๐บ๐ธ
TPI-Abuse
2026-09-01 10:29:36
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.187.60.250 (250.60.187.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.187.60.250 (250.60.187.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 06:29:31.989283 2026] [security2:error] [pid 19082:tid 19082] [client 34.187.60.250:46614] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "uccryakima.org"] [uri "/.env.local"] [unique_id "apapC2eB30_wq0Mih6KMmQAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
MusicLibrary
2026-09-01 10:19:18
(1 day ago)
Probing foreign-stack admin panels / known exploit paths (Joomla, phpMyAdmin, phpunit, OWA, etc.)
Bad Web Bot
Web App Attack
๐ฎ๐ฉ
Burayot
2026-09-01 09:30:33
(1 day ago)
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 34.187.60.250 (250.60.187.34.bc.goo ...
show more
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 34.187.60.250 (250.60.187.34.bc.googleusercontent.com): 1 in the last 3600 secs
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 09:23:45
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.187.60.250 (250.60.187.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.187.60.250 (250.60.187.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 05:23:38.472566 2026] [security2:error] [pid 12835:tid 12835] [client 34.187.60.250:49144] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "contiautos.com.grupoporvenir.com"] [uri "/.env.local"] [unique_id "apaZmnvHlP1EhCWf3n8SLwAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 08:33:56
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.187.60.250 (250.60.187.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.187.60.250 (250.60.187.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 04:33:49.294381 2026] [security2:error] [pid 15384:tid 15384] [client 34.187.60.250:39218] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "michaelandkatie.us"] [uri "/.env.bak"] [unique_id "apaN7fAbfIhvCkmsdOxVyAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-01 07:40:02
(1 day ago)
suspicious request in access.log
Web App Attack
Anonymous
2026-09-01 07:15:05
(1 day ago)
(mod_security) mod_security triggered on hostname [redacted])
SQL Injection
๐ซ๐ท
Rom74
2026-09-01 06:41:59
(1 day ago)
[Tue Sep 01 08:41:58.899742 2026] [security2:error] [pid 1939907:tid 129744787994304] [client 34.187 ...
show more
[Tue Sep 01 08:41:58.899742 2026] [security2:error] [pid 1939907:tid 129744787994304] [client 34.187.60.250:0] [client 34.187.60.250] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "teslogiciels.com"] [uri "/.env.old"] [unique_id "apZztkxaNoIhOV_QGrk91QAAAFc"]
[Tue Sep 01 08:41:58.906890 2026] [security2:error] [pid 1939906:tid 129745383581376] [client 34.187.60.250:0] [client 34.187.60.250] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total S
...
show less
Web App Attack
๐ฌ๐ง
consul.to
2026-09-01 06:37:42
(1 day ago)
Web attack/malicious scanning detected
Web App Attack
๐น๐ผ
kk_it_man
2026-09-01 05:23:02
(1 day ago)
ET INFO Request to Hidden Environment File - Inbound
ET WEB_SERVER Tilde in URI - potential .php~ ...
show more
ET INFO Request to Hidden Environment File - Inbound
ET WEB_SERVER Tilde in URI - potential .php~ source disclosure vulnerability
show less
Port Scan
๐บ๐ธ
Vano Ganzzz
2026-09-01 05:09:18
(1 day ago)
Triggered Cloudflare WAF (firewallCustom) from NL.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Prot ...
show more
Triggered Cloudflare WAF (firewallCustom) from NL.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Protocol: HTTP/1.1 (GET method)
Endpoint: /%2eenv
Timestamp: 2026-09-01T05:09:18Z
Ray ID: a341c3141de8b944
UA: crusader-worker/1.0
show less
Bad Web Bot
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-09-01 04:49:28
(1 day ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-01 04:21:47
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.187.60.250 (250.60.187.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.187.60.250 (250.60.187.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 00:21:42.711490 2026] [security2:error] [pid 7810:tid 7810] [client 34.187.60.250:58936] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "new-bethel-baptist-church.com"] [uri "/.env.dev"] [unique_id "apZS1v0gt-N-xCCwiUzk1QAAACQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ธ๐ช
vaia.cloud
2026-09-01 03:50:03
(1 day ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
๐ณ๐ฑ
MyGlobalFlowers
2026-09-01 03:16:50
(1 day ago)
Multiple WAF Violations
Web App Attack