๐บ๐ธ
TPI-Abuse
2026-08-27 13:06:55
(36 minutes ago)
(mod_security) mod_security (id:210492) triggered by 34.22.39.75 (75.39.22.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.22.39.75 (75.39.22.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 09:06:50.017701 2026] [security2:error] [pid 28174:tid 28174] [client 34.22.39.75:43796] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sarahgrammer.com"] [uri "/.env.production"] [unique_id "apA2ahKn69N2tcX-GmflgAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
Starburst SysOp Team
2026-08-27 11:42:20
(2 hours ago)
Restricted File Access Attempt. Matched phrase ".env" at REQUEST_FILENAME. (930130-mnz6-1)
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 11:27:10
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.22.39.75 (75.39.22.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.22.39.75 (75.39.22.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 07:27:02.053576 2026] [security2:error] [pid 28189:tid 28189] [client 34.22.39.75:53764] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.wa211.org"] [uri "/wp-config.php.swp"] [unique_id "apAfBkY5W44wqgI2vbrLBgAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 10:56:26
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.22.39.75 (75.39.22.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.22.39.75 (75.39.22.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 06:56:18.997456 2026] [security2:error] [pid 4234:tid 4244] [client 34.22.39.75:42736] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "inkandthreadllc.com"] [uri "/.env.save"] [unique_id "apAX0iN3XfLGuCaKpgmWRQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 10:32:12
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.22.39.75 (75.39.22.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.22.39.75 (75.39.22.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 06:32:06.957210 2026] [security2:error] [pid 2278206:tid 2278287] [client 34.22.39.75:46950] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "stephanie.stauffer.name"] [uri "/wp-config.php.bak"] [unique_id "apASJhrxRNAlh6AoP1Tq-wAAAdM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
big-cloud.nl
2026-08-27 10:01:06
(3 hours ago)
Try to access /.env
Web App Attack
๐ซ๐ท
pm33
2026-08-27 09:04:29
(4 hours ago)
Excessive crawling HTTP 404
Web App Attack
๐ซ๐ฎ
paissangroup
2026-08-27 08:23:22
(5 hours ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 08:17:33
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.22.39.75 (75.39.22.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.22.39.75 (75.39.22.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 04:17:29.394938 2026] [security2:error] [pid 15023:tid 15023] [client 34.22.39.75:44688] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "summithost.com"] [uri "/.env"] [unique_id "ao_ymdwvXbbfsxXWWqnibQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
2000cn.com.au
2026-08-27 06:41:28
(7 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
Anonymous
2026-08-27 06:17:16
(7 hours ago)
2026/08/27 06:17:15 [error] 1492298#1492298: *52160 [client 34.22.39.75] ModSecurity: Access denied ...
show more
2026/08/27 06:17:15 [error] 1492298#1492298: *52160 [client 34.22.39.75] ModSecurity: Access denied with code 403 (phase 2). Matched "Operator `Ge' with parameter `5' against variable `TX:BLOCKING_INBOUND_ANOMALY_SCORE' (Value: `5' ) [file "/usr/local/owasp-modsecurity-crs-4.11.0/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "222"] [id "949110"] [rev ""] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [data ""] [severity "0"] [ver "OWASP_CRS/4.29.0"] [maturity "0"] [accuracy "0"] [tag "anomaly-evaluation"] [tag "OWASP_CRS"] [hostname "www.royalealmond.com"] [uri "/wp-config.php~"] [unique_id "178781143558.723221"] [ref ""], client: 34.22.39.75, server: www.royalealmond.com, request: "GET /wp-config.php~ HTTP/1.1", host: "www.royalealmond.com"
2026/08/27 06:17:15 [error] 1492295#1492295: *52148 [client 34.22.39.75] ModSecurity: Access denied with code 403 (phase 2). Matched "Operator `Ge' with parameter `5' against variable `TX:BLOCKING_INBOUND_ANOMALY_SCORE' (Value: `5' ) [file
...
show less
Brute-Force
๐ซ๐ท
masterguru
2026-08-27 06:07:39
(7 hours ago)
Restricted File Access Attempt. Matched phrase ".env" at REQUEST_FILENAME. (930130-193)
Hacking
Web App Attack
๐ฎ๐ณ
evicky2002
2026-08-27 06:00:33
(7 hours ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
๐ณ๐ฑ
e.fierstra
2026-08-27 05:23:17
(8 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐ฎ๐ฉ
securejdprop
2026-08-27 05:18:40
(8 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/vpatch-env-access.
Hacking
Web App Attack