๐บ๐ธ
TPI-Abuse
2026-09-01 13:50:52
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.142.117.111 (111.117.142.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.142.117.111 (111.117.142.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 09:50:45.861456 2026] [security2:error] [pid 12719:tid 12719] [client 34.142.117.111:40840] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.naked60yearoldgaymen.com"] [uri "/.env.backup"] [unique_id "apbYNXNcruVEDvVXUQZ-ogAAADg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 12:49:40
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.142.117.111 (111.117.142.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.142.117.111 (111.117.142.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 08:49:36.232281 2026] [security2:error] [pid 1282:tid 1282] [client 34.142.117.111:49578] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "picklehill.borzois.com"] [uri "/wp-config.php~"] [unique_id "apbJ4HIIF2A55mX2BMBoUQAAAEk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 11:25:15
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.142.117.111 (111.117.142.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.142.117.111 (111.117.142.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 07:25:10.353082 2026] [security2:error] [pid 23660:tid 23660] [client 34.142.117.111:37732] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.thomasandross.com"] [uri "/.env.backup"] [unique_id "apa2Fr34xvMjwvDJem7CcQAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
todix
2026-09-01 11:15:10
(1 day ago)
Web App Attack Exploid from 34.142.117.111
Web App Attack
๐ฉ๐ช
Hazzard
2026-09-01 11:08:38
(1 day ago)
(mod_security) mod_security triggered on hostname [redacted]): (CF_ENABLE)
SQL Injection
๐ฑ๐ป
garmtech.com
2026-09-01 10:59:39
(1 day ago)
Attempted access to sensitive endpoint (/.env.save) detected. Automated scan or unauthorized probing ...
show more
Attempted access to sensitive endpoint (/.env.save) detected. Automated scan or unauthorized probing.
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 10:59:01
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.142.117.111 (111.117.142.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.142.117.111 (111.117.142.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 06:58:52.980983 2026] [security2:error] [pid 32381:tid 32381] [client 34.142.117.111:42304] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.paragontechusa.com"] [uri "/.env.backup"] [unique_id "apav7CSvPx1JCxe78PAufQAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
aranguren.org
2026-09-01 10:48:20
(1 day ago)
34.142.117.111 - - [01/Sep/2026:20:48:19 +1000] "GET /.env.production HTTP/1.1" 404 996 "-" "crusade ...
show more
34.142.117.111 - - [01/Sep/2026:20:48:19 +1000] "GET /.env.production HTTP/1.1" 404 996 "-" "crusader-worker/1.0"
34.142.117.111 - - [01/Sep/2026:20:48:19 +1000] "GET /actuator/env HTTP/1.1" 404 996 "-" "crusader-worker/1.0"
34.142.117.111 - - [01/Sep/2026:20:48:19 +1000] "GET /crusader-404-probe HTTP/1.1" 404 996 "-" "crusader-worker/1.0"
34.142.117.111 - - [01/Sep/2026:20:48:19 +1000] "GET /.env.bak HTTP/1.1" 404 996 "-" "crusader-worker/1.0"
34.142.117.111 - - [01/Sep/2026:20:48:19 +1000] "GET /.env.save HTTP/1.1" 404 996 "-" "crusader-worker/1.0"
34.142.117.111 - - [01/Sep/2026:20:48:19 +1000] "GET /.env.dev HTTP/1.1" 404 996 "-" "crusader-worker/1.0"
...
show less
Bad Web Bot
๐ท๐ด
iulianh
2026-09-01 10:19:14
(1 day ago)
80,443
Brute-Force
SSH
๐ธ๐ช
vaia.cloud
2026-09-01 10:05:02
(1 day ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
๐ฌ๐ง
consul.to
2026-09-01 10:04:09
(1 day ago)
Web attack/malicious scanning detected
Web App Attack
๐ซ๐ท
masterguru
2026-09-01 09:43:35
(1 day ago)
Restricted File Access Attempt. Matched phrase ".env" at REQUEST_FILENAME. (930130-193)
Hacking
Web App Attack
๐ฉ๐ช
kkw
2026-09-01 08:27:38
(1 day ago)
[REDACTED] 34.142.117.111 - - [01/Sep/2026:10:27:36 +0200] "GET /wp-config.php.swp HTTP/1.1" 302 583 ...
show more
[REDACTED] 34.142.117.111 - - [01/Sep/2026:10:27:36 +0200] "GET /wp-config.php.swp HTTP/1.1" 302 5834 "-" "crusader-worker/1.0"
... (mode: searching http-sensitive-files)
show less
Bad Web Bot
Web App Attack
Anonymous
2026-09-01 08:26:23
(1 day ago)
Web scanner: GET /.env.example
Web App Attack
Hacking
๐ฌ๐ง
Aetherweb Ark
2026-09-01 08:19:36
(1 day ago)
(mod_security) mod_security (id:949110) triggered by 34.142.117.111 (GB/United Kingdom/111.117.142.3 ...
show more
(mod_security) mod_security (id:949110) triggered by 34.142.117.111 (GB/United Kingdom/111.117.142.34.bc.googleusercontent.com): N in the last X secs
show less
Web App Attack