๐บ๐ธ
TPI-Abuse
2026-09-01 13:48:45
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.23.10.15 (15.10.23.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.23.10.15 (15.10.23.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 09:48:37.794402 2026] [security2:error] [pid 11644:tid 11644] [client 34.23.10.15:55086] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.frontlinefirestop.com"] [uri "/.env.old"] [unique_id "apbXtSK19o-s9lBAFKCvVAAAACE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-01 12:29:42
(3 hours ago)
34.23.10.15 - - [01/Sep/2026:07:29:42 -0500] "GET /.env.backup HTTP/1.1" 403 199 "-" "crusader-worke ...
show more
34.23.10.15 - - [01/Sep/2026:07:29:42 -0500] "GET /.env.backup HTTP/1.1" 403 199 "-" "crusader-worker/1.0" 34.23.10.15
34.23.10.15 - - [01/Sep/2026:07:29:42 -0500] "GET /.env.local HTTP/1.1" 403 199 "-" "crusader-worker/1.0" 34.23.10.15
34.23.10.15 - - [01/Sep/2026:07:29:42 -0500] "GET /.env.example HTTP/1.1" 403 199 "-" "crusader-worker/1.0" 34.23.10.15
34.23.10.15 - - [01/Sep/2026:07:29:42 -0500] "GET /.env.production HTTP/1.1" 403 199 "-" "crusader-worker/1.0" 34.23.10.15
34.23.10.15 - - [01/Sep/2026:07:29:42 -0500] "GET /.env.old HTTP/1.1" 403 199 "-" "crusader-worker/1.0" 34.23.10.15
34.23.10.15 - - [01/Sep/2026:07:29:42 -0500] "GET /.env.save HTTP/1.1" 403 199 "-" "crusader-worker/1.0" 34.23.10.15
34.23.10.15 - - [01/Sep/2026:07:29:42 -0500] "GET /.env HTTP/1.1" 403 199 "-" "crusader-worker/1.0" 34.23.10.15
34.23.10.15 - - [01/Sep/2026:07:29:42 -0500] "GET /.env.dev HTTP/1.1" 403 199 "-" "crusader-worker/1.0" 34.23.10.15
34.23.10.15 - - [01/Sep/2026:07:29:42 -0500] "GET /.env.bak
...
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 11:03:59
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.23.10.15 (15.10.23.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.23.10.15 (15.10.23.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 07:03:54.755989 2026] [security2:error] [pid 28753:tid 28753] [client 34.23.10.15:34758] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.denkyusalesca.com"] [uri "/.env.save"] [unique_id "apaxGn1A-espSS2lVL1OEQAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
AWW-Admin
2026-09-01 11:00:52
(4 hours ago)
(mod_security) mod_security triggered on hostname [redacted] 34.23.10.15 (US/United States/15.10.23. ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.23.10.15 (US/United States/15.10.23.34.bc.googleusercontent.com)
show less
SQL Injection
๐บ๐ธ
TPI-Abuse
2026-09-01 10:09:20
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.23.10.15 (15.10.23.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.23.10.15 (15.10.23.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 06:09:15.696565 2026] [security2:error] [pid 29742:tid 29911] [client 34.23.10.15:55022] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "indigocapital.es"] [uri "/.env.production"] [unique_id "apakS-_wdJAdgtQQjjxNwwAAAYE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-01 09:19:05
(6 hours ago)
Bot / scanning and/or hacking attempts: GET /wp-config.php.swp HTTP/1.1, GET /.env.backup HTTP/1.1, ...
show more
Bot / scanning and/or hacking attempts: GET /wp-config.php.swp HTTP/1.1, GET /.env.backup HTTP/1.1, GET /actuator/configprops HTTP/1.1, GET /wp-config.php~ HTTP/1.1, GET /.env.dev HTTP/1.1, GET /.env.production HTTP/1.1
show less
Hacking
Web App Attack
๐ฉ๐ช
raph
2026-09-01 09:14:54
(6 hours ago)
[DOT FILES] crawler *.env*, .git*, .config*, etc.
Bad Web Bot
Web App Attack
๐ฌ๐ง
Aetherweb Ark
2026-09-01 08:19:37
(7 hours ago)
(mod_security) mod_security (id:949110) triggered by 34.23.10.15 (US/United States/15.10.23.34.bc.go ...
show more
(mod_security) mod_security (id:949110) triggered by 34.23.10.15 (US/United States/15.10.23.34.bc.googleusercontent.com): N in the last X secs
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 07:50:48
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.23.10.15 (15.10.23.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.23.10.15 (15.10.23.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 03:50:42.349484 2026] [security2:error] [pid 9804:tid 9804] [client 34.23.10.15:36930] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "gabver.com"] [uri "/.env.save"] [unique_id "apaD0i235Bh2-NFLdakqzQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
Mendip_Defender
2026-09-01 06:31:27
(9 hours ago)
[01/Sep/2026:07:31:29.814965 +0100] apZxQTovh059K9DdwUzh8AAAAEw 34.23.10.15 34482 188.246.206.60 708 ...
show more
[01/Sep/2026:07:31:29.814965 +0100] apZxQTovh059K9DdwUzh8AAAAEw 34.23.10.15 34482 188.246.206.60 7081
[01/Sep/2026:07:31:38.588702 +0100] apZxSjovh059K9DdwUzh8QAAAEM 34.23.10.15 46224 188.246.206.60 7081
...
show less
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-09-01 05:40:45
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.23.10.15 (15.10.23.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.23.10.15 (15.10.23.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 01:40:27.876120 2026] [security2:error] [pid 9977:tid 9977] [client 34.23.10.15:52180] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "i-med.com"] [uri "/.env.local"] [unique_id "apZlS87aJOgoTLJweJ90qgAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 04:47:06
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.23.10.15 (15.10.23.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.23.10.15 (15.10.23.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 00:46:58.103383 2026] [security2:error] [pid 3236:tid 3236] [client 34.23.10.15:60334] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "highstakeslearning.com"] [uri "/.env.old"] [unique_id "apZYwmtseG9_FltccMso0wAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-09-01 04:40:50
(11 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐ท๐บ
DZBOT
2026-09-01 04:32:01
(11 hours ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 04:20:24
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.23.10.15 (15.10.23.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.23.10.15 (15.10.23.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 00:20:19.999403 2026] [security2:error] [pid 25878:tid 25905] [client 34.23.10.15:54184] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "nederbragt.net"] [uri "/.env.production"] [unique_id "apZSg1R6gF3crBQtiO_25QAAANg"]
show less
Brute-Force
Bad Web Bot
Web App Attack