🇺🇸
TPI-Abuse
2026-09-04 15:00:17
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.185.78.146 (146.78.185.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.185.78.146 (146.78.185.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 11:00:09.911251 2026] [security2:error] [pid 17557:tid 17557] [client 34.185.78.146:52288] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "pontiacpalace.com"] [uri "/.env.bak"] [unique_id "aprc-YXuBk3eVPjwhazikwAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-04 14:57:02
(6 hours ago)
Unauthorized SSH login attempts
Brute-Force
SSH
🇨🇦
arsonist
2026-09-04 14:47:12
(6 hours ago)
This IP accessed the path /.env.save, which is banned. Powered by ListenCaddy
Bad Web Bot
Web App Attack
🇳🇱
e.fierstra
2026-09-04 14:41:43
(6 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
🇩🇪
FD-IX
2026-09-04 14:15:58
(6 hours ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 14:07:40
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.185.78.146 (146.78.185.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.185.78.146 (146.78.185.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 10:07:34.591338 2026] [security2:error] [pid 3503:tid 3503] [client 34.185.78.146:39968] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.jerryglass.net"] [uri "/.env.local"] [unique_id "aprQptkq7mWN4ijkWnvHuAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 13:50:01
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.185.78.146 (146.78.185.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.185.78.146 (146.78.185.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 09:49:57.554811 2026] [security2:error] [pid 658:tid 658] [client 34.185.78.146:58530] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "airedaleflyer.bridgital.com"] [uri "/.env.save"] [unique_id "aprMhZLkXT_o8sAoaFkq7QAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
Skyrider
2026-09-04 12:52:26
(8 hours ago)
crowdsecurity/http-sensitive-files
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 12:31:20
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.185.78.146 (146.78.185.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.185.78.146 (146.78.185.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 08:31:13.506037 2026] [security2:error] [pid 5175:tid 5175] [client 34.185.78.146:50544] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "gdpeters.com"] [uri "/.env.bak"] [unique_id "apq6EcVOekAuYkZEBcnpbQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 11:45:13
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.185.78.146 (146.78.185.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.185.78.146 (146.78.185.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 07:45:08.221523 2026] [security2:error] [pid 14047:tid 14047] [client 34.185.78.146:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.portfoliolighting.net"] [uri "/.ENV"] [unique_id "apqvRIcdr5UL8RIR9Eq9zgAAADo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
raph
2026-09-04 11:04:47
(10 hours ago)
[DOT FILES] crawler *.env*, .git*, .config*, etc.
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 10:51:29
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.185.78.146 (146.78.185.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.185.78.146 (146.78.185.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 06:51:23.299613 2026] [security2:error] [pid 20715:tid 21000] [client 34.185.78.146:40262] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "nankerphelge.opticaldesignconcepts.com"] [uri "/.env.prod"] [unique_id "apqiqxKoCyJEX5z1mHPjVgAAANQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 10:22:05
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.185.78.146 (146.78.185.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.185.78.146 (146.78.185.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 06:21:57.577679 2026] [security2:error] [pid 3491:tid 3491] [client 34.185.78.146:60182] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "notariapenco.tecnoconce.com"] [uri "/.env.prod"] [unique_id "apqbxXf7Zt4hbK6CQVkcYAAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
Lee Daniel
2026-09-04 10:01:52
(11 hours ago)
34.185.78.146 - - [04/Sep/2026:06:01:51 -0400] "GET /.env HTTP/1.1" 403 6290 "-" "crusader-worker/1. ...
show more
34.185.78.146 - - [04/Sep/2026:06:01:51 -0400] "GET /.env HTTP/1.1" 403 6290 "-" "crusader-worker/1.0"
...
show less
DDoS Attack
Web Spam
Email Spam
Port Scan
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 09:52:38
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.185.78.146 (146.78.185.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.185.78.146 (146.78.185.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 05:52:31.590084 2026] [security2:error] [pid 17753:tid 17753] [client 34.185.78.146:38216] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "gpaarch.com"] [uri "/.env.save"] [unique_id "apqU333VaWaelDsIgoEVXQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack