๐บ๐ธ
TPI-Abuse
2026-09-03 21:47:03
(11 minutes ago)
(mod_security) mod_security (id:210492) triggered by 34.145.2.249 (249.2.145.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.145.2.249 (249.2.145.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 17:46:59.443355 2026] [security2:error] [pid 22620:tid 22620] [client 34.145.2.249:42816] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.backyardbrickoven.com"] [uri "/@fs/.env"] [unique_id "apnq0z6p6r5NFA3-Isqa8AAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-03 21:31:02
(28 minutes ago)
(mod_security) mod_security (id:210492) triggered by 34.145.2.249 (249.2.145.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.145.2.249 (249.2.145.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 17:30:56.155754 2026] [security2:error] [pid 24751:tid 24751] [client 34.145.2.249:10732] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.greatnorthernstrategies.com"] [uri "/@fs/src/.env"] [unique_id "apnnENs1255GIobWK3g2IQAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-03 20:54:31
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.145.2.249 (249.2.145.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.145.2.249 (249.2.145.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 16:54:25.750744 2026] [security2:error] [pid 10854:tid 10854] [client 34.145.2.249:53506] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.resilientigm.com"] [uri "/@fs/app/.env"] [unique_id "apnegTaiPtUrTLNqeJiREAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-03 20:22:08
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.145.2.249 (249.2.145.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.145.2.249 (249.2.145.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 16:22:05.285198 2026] [security2:error] [pid 1600440:tid 1600469] [client 34.145.2.249:23464] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.gitlab.transitionalcareservices.com"] [uri "/@fs/..%252f..%252f..%252f..%252f..%252froot/.env"] [unique_id "apnW7aCyJIsNKL9klsFYkwAAANE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-03 20:06:13
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.145.2.249 (249.2.145.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.145.2.249 (249.2.145.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 16:06:06.800033 2026] [security2:error] [pid 31849:tid 31849] [client 34.145.2.249:58038] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.shinynew.com"] [uri "/@fs/.env"] [unique_id "apnTLmNhwufRCfrhyyR1jwAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Octopuce
2026-09-03 20:05:35
(1 hour ago)
Aggressive web search of vulnerable pages: /uploads../.env /config/.env /web/.env /docker/.env /.env ...
show more
Aggressive web search of vulnerable pages: /uploads../.env /config/.env /web/.env /docker/.env /.env.local ...
show less
Web App Attack
๐ณ๐ฑ
Site.eu
2026-09-03 19:37:57
(2 hours ago)
Excessive 404/403 errors
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-09-03 19:10:35
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.145.2.249 (249.2.145.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.145.2.249 (249.2.145.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 15:10:29.801416 2026] [security2:error] [pid 506:tid 506] [client 34.145.2.249:10058] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.bryteandbroderick.org"] [uri "/@fs/root/.env"] [unique_id "apnGJVSqAj6o1YDn4hOhbgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-03 18:44:39
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.145.2.249 (249.2.145.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.145.2.249 (249.2.145.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 14:44:35.962852 2026] [security2:error] [pid 24024:tid 24024] [client 34.145.2.249:34626] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.rodrandolph.com"] [uri "/@fs/.env"] [unique_id "apnAE0oyQ5N1eIJO1mHqmwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-09-03 18:31:29
(3 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
Anonymous
2026-09-03 18:09:48
(3 hours ago)
Aggressive web scan
Web App Attack
๐ฉ๐ช
ghostwarriors
2026-09-03 17:50:08
(4 hours ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack
๐ฎ๐น
VHosting
2026-09-03 17:50:03
(4 hours ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐ซ๐ท
dynamix
2026-09-03 17:33:49
(4 hours ago)
Multiple WAF Violations
Web App Attack
๐ฉ๐ช
yitzhaq
2026-09-03 17:32:59
(4 hours ago)
34.145.2.249 - - [03/Sep/2026:19:32:55 +0200] "GET /@fs/root/rootkey.csv?raw?? HTTP/1.1" 404 761 "-" ...
show more
34.145.2.249 - - [03/Sep/2026:19:32:55 +0200] "GET /@fs/root/rootkey.csv?raw?? HTTP/1.1" 404 761 "-" "Mozilla/5.0 (compatible; GrokBot/1.0; +https://x.ai/grokbot)"
34.145.2.249 - - [03/Sep/2026:19:32:55 +0200] "GET /@fs/home/ubuntu/.aws/credentials?raw?? HTTP/1.1" 404 761 "-" "Mozilla/5.0 (compatible; facebookexternalhit/1.1; +http://www.facebook.com/externalhit_uatext.php)"
34.145.2.249 - - [03/Sep/2026:19:32:55 +0200] "GET /@fs/..%252f..%252f..%252f..%252f..%252fapp/.env?raw?? HTTP/1.1" 404 761 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; OAI-SearchBot/1.4; robots.txt; +https://openai.com/searchbot)"
34.145.2.249 - - [03/Sep/2026:19:32:55 +0200] "GET /@fs/.env.production?raw?? HTTP/1.1" 404 761 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_4 like Mac OS X) AppleWebKit/537.36 (KHTML, like Gecko; compatible; meta-externalagent/1.1; +https://developers.facebook.com/docs/sharing/webmasters/crawler) Chrome/122.0.7020.84 Mobile Safari/537.36"
34.145.2.249 - - [03/Sep/20
show less
Bad Web Bot