🇺🇸
TPI-Abuse
2026-09-09 04:37:55
(4 minutes ago)
(mod_security) mod_security (id:210492) triggered by 34.142.158.75 (75.158.142.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.142.158.75 (75.158.142.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 00:37:49.315084 2026] [security2:error] [pid 16719:tid 16719] [client 34.142.158.75:36988] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.vegasweddingvacation.com"] [uri "/@fs/app/.env"] [unique_id "aqDinZqbiMqlLj17IKGBhAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 04:19:16
(22 minutes ago)
(mod_security) mod_security (id:210492) triggered by 34.142.158.75 (75.158.142.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.142.158.75 (75.158.142.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 00:19:08.606267 2026] [security2:error] [pid 20795:tid 20815] [client 34.142.158.75:21224] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.kandooo.com"] [uri "/@fs/..%252f..%252f..%252f..%252f..%252froot/.env"] [unique_id "aqDePOColVaRINUggTrzaAAAAJI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 03:59:17
(42 minutes ago)
(mod_security) mod_security (id:210492) triggered by 34.142.158.75 (75.158.142.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.142.158.75 (75.158.142.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 23:58:49.481964 2026] [security2:error] [pid 9458:tid 9458] [client 34.142.158.75:41160] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.famagustacyprus.eu"] [uri "/@fs/..%252f..%252f..%252f..%252f..%252fapp/.env"] [unique_id "aqDZebf9JP44ZV4Eny_n_AAAAB8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
WellSpring
2026-09-09 03:04:38
(1 hour ago)
env leak on 215.today/@fs/var/www/html/.env — WellSpr.ing/NetSentinel civic-AI security layer
Web App Attack
🇩🇪
Viveronese
2026-09-09 02:47:21
(1 hour ago)
HTTP vulnerability scanning
Web App Attack
Anonymous
2026-09-09 02:46:08
(1 hour ago)
Aggressive web scan
Web App Attack
🇫🇷
dynamix
2026-09-09 02:15:54
(2 hours ago)
Multiple WAF Violations
Web App Attack
Anonymous
2026-09-09 01:54:29
(2 hours ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-09 01:54:24
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.142.158.75 (75.158.142.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.142.158.75 (75.158.142.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 21:54:16.576265 2026] [security2:error] [pid 29278:tid 29278] [client 34.142.158.75:62256] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.thepotteriesmesilla.com"] [uri "/@fs/root/.env"] [unique_id "aqC8SC6F1a5Wg2WpyyKutwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
masterguru
2026-09-09 01:38:11
(3 hours ago)
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 34.142.158.75 (SG/Singapore/75.158.14 ...
show more
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 34.142.158.75 (SG/Singapore/75.158.142.34.bc.googleusercontent.com): 2 in the last 3600 secs (0-196)
show less
Hacking
🇺🇸
TPI-Abuse
2026-09-09 00:59:19
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.142.158.75 (75.158.142.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.142.158.75 (75.158.142.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 20:59:11.590149 2026] [security2:error] [pid 796:tid 796] [client 34.142.158.75:30618] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.edupal.net"] [uri "/@fs/.env.local"] [unique_id "aqCvX2BHbzQHnIwGL-NEKAAAACE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
Site.eu
2026-09-09 00:48:42
(3 hours ago)
Excessive 404/403 errors
Brute-Force
🇫🇷
Octopuce
2026-09-09 00:37:13
(4 hours ago)
Aggressive web search of vulnerable pages: /v2/.env /assets../.env /.env.local /_nuxt/../.env /uploa ...
show more
Aggressive web search of vulnerable pages: /v2/.env /assets../.env /.env.local /_nuxt/../.env /uploads../.env ...
show less
Web App Attack
🇮🇹
VHosting
2026-09-09 00:30:03
(4 hours ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 00:27:32
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.142.158.75 (75.158.142.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.142.158.75 (75.158.142.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 20:27:24.256975 2026] [security2:error] [pid 32343:tid 32356] [client 34.142.158.75:34046] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.aclarityforensics.com"] [uri "/@fs/.env.production"] [unique_id "aqCn7LrBQsZF7wRrDF2MrAAAAUg"]
show less
Brute-Force
Bad Web Bot
Web App Attack