๐บ๐ธ
TPI-Abuse
2026-09-01 13:48:46
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.150.230.1 (1.230.150.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.150.230.1 (1.230.150.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 09:48:42.471235 2026] [security2:error] [pid 29095:tid 29095] [client 34.150.230.1:46082] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.ifilemuseum.com"] [uri "/.env.backup"] [unique_id "apbXuqWIXnHwx2k_tSHYDwAAACs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 13:12:42
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.150.230.1 (1.230.150.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.150.230.1 (1.230.150.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 09:12:34.501199 2026] [security2:error] [pid 23472:tid 23472] [client 34.150.230.1:48866] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "lazymanvegan.com"] [uri "/.env"] [unique_id "apbPQvzu-bBwteZrGO4dSQAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
kommunos
2026-09-01 13:05:20
(1 day ago)
/.env.production
Web App Attack
๐บ๐ธ
mnsf
2026-09-01 12:05:25
(1 day ago)
Abuse Detected (9)
Brute-Force
Web App Attack
๐ซ๐ฎ
paissangroup
2026-09-01 12:02:00
(1 day ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 10:59:10
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.150.230.1 (1.230.150.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.150.230.1 (1.230.150.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 06:59:04.009032 2026] [security2:error] [pid 15654:tid 15654] [client 34.150.230.1:51568] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.halvaughan.com"] [uri "/.env.bak"] [unique_id "apav-Mn0PIFUg0G1Q5EdpgAAAB8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
2000cn.com.au
2026-09-01 10:56:48
(1 day ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
Anonymous
2026-09-01 10:30:02
(1 day ago)
suspicious request in access.log
Web App Attack
๐ฎ๐น
Inartis
2026-09-01 10:10:04
(1 day ago)
34.150.230.1 - - [01/Sep/2026:12:10:03 +0200] "GET /.env HTTP/1.1" 403 5654 "-" "crusader-worker/1.0 ...
show more
34.150.230.1 - - [01/Sep/2026:12:10:03 +0200] "GET /.env HTTP/1.1" 403 5654 "-" "crusader-worker/1.0"
34.150.230.1 - - [01/Sep/2026:12:10:03 +0200] "GET /.env.production HTTP/1.1" 403 5654 "-" "crusader-worker/1.0"
34.150.230.1 - - [01/Sep/2026:12:10:03 +0200] "GET /.env.dev HTTP/1.1" 403 5654 "-" "crusader-worker/1.0"
...
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 09:31:13
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.150.230.1 (1.230.150.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.150.230.1 (1.230.150.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 05:31:06.986945 2026] [security2:error] [pid 828:tid 828] [client 34.150.230.1:44534] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "com.asiancommoditiescorporation.com"] [uri "/.env.local"] [unique_id "apabWj7ztcLYPCYpv-ZGjgAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
raph
2026-09-01 08:52:48
(1 day ago)
[DOT FILES] crawler *.env*, .git*, .config*, etc.
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 08:29:31
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.150.230.1 (1.230.150.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.150.230.1 (1.230.150.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 04:29:26.079589 2026] [security2:error] [pid 21821:tid 21821] [client 34.150.230.1:41992] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mangamaster.hongkonger.org"] [uri "/.env.backup"] [unique_id "apaM5vdhDuX6dQedb3p7vQAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-09-01 07:08:50
(1 day ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 1247
Exploited Host
Web App Attack
๐ซ๐ท
dynamix
2026-09-01 07:04:09
(1 day ago)
Multiple WAF Violations
Web App Attack
๐ท๐บ
DZBOT
2026-09-01 06:49:09
(1 day ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack