🇩🇪
DEV-DNS
2026-08-29 03:26:08
(10 hours ago)
(mod_security) mod_security triggered on hostname [redacted])
SQL Injection
🇺🇸
TPI-Abuse
2026-08-29 03:17:31
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.138.107.69 (69.107.138.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.138.107.69 (69.107.138.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 23:17:25.218274 2026] [security2:error] [pid 9820:tid 9903] [client 34.138.107.69:46778] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.21370.opticaldesignconcepts.com"] [uri "/.env.old"] [unique_id "apJPRYQ2s3rN4U8Ag_ZSQgAAAgY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
4server
2026-08-29 03:12:17
(11 hours ago)
[SatAug2905:12:12.6662442026][security2:error][pid3538733:tid3538813][client34.138.107.69:0]ModSecur ...
show more
[SatAug2905:12:12.6662442026][security2:error][pid3538733:tid3538813][client34.138.107.69:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:5\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.10\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"rs-gaming.net.136-243-54-122.cpanel.site\"][uri\"/.env.prod\"][unique_id\"apJODOd8_316gueAEjTwnwAAAMk\"]
show less
Port Scan
Brute-Force
Web App Attack
🇲🇾
Rizzy
2026-08-29 03:08:53
(11 hours ago)
Multiple WAF Violations
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-08-29 01:42:11
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.138.107.69 (69.107.138.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.138.107.69 (69.107.138.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 21:42:07.151120 2026] [security2:error] [pid 9381:tid 9381] [client 34.138.107.69:42186] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.progressivefileshare.org"] [uri "/wp-config.php~"] [unique_id "apI47-PEFgGZtsN4nEQYIQAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-29 01:11:23
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.138.107.69 (69.107.138.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.138.107.69 (69.107.138.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 21:11:18.674917 2026] [security2:error] [pid 5514:tid 5514] [client 34.138.107.69:56904] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.nightowlprinting.com"] [uri "/.env.production"] [unique_id "apIxtk7etWJ4ggX9qYXywgAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
masterguru
2026-08-29 00:37:24
(13 hours ago)
Restricted File Access Attempt. Matched phrase ".env" at REQUEST_FILENAME. (930130-197)
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-08-29 00:07:25
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.138.107.69 (69.107.138.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.138.107.69 (69.107.138.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 20:07:19.083640 2026] [security2:error] [pid 21410:tid 21410] [client 34.138.107.69:41760] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "wurkroom.biz.smartstylehair.com"] [uri "/wp-config.php~"] [unique_id "apIit2XsK95r65VB6pcS-gAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
Aetherweb Ark
2026-08-28 23:41:45
(14 hours ago)
(mod_security) mod_security (id:949110) triggered by 34.138.107.69 (US/United States/69.107.138.34.b ...
show more
(mod_security) mod_security (id:949110) triggered by 34.138.107.69 (US/United States/69.107.138.34.bc.googleusercontent.com): N in the last X secs
show less
Web App Attack
🇺🇸
wordpresshosting.solutions
2026-08-28 23:04:38
(15 hours ago)
Web app vulnerability scanning detected. Evidence: 34.138.107.69 - - [28/Aug/2026:23:04:35 +0000] "G ...
show more
Web app vulnerability scanning detected. Evidence: 34.138.107.69 - - [28/Aug/2026:23:04:35 +0000] "GET /.env.save HTTP/1.1" 404 50082 "-" "crusader-worker/1.0"
34.138.107.69 - - [28/Aug/2026:23:04:35 +0000] "GET /.env.local HTTP/1.1" 404 50084 "-" "crusader-worker/1.0"
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-08-28 22:44:07
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.138.107.69 (69.107.138.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.138.107.69 (69.107.138.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 18:44:02.596517 2026] [security2:error] [pid 15671:tid 15671] [client 34.138.107.69:42780] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "artspacecleveland.com"] [uri "/.env.bak"] [unique_id "apIPMtNWt6Zj6qAUMmXH8QAAACc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-28 22:41:18
(15 hours ago)
Web probing activity
Hacking
Web App Attack
🇺🇦
Scientific Route
2026-08-28 22:23:58
(15 hours ago)
34.138.107.69 - - [29/Aug/2026:01:23:57 +0300] "GET /.env.prod HTTP/1.1" 404 437 "-" "crusader-worke ...
show more
34.138.107.69 - - [29/Aug/2026:01:23:57 +0300] "GET /.env.prod HTTP/1.1" 404 437 "-" "crusader-worker/1.0"
34.138.107.69 - - [29/Aug/2026:01:23:57 +0300] "GET /.env.production HTTP/1.1" 404 437 "-" "crusader-worker/1.0"
...
show less
Web App Attack
🇺🇸
ssssssssssssssssssssuper
2026-08-28 22:20:55
(15 hours ago)
34.138.107.69 - - [28/Aug/2026:18:20:55 -0400] "GET /.env HTTP/1.1" 404 162 "-" "crusader-worker/1.0 ...
show more
34.138.107.69 - - [28/Aug/2026:18:20:55 -0400] "GET /.env HTTP/1.1" 404 162 "-" "crusader-worker/1.0"
34.138.107.69 - - [28/Aug/2026:18:20:55 -0400] "GET /.env.local HTTP/1.1" 404 162 "-" "crusader-worker/1.0"
34.138.107.69 - - [28/Aug/2026:18:20:55 -0400] "GET /.env.production HTTP/1.1" 404 162 "-" "crusader-worker/1.0"
...
show less
Port Scan
Hacking
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-28 21:46:52
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.138.107.69 (69.107.138.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.138.107.69 (69.107.138.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 17:46:45.798878 2026] [security2:error] [pid 12282:tid 12282] [client 34.138.107.69:40108] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.pcsyportatiles.com.integratic.com.co"] [uri "/.env.old"] [unique_id "apIBxa1Aq5I9q5FBXBuoOQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack