 (202.135.124.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 04:29:39.822367 2026] [security2:error] [pid 21426:tid 21426] [client 34.124.135.202:54816] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.securityzonepr.com"] [uri "/.env.backup"] [unique_id "apqBcyrgJtHoSHFTxjf_jAAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
debestelapp
2026-09-04 08:20:10
(3 hours ago)
Web App Attack
Anonymous
2026-09-04 08:12:04
(3 hours ago)
Bot / scanning and/or hacking attempts: GET /.env.dev HTTP/1.1, GET /.env.old HTTP/1.1, GET /.env.pr ...
show more
Bot / scanning and/or hacking attempts: GET /.env.dev HTTP/1.1, GET /.env.old HTTP/1.1, GET /.env.prod HTTP/1.1, GET /.env.bak HTTP/1.1, GET /wp-config.php~ HTTP/1.1, GET /.env.production HTTP/1.1, GET /.env.backup HTTP/1.1, GET /.env.example HTTP/1.1, GET /env HTTP/1.1, GET /.env HTTP/1.1, GET /crusader-404-probe HTTP/1.1, GET /actuator/configprops HTTP/1.1, GET /.env.local HTTP/1.1, GET /wp-config.php.swp HTTP/1.1, GET /_ignition/health-check HTTP/1.1, GET /.env.save HTTP/1.1, GET /actuator/env HTTP/1.1
show less
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 07:33:17
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.124.135.202 (202.135.124.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.124.135.202 (202.135.124.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 03:33:10.572190 2026] [security2:error] [pid 12074:tid 12074] [client 34.124.135.202:54264] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "tomorrowsdust.net.greighhouse.com"] [uri "/wp-config.php.bak"] [unique_id "app0NrQnngZ77g2kC9MTJgAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇯🇵
Valhalla
2026-09-04 07:11:08
(4 hours ago)
/storage/logs/laravel.log
Hacking
Web App Attack
🇩🇪
Marc
2026-09-04 07:04:00
(4 hours ago)
34.124.135.202 - - [04/Sep/2026:09:04:00 +0200] "GET /crusader-404-probe HTTP/1.1" 404 4618 "-" "cru ...
show more
34.124.135.202 - - [04/Sep/2026:09:04:00 +0200] "GET /crusader-404-probe HTTP/1.1" 404 4618 "-" "crusader-worker/1.0" 34.124.135.202 - - [04/Sep/2026:09:04:00 +0200] "GET /.env.bak HTTP/1.1" 404 4617 "-" "crusader-worker/1.0" 34.124.135.202 - - [04/Sep/2026:09:04:00 +0200] "GET /.env.example HTTP/1.1" 404 4617 "-" "crusader-worker/1.0"
show less
Brute-Force
🇺🇸
TPI-Abuse
2026-09-04 07:01:33
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.124.135.202 (202.135.124.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.124.135.202 (202.135.124.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 03:01:30.235641 2026] [security2:error] [pid 29513:tid 29513] [client 34.124.135.202:52122] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "nationalenq.com"] [uri "/.env.old"] [unique_id "appsyvib6JgKWFVR7UALzwAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-04 06:20:04
(5 hours ago)
suspicious request in access.log
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 06:10:00
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.124.135.202 (202.135.124.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.124.135.202 (202.135.124.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 02:09:53.318272 2026] [security2:error] [pid 19573:tid 19654] [client 34.124.135.202:42604] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "psychclinicforchange.com"] [uri "/.env"] [unique_id "appgsZmVvP1SYC0k1lCvWwAAARY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
e.fierstra
2026-09-04 05:50:21
(6 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
🇩🇪
Gwyneth Llewelyn
2026-09-04 05:34:46
(6 hours ago)
2026/09/04 06:34:32 [error] 380594#380594: *2706882 access forbidden by rule, client: 34.124.135.202 ...
show more
2026/09/04 06:34:32 [error] 380594#380594: *2706882 access forbidden by rule, client: 34.124.135.202, server: [redacted], request: "GET /.env HTTP/2.0", host: "artesia.betatechnologies.info"
34.124.135.202 - - [04/Sep/2026:06:34:32 +0100] "GET /.env HTTP/2.0" 403 1045 "-" "crusader-worker/1.0"
2026/09/04 06:34:44 [error] 380594#380594: *2706889 access forbidden by rule, client: 34.124.135.202, server: [redacted], request: "GET //.env HTTP/2.0", host: "artesia.betatechnologies.info"
show less
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 04:46:36
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.124.135.202 (202.135.124.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.124.135.202 (202.135.124.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 00:46:27.203962 2026] [security2:error] [pid 27019:tid 27019] [client 34.124.135.202:45318] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "brbvip.com.bamedica.com"] [uri "/wp-config.php.swp"] [unique_id "appNI0uKxVZvq-fZWqPqbgAAAFY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
consul.to
2026-09-04 04:46:03
(7 hours ago)
Web attack/malicious scanning detected
Web App Attack