🇺🇸
TPI-Abuse
2026-09-04 14:09:02
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.150.32.70 (70.32.150.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.150.32.70 (70.32.150.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 10:08:53.366393 2026] [security2:error] [pid 20789:tid 20789] [client 34.150.32.70:47878] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.dentistholidaycards.com"] [uri "/.env"] [unique_id "aprQ9czymu-ct1YjxcuF_wAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
e.fierstra
2026-09-04 13:47:13
(1 day ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 13:27:56
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.150.32.70 (70.32.150.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.150.32.70 (70.32.150.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 09:27:51.444257 2026] [security2:error] [pid 20045:tid 20045] [client 34.150.32.70:52356] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sittser.com"] [uri "/wp-config.php.bak"] [unique_id "aprHVyntgqZWJwzvwHACqwAAACU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
WeCloudit-Anti-Abuse
2026-09-04 12:31:32
(1 day ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
🇯🇵
VXG-NET
2026-09-04 12:15:55
(1 day ago)
port=80, indicator_type=info-leak
Hacking
🇫🇷
Feelautom
2026-09-04 11:07:24
(1 day ago)
[FeelAutom Auto-Ban] PathScan: /.env.backup (Score: 202)
Port Scan
🇳🇱
javierin
2026-09-04 10:56:09
(1 day ago)
34.150.32.70 - blogs.javierin.com - - [04/Sep/2026:10:56:08 +0000] "GET /actuator/env HTTP/1.1" 404 ...
show more
34.150.32.70 - blogs.javierin.com - - [04/Sep/2026:10:56:08 +0000] "GET /actuator/env HTTP/1.1" 404 7362 "-" "crusader-worker/1.0"
34.150.32.70 - blogs.javierin.com - - [04/Sep/2026:10:56:08 +0000] "GET /.env.bak HTTP/1.1" 404 7362 "-" "crusader-worker/1.0"
...
show less
Web App Attack
Hacking
🇩🇪
XICTRON
2026-09-04 10:35:05
(1 day ago)
ModSecurity rule violation detected by Fail2Ban
Web App Attack
🇩🇪
lolyay
2026-09-04 10:17:22
(1 day ago)
34.150.32.70 - - [04/Sep/2026:10:17:21 +0000] "GET /.env HTTP/1.1" 200 4 "-" "crusader-worker/1.0"
3 ...
show more
34.150.32.70 - - [04/Sep/2026:10:17:21 +0000] "GET /.env HTTP/1.1" 200 4 "-" "crusader-worker/1.0"
34.150.32.70 - - [04/Sep/2026:10:17:21 +0000] "GET /.env.example HTTP/1.1" 200 4 "-" "crusader-worker/1.0"
...
show less
Web App Attack
Bad Web Bot
🇫🇷
COMAITE
2026-09-04 09:15:05
(1 day ago)
Suspicious URL access.
Web App Attack
🇸🇪
vaia.cloud
2026-09-04 09:10:05
(1 day ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 08:57:05
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.150.32.70 (70.32.150.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.150.32.70 (70.32.150.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 04:57:00.088604 2026] [security2:error] [pid 1420:tid 1444] [client 34.150.32.70:49004] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "tieco.salvoni.com"] [uri "/.env.old"] [unique_id "apqH3JyWrnu_DsJunTr33wAAAIg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 08:29:40
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.150.32.70 (70.32.150.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.150.32.70 (70.32.150.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 04:29:33.850380 2026] [security2:error] [pid 20695:tid 20695] [client 34.150.32.70:58050] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.ezsmiledental.com"] [uri "/.env.local"] [unique_id "apqBbfoMsIpedz2kGE8DOAAAACA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇴
jad-abuse
2026-09-04 08:28:24
(1 day ago)
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: env_probe ...
show more
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: env_probe, scanner_ua, source_backup, config_backup, ignition_debug, actuator. Observed by 1 sensor(s); 42 hits.
show less
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 07:47:36
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.150.32.70 (70.32.150.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.150.32.70 (70.32.150.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 03:47:29.478723 2026] [security2:error] [pid 12552:tid 12552] [client 34.150.32.70:47664] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "furballaudio.com"] [uri "/.env"] [unique_id "app3kXucEdhiWvj4QUoscAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack