๐บ๐ธ
TPI-Abuse
2026-09-01 14:03:34
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.138.230.64 (64.230.138.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.138.230.64 (64.230.138.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 10:03:29.072980 2026] [security2:error] [pid 10218:tid 10218] [client 34.138.230.64:51438] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.daviddenotaris.com"] [uri "/.env.production"] [unique_id "apbbMZfq32bMUbIU9G8F6AAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
debestelapp
2026-09-01 13:10:11
(5 hours ago)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 12:38:59
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.138.230.64 (64.230.138.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.138.230.64 (64.230.138.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 08:38:54.446291 2026] [security2:error] [pid 4530:tid 4530] [client 34.138.230.64:40104] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "canfieldnyc.com"] [uri "/.env.save"] [unique_id "apbHXg4OuNMJkBooV2byjgAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 12:05:04
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.138.230.64 (64.230.138.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.138.230.64 (64.230.138.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 08:04:56.841963 2026] [security2:error] [pid 20051:tid 20051] [client 34.138.230.64:49846] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "desoucey.com"] [uri "/.env.bak"] [unique_id "apa_aGLE0XXewLuLRdxU2AAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 11:00:59
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.138.230.64 (64.230.138.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.138.230.64 (64.230.138.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 07:00:55.073203 2026] [security2:error] [pid 26338:tid 26338] [client 34.138.230.64:60226] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.ajvaage.com"] [uri "/.env.example"] [unique_id "apawZ_OSvj6boEDLlOvmAQAAACc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ธ๐ช
SkyDancer
2026-09-01 10:49:33
(8 hours ago)
Multiple unauthorized attempts to access using wrong credentials. Attack automatically blocked by Sk ...
show more
Multiple unauthorized attempts to access using wrong credentials. Attack automatically blocked by SkyDancer Ai. EXT-SYS-Vx
show less
Hacking
Brute-Force
SSH
๐ซ๐ท
masterguru
2026-09-01 09:32:34
(9 hours ago)
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 34.138.230.64 (US/United States/64.23 ...
show more
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 34.138.230.64 (US/United States/64.230.138.34.bc.googleusercontent.com): 2 in the last 3600 secs (0-196)
show less
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-01 09:21:36
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.138.230.64 (64.230.138.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.138.230.64 (64.230.138.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 05:21:28.285613 2026] [security2:error] [pid 9725:tid 9725] [client 34.138.230.64:37966] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ssion.com"] [uri "/.env"] [unique_id "apaZGNAOlrF56gh1VJODvwAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-09-01 07:33:03
(11 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
๐ฉ๐ช
4server
2026-09-01 07:28:34
(11 hours ago)
[TueSep0109:28:31.8982422026][security2:error][pid3847440:tid3847565][client34.138.230.64:0]ModSecur ...
show more
[TueSep0109:28:31.8982422026][security2:error][pid3847440:tid3847565][client34.138.230.64:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Patternmatch\"\(\?i\)\(\?:/\(\?:\^\|/\)\\\\\\\\.\(env\|git\|svn\|hg\|DS_Store\)\|/\(\?:wp-config\|\\\\\\\\.htaccess\|\\\\\\\\.htpasswd\)\|\\\\\\\\.\(\?:sql\|bak\|old\|log\)\$\)\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"156\"][id\"960720\"][msg\"Forbiddenfileaccessattempt\"][severity\"CRITICAL\"][hostname\"your-team.ch.136-243-54-122.cpanel.site\"][uri\"/.env.bak\"][unique_id\"apZ-n29O57hb5_fgKmSPQwAAAM8\"]
show less
Port Scan
Brute-Force
Web App Attack
๐ฌ๐ง
Aetherweb Ark
2026-09-01 07:28:34
(11 hours ago)
(mod_security) mod_security (id:949110) triggered by 34.138.230.64 (US/United States/64.230.138.34.b ...
show more
(mod_security) mod_security (id:949110) triggered by 34.138.230.64 (US/United States/64.230.138.34.bc.googleusercontent.com): N in the last X secs
show less
Web App Attack
๐ฎ๐ช
AutosOnShow
2026-09-01 06:33:04
(12 hours ago)
blocked for webapp attack | path requested: /.env | seen at 2026-09-01 06:32:43.739 |
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-09-01 06:31:27
(12 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 06:02:26
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.138.230.64 (64.230.138.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.138.230.64 (64.230.138.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 02:02:16.025309 2026] [security2:error] [pid 1628:tid 1628] [client 34.138.230.64:56512] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cougarcrusade.com"] [uri "/.env.local"] [unique_id "apZqaFvqh1NHrh1bJDck1AAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 05:44:40
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.138.230.64 (64.230.138.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.138.230.64 (64.230.138.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 01:44:32.034942 2026] [security2:error] [pid 7105:tid 7105] [client 34.138.230.64:59712] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "edmontonbuilder.com.weyoungrenovations.com"] [uri "/.env.local"] [unique_id "apZmQLvd013aBisrxLK-ewAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack