๐บ๐ธ
TPI-Abuse
2026-09-22 16:38:25
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.158.208.60 (60.208.158.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.158.208.60 (60.208.158.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 12:38:20.390353 2026] [security2:error] [pid 17304:tid 17304] [client 34.158.208.60:55138] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "readyaiminspire.com"] [uri "/.env"] [unique_id "arKu_OtlgveFIqmOVr64KAAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-22 16:37:25
(1 day ago)
Failed login attempt detected by Fail2Ban in plesk-modsecurity jail
Exploited Host
Anonymous
2026-09-22 16:10:02
(1 day ago)
suspicious request in access.log
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 15:48:26
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.158.208.60 (60.208.158.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.158.208.60 (60.208.158.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 11:48:18.914536 2026] [security2:error] [pid 24168:tid 24168] [client 34.158.208.60:46990] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "omahareact.org"] [uri "/.env.example"] [unique_id "arKjQuOFApbRACmhAcpL_QAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Marc
2026-09-22 15:21:46
(2 days ago)
34.158.208.60 - - [22/Sep/2026:17:21:46 +0200] "GET /crusader-404-probe HTTP/1.1" 404 4618 "-" "crus ...
show more
34.158.208.60 - - [22/Sep/2026:17:21:46 +0200] "GET /crusader-404-probe HTTP/1.1" 404 4618 "-" "crusader-worker/1.0" 34.158.208.60 - - [22/Sep/2026:17:21:46 +0200] "GET /.env.save HTTP/1.1" 404 4618 "-" "crusader-worker/1.0" 34.158.208.60 - - [22/Sep/2026:17:21:46 +0200] "GET /.env.production HTTP/1.1" 404 4616 "-" "crusader-worker/1.0"
show less
Brute-Force
๐บ๐ธ
kosada.com
2026-09-22 15:21:42
(2 days ago)
Repeated exploit attempts, for example: /.env.production /.env (HTTP/1.1 port 443)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 14:48:14
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.158.208.60 (60.208.158.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.158.208.60 (60.208.158.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 10:48:07.760615 2026] [security2:error] [pid 26886:tid 26886] [client 34.158.208.60:45128] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.elnixon.com"] [uri "/.env.dev"] [unique_id "arKVJ0ikR5Si5VliO0_42AAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ธ๐ช
vaia.cloud
2026-09-22 14:25:02
(2 days ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 14:11:31
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.158.208.60 (60.208.158.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.158.208.60 (60.208.158.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 10:11:26.131918 2026] [security2:error] [pid 381:tid 381] [client 34.158.208.60:33034] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jsolanogranite.com"] [uri "/.env.backup"] [unique_id "arKMjto5p4uM1kB9LcXFKwAAAC0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 13:54:04
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.158.208.60 (60.208.158.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.158.208.60 (60.208.158.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 09:53:57.515121 2026] [security2:error] [pid 29444:tid 29444] [client 34.158.208.60:44778] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "imagesbyaubrey.com"] [uri "/.env.prod"] [unique_id "arKIddSWK0abN_n26M60NQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-09-22 13:52:10
(2 days ago)
[22/Sep/2026:16:52:09 +0300] -- 34.158.208.60 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.env ...
show more
[22/Sep/2026:16:52:09 +0300] -- 34.158.208.60 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.env.old HTTP/1.1
show less
Bad Web Bot
Web App Attack
๐ฆ๐บ
screwlooseit.com.au
2026-09-22 13:47:05
(2 days ago)
Blocked by CSF 13 firewall - Rule: US/United States/60.208.158.34.bc.googleusercontent.com
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-09-22 13:38:14
(2 days ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-22 13:31:54
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.158.208.60 (60.208.158.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.158.208.60 (60.208.158.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 09:31:49.419866 2026] [security2:error] [pid 28668:tid 28668] [client 34.158.208.60:49568] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "grmvrr.com"] [uri "/.env"] [unique_id "arKDRVbLxt8S34TpGz8IeQAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
BlueWire Hosting
2026-09-22 13:28:04
(2 days ago)
High-confidence malicious configuration/VCS probe
Web App Attack