🇺🇸
TPI-Abuse
2026-09-04 15:02:22
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.139.154.93 (93.154.139.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.139.154.93 (93.154.139.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 11:02:16.057598 2026] [security2:error] [pid 23006:tid 23071] [client 34.139.154.93:43672] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "lex.nederbragt.net"] [uri "/.env.production"] [unique_id "aprdeOK_eLa5AsS1DMl_zAAAAQM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇮
mnazibo
2026-09-04 15:00:06
(7 hours ago)
Date: 04/Sep/2026 17:54:10 | Reported IP: 34.139.154.93 mod_security | id: 930130 | US/group.my_doma ...
show more
Date: 04/Sep/2026 17:54:10 | Reported IP: 34.139.154.93 mod_security | id: 930130 | US/group.my_domain/- | Connections: 17 | Blocked: Permanent Block: [LF_MODSEC] | URIs: /%2eenv; /.env.; /.env/; //.env; /.ENV; /.env.backup; /.env.bak; /.env.dev; /.env.example; /.env.local; /.env.old; /.env.prod; /.env.production; /.env.save; /wp-config.php~; /wp-config.php.bak; /wp-config.php.swp | Logs: Restricted File Access Attempt
show less
SQL Injection
Brute-Force
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-04 14:11:32
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.139.154.93 (93.154.139.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.139.154.93 (93.154.139.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 10:11:27.530979 2026] [security2:error] [pid 25214:tid 25214] [client 34.139.154.93:42320] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.fishing-links.com"] [uri "/wp-config.php.swp"] [unique_id "aprRjwnmIf2KUBzDEzkluQAAAFk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
mnsf
2026-09-04 14:05:43
(8 hours ago)
Scanning/Probing (20)
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 13:41:59
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.139.154.93 (93.154.139.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.139.154.93 (93.154.139.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 09:41:53.586738 2026] [security2:error] [pid 779718:tid 779718] [client 34.139.154.93:46798] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "unitedwestandent.org"] [uri "/.env.old"] [unique_id "aprKoeKwL60pp2z1t7986wAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇮
as211431.net
2026-09-04 13:06:39
(9 hours ago)
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET metho ...
show more
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET method)
Endpoint: /.ENV
UA: crusader-worker/1.0
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
🇨🇭
4server
2026-09-04 13:01:51
(9 hours ago)
[FriSep0415:01:47.5745962026][security2:error][pid723848:tid723899][client34.139.154.93:0]ModSecurit ...
show more
[FriSep0415:01:47.5745962026][security2:error][pid723848:tid723899][client34.139.154.93:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\".env\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"610\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"shakary.com\"][uri\"/.env.bak\"][unique_id\"aprBO_-NfPNU-NYXrpDpzgAAAVU\"]
show less
Hacking
Web App Attack
🇮🇹
clamehost.it
2026-09-04 12:30:52
(9 hours ago)
Automatic report - Brute Force attack using this IP address
Brute-Force
🇺🇸
TPI-Abuse
2026-09-04 12:22:24
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.139.154.93 (93.154.139.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.139.154.93 (93.154.139.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 08:22:16.317521 2026] [security2:error] [pid 18934:tid 18934] [client 34.139.154.93:47402] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "indicadores.gabosoftware.com"] [uri "/.env.example"] [unique_id "apq3-Nr_3xgQ5WYhafyNpwAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
e.fierstra
2026-09-04 12:09:34
(10 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 11:43:13
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.139.154.93 (93.154.139.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.139.154.93 (93.154.139.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 07:43:08.099104 2026] [security2:error] [pid 7006:tid 7006] [client 34.139.154.93:49312] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.haisten.net"] [uri "/.env.production"] [unique_id "apquzJ2EJZj-P1luVbxHqAAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 11:01:17
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.139.154.93 (93.154.139.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.139.154.93 (93.154.139.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 07:01:10.960053 2026] [security2:error] [pid 7709:tid 7709] [client 34.139.154.93:54078] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "houston-church-of-god.org.aim-controls.com"] [uri "/.env"] [unique_id "apqk9oVvWIgWi0-e05XL-wAAACo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇸🇪
vaia.cloud
2026-09-04 10:15:02
(12 hours ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
🇫🇷
breubit
2026-09-04 10:11:40
(12 hours ago)
34.139.154.93 - - [04/Sep/2026:12:11:40 +0200] "GET /.env.dev HTTP/1.1" 404 4432 "-" "crusader-worke ...
show more
34.139.154.93 - - [04/Sep/2026:12:11:40 +0200] "GET /.env.dev HTTP/1.1" 404 4432 "-" "crusader-worker/1.0"
...
show less
Web App Attack
🇿🇦
conure.sh
2026-09-04 10:05:57
(12 hours ago)
csagent: score 20.0: secrets grab x2; 1 domain(s) in 0s
Web App Attack