🇺🇸
TPI-Abuse
2026-09-04 15:16:17
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.134.20.208 (208.20.134.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.134.20.208 (208.20.134.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 11:16:13.054137 2026] [security2:error] [pid 17481:tid 17481] [client 34.134.20.208:51732] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.ridgecrestrealtors.com"] [uri "/.env.dev"] [unique_id "aprgvWRDtRRQ9RTO-Tx2JwAAADM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 14:40:44
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.134.20.208 (208.20.134.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.134.20.208 (208.20.134.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 10:40:39.652562 2026] [security2:error] [pid 17081:tid 17081] [client 34.134.20.208:52092] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sawyerwest.com"] [uri "/wp-config.php.swp"] [unique_id "aprYZ_-viivX4rC1rmubZgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 14:13:38
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.134.20.208 (208.20.134.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.134.20.208 (208.20.134.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 10:13:34.164230 2026] [security2:error] [pid 3074852:tid 3074977] [client 34.134.20.208:35572] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "wijaya.biz"] [uri "/.env"] [unique_id "aprSDsEtaesxEZ02xUhD-wAAANU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
Hazzard
2026-09-04 14:08:06
(1 day ago)
(mod_security) mod_security triggered on hostname [redacted]): (CF_ENABLE)
SQL Injection
🇦🇺
2000cn.com.au
2026-09-04 12:46:19
(1 day ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-04 12:46:02
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.134.20.208 (208.20.134.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.134.20.208 (208.20.134.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 08:45:54.974551 2026] [security2:error] [pid 13486:tid 13486] [client 34.134.20.208:57230] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "artisticheadstones.com"] [uri "/.env.dev"] [unique_id "apq9gjbtZaNiUVNj8RRiBQAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 11:57:54
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.134.20.208 (208.20.134.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.134.20.208 (208.20.134.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 07:57:48.042261 2026] [security2:error] [pid 24672:tid 24672] [client 34.134.20.208:53466] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "thebestproduct.guru"] [uri "/.env"] [unique_id "apqyPBMT-PwP0o4SYZMaBQAAAEg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
e.fierstra
2026-09-04 11:00:12
(1 day ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
🇷🇺
Albram
2026-09-04 10:48:11
(1 day ago)
Tries find Web server vulnerability
...
Hacking
Web App Attack
🇺🇸
cybertailor
2026-09-04 10:21:38
(1 day ago)
34.134.20.208 - - [04/Sep/2026:15:21:35 +0500] "GET /actuator/configprops HTTP/1.1" 404 146 "-" "cru ...
show more
34.134.20.208 - - [04/Sep/2026:15:21:35 +0500] "GET /actuator/configprops HTTP/1.1" 404 146 "-" "crusader-worker/1.0"
34.134.20.208 - - [04/Sep/2026:15:21:35 +0500] "GET /.env.bak HTTP/1.1" 404 146 "-" "crusader-worker/1.0"
34.134.20.208 - - [04/Sep/2026:15:21:35 +0500] "GET /wp-config.php.swp HTTP/1.1" 404 146 "-" "crusader-worker/1.0"
34.134.20.208 - - [04/Sep/2026:15:21:35 +0500] "GET /.env.old HTTP/1.1" 404 146 "-" "crusader-worker/1.0"
34.134.20.208 - - [04/Sep/2026:15:21:35 +0500] "GET /.env.production HTTP/1.1" 404 146 "-" "crusader-worker/1.0"
...
show less
Port Scan
🇩🇪
raph
2026-09-04 10:07:29
(1 day ago)
[DOT FILES] crawler *.env*, .git*, .config*, etc.
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 09:36:40
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.134.20.208 (208.20.134.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.134.20.208 (208.20.134.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 05:36:35.857543 2026] [security2:error] [pid 24320:tid 24325] [client 34.134.20.208:44344] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "havacubvision.com"] [uri "/wp-config.php~"] [unique_id "apqRI2Gnu9jfQJd6CsUwSwAAAMA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
FeG Deutschland
2026-09-04 08:44:17
(1 day ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 08:43:29
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.134.20.208 (208.20.134.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.134.20.208 (208.20.134.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 04:43:25.405275 2026] [security2:error] [pid 25123:tid 25123] [client 34.134.20.208:45066] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "rdu.kmp.net"] [uri "/.env.prod"] [unique_id "apqEraFoGz_KqcLZ8Do79QAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇨🇭
4server
2026-09-04 08:42:30
(1 day ago)
[FriSep0410:42:23.8456392026][security2:error][pid4081386:tid4081408][client34.134.20.208:0]ModSecur ...
show more
[FriSep0410:42:23.8456392026][security2:error][pid4081386:tid4081408][client34.134.20.208:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\".env\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"610\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"rssolution.rs-solution.ch\"][uri\"/.env.bak\"][unique_id\"apqEb6BCEc_xUEFjJf47VgAAAAI\"]
show less
Hacking
Web App Attack