🇺🇸
TPI-Abuse
2026-09-06 03:51:12
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.156.209.109 (109.209.156.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.156.209.109 (109.209.156.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 23:51:07.757856 2026] [security2:error] [pid 12898:tid 12898] [client 34.156.209.109:34186] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.casademunt.com"] [uri "/.env"] [unique_id "apzjK58ajJML8kJMDZWvFQAAACQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 03:21:45
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.156.209.109 (109.209.156.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.156.209.109 (109.209.156.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 23:21:40.394787 2026] [security2:error] [pid 16155:tid 16155] [client 34.156.209.109:55458] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "destructionstudios.com"] [uri "/.env.old"] [unique_id "apzcRFymzCO6UyZ1hU2dOwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 03:00:42
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.156.209.109 (109.209.156.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.156.209.109 (109.209.156.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 23:00:30.621592 2026] [security2:error] [pid 6520:tid 6520] [client 34.156.209.109:44044] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.backyardbrickoven.com"] [uri "/.env.production"] [unique_id "apzXTlEFVfyUZcy8LYE0lgAAADk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇱🇻
garmtech.com
2026-09-06 03:00:36
(4 hours ago)
Attempted access to sensitive endpoint (/.env.prod) detected. Automated scan or unauthorized probing ...
show more
Attempted access to sensitive endpoint (/.env.prod) detected. Automated scan or unauthorized probing.
show less
Web App Attack
Anonymous
2026-09-06 02:42:01
(4 hours ago)
34.156.209.109 - - [05/Sep/2026:21:42:00 -0500] "GET /.env.prod HTTP/1.1" 403 199 "-" "crusader-work ...
show more
34.156.209.109 - - [05/Sep/2026:21:42:00 -0500] "GET /.env.prod HTTP/1.1" 403 199 "-" "crusader-worker/1.0" 34.156.209.109
34.156.209.109 - - [05/Sep/2026:21:42:00 -0500] "GET /.env.local HTTP/1.1" 403 199 "-" "crusader-worker/1.0" 34.156.209.109
34.156.209.109 - - [05/Sep/2026:21:42:00 -0500] "GET /.env.old HTTP/1.1" 403 199 "-" "crusader-worker/1.0" 34.156.209.109
34.156.209.109 - - [05/Sep/2026:21:42:00 -0500] "GET /.env.backup HTTP/1.1" 403 199 "-" "crusader-worker/1.0" 34.156.209.109
34.156.209.109 - - [05/Sep/2026:21:42:00 -0500] "GET /.env.example HTTP/1.1" 403 199 "-" "crusader-worker/1.0" 34.156.209.109
34.156.209.109 - - [05/Sep/2026:21:42:00 -0500] "GET /.env.production HTTP/1.1" 403 199 "-" "crusader-worker/1.0" 34.156.209.109
34.156.209.109 - - [05/Sep/2026:21:42:00 -0500] "GET /.env.bak HTTP/1.1" 403 199 "-" "crusader-worker/1.0" 34.156.209.109
34.156.209.109 - - [05/Sep/2026:21:42:00 -0500] "GET /.env.save HTTP/1.1" 403 199 "-" "crusader-worker/1.0" 34.156.209.109
34.156
...
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 01:34:20
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.156.209.109 (109.209.156.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.156.209.109 (109.209.156.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 21:34:13.663342 2026] [security2:error] [pid 25249:tid 25249] [client 34.156.209.109:38776] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mscpc.seizetheseason.com"] [uri "/.env.bak"] [unique_id "apzDFeu-7696RiFtdhgNuQAAAEE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 00:00:11
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.156.209.109 (109.209.156.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.156.209.109 (109.209.156.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 20:00:01.403395 2026] [security2:error] [pid 2683:tid 2683] [client 34.156.209.109:52206] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "juniperhills.davidwoodard.com"] [uri "/.env.prod"] [unique_id "apytAXASZT0wJ_AnD_xNDQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
debestelapp
2026-09-05 23:55:14
(7 hours ago)
Web App Attack
🇳🇱
WeCloudit-Anti-Abuse
2026-09-05 23:00:02
(8 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
🇫🇷
dynamix
2026-09-05 22:54:07
(8 hours ago)
Multiple WAF Violations
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 22:46:59
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.156.209.109 (109.209.156.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.156.209.109 (109.209.156.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 18:46:51.863811 2026] [security2:error] [pid 15368:tid 15368] [client 34.156.209.109:55120] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "dosrios.com.mx"] [uri "/.env.save"] [unique_id "apyb2wMp9ADlmGNZ21J0RwAAACE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
consul.to
2026-09-05 21:48:45
(9 hours ago)
Web attack/malicious scanning detected
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 21:04:42
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.156.209.109 (109.209.156.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.156.209.109 (109.209.156.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 17:04:36.700767 2026] [security2:error] [pid 6925:tid 6925] [client 34.156.209.109:60740] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "californiastarsfarm.com.herston.net"] [uri "/.env.backup"] [unique_id "apyD5H2IIr6-MEf3nv-UsgAAACk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
e.fierstra
2026-09-05 20:40:18
(10 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
Anonymous
2026-09-05 20:21:10
(11 hours ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack