🇩🇪
on-com
2026-09-04 10:13:48
(1 hour ago)
URL scan
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 10:02:27
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.141.85.59 (59.85.141.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.141.85.59 (59.85.141.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 06:02:23.475112 2026] [security2:error] [pid 12534:tid 12534] [client 34.141.85.59:47218] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.creeation.com"] [uri "/wp-config.php.bak"] [unique_id "apqXL1FQ6pK7vy-XaBukqQAAAG4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 09:18:46
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.141.85.59 (59.85.141.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.141.85.59 (59.85.141.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 05:18:37.902596 2026] [security2:error] [pid 30400:tid 30400] [client 34.141.85.59:48594] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kathynash.com"] [uri "/.env.local"] [unique_id "apqM7c-p2PZ5XS6XwBnADAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-04 08:42:15
(3 hours ago)
PSCSERV WPSCAN 34.141.85.59
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 08:17:09
(3 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.141.85.59 (59.85.141.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.141.85.59 (59.85.141.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 04:17:01.951471 2026] [security2:error] [pid 7053:tid 7053] [client 34.141.85.59:54238] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||diveshop-pr.com|F|2"] [data ".log"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "diveshop-pr.com"] [uri "/storage/logs/laravel.log"] [unique_id "app-fV1hwPkkZ3Yque_YCAAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
masterguru
2026-09-04 07:49:46
(4 hours ago)
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 34.141.85.59 (DE/Germany/59.85.141.34 ...
show more
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 34.141.85.59 (DE/Germany/59.85.141.34.bc.googleusercontent.com): 1 in the last 3600 secs (0-195)
show less
Hacking
🇺🇸
TPI-Abuse
2026-09-04 07:43:29
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.141.85.59 (59.85.141.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.141.85.59 (59.85.141.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 03:43:26.515548 2026] [security2:error] [pid 23927:tid 23927] [client 34.141.85.59:46908] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ftp.dodojuice.com"] [uri "/.env.bak"] [unique_id "app2npA1GMiHlsnxWCfdswAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 07:13:46
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.141.85.59 (59.85.141.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.141.85.59 (59.85.141.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 03:13:39.440468 2026] [security2:error] [pid 12203:tid 12221] [client 34.141.85.59:53816] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cynosurefinishes.com.cynosureinternetservices.com"] [uri "/.env.example"] [unique_id "appvown-lUA2gViiKA_6eAAAARA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
raph
2026-09-04 06:44:01
(5 hours ago)
[DOT FILES] crawler *.env*, .git*, .config*, etc.
Bad Web Bot
Web App Attack
🇩🇪
big-cloud.nl
2026-09-04 06:18:18
(5 hours ago)
Try to access /.env
Web App Attack
🇫🇷
dynamix
2026-09-04 06:03:44
(5 hours ago)
Multiple WAF Violations
Web App Attack
🇸🇬
ipidentify
2026-09-04 05:44:53
(6 hours ago)
2026-09-04T05:44:53Z GET /.env
Web App Attack
🇩🇪
s@ch@
2026-09-04 05:30:01
(6 hours ago)
Jail: plesk-modsecurity | Web application attack (Plesk ModSecurity)
Web App Attack
🇩🇪
LRob
2026-09-04 05:20:53
(6 hours ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /.env (+12 more) | 2026-09-04 05:20 UTC
show less
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 05:17:04
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.141.85.59 (59.85.141.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.141.85.59 (59.85.141.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 01:16:59.534693 2026] [security2:error] [pid 13299:tid 13299] [client 34.141.85.59:51306] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "wordandwisdom.org"] [uri "/.env.local"] [unique_id "appUS8UfWGcpPOw-YC6y6gAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack