๐บ๐ธ
TPI-Abuse
2026-09-01 13:52:46
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.24.213.219 (219.213.24.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.24.213.219 (219.213.24.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 09:52:42.746595 2026] [security2:error] [pid 11004:tid 11004] [client 34.24.213.219:54850] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.toxicwater.com"] [uri "/.env.bak"] [unique_id "apbYqgZ9mJvlrLVYJHVJlAAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
2000cn.com.au
2026-09-01 12:59:31
(1 day ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐ฌ๐ง
consul.to
2026-09-01 12:19:51
(1 day ago)
Web attack/malicious scanning detected
Web App Attack
๐ซ๐ท
ELYAZ
2026-09-01 12:13:36
(1 day ago)
(y3) Failed access -byebye- from 34.24.213.219 (US/United States/219.213.24.34.bc.googleusercontent. ...
show more
(y3) Failed access -byebye- from 34.24.213.219 (US/United States/219.213.24.34.bc.googleusercontent.com): (CF_ENABLE)
show less
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-01 10:59:19
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.24.213.219 (219.213.24.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.24.213.219 (219.213.24.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 06:59:16.000100 2026] [security2:error] [pid 22242:tid 22338] [client 34.24.213.219:50970] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.shopcourtneybarton.com"] [uri "/.env.old"] [unique_id "apawA0JyANdOXl3YOOfr2wAAARE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-01 10:48:44
(1 day ago)
2026/09/01 07:48:44 [error] 1369#1369: *1490 access forbidden by rule, client: 34.24.213.219, server ...
show more
2026/09/01 07:48:44 [error] 1369#1369: *1490 access forbidden by rule, client: 34.24.213.219, server: pgadmin4.sorotop.com.br, request: "GET /.env.backup HTTP/1.1", host: "pgadmin4.sorotop.com.br"
2026/09/01 07:48:44 [error] 1368#1368: *1489 access forbidden by rule, client: 34.24.213.219, server: pgadmin4.sorotop.com.br, request: "GET /.env.example HTTP/1.1", host: "pgadmin4.sorotop.com.br"
2026/09/01 07:48:44 [error] 1370#1370: *1492 access forbidden by rule, client: 34.24.213.219, server: pgadmin4.sorotop.com.br, request: "GET /.env.old HTTP/1.1", host: "pgadmin4.sorotop.com.br"
...
show less
Port Scan
๐จ๐ญ
zynex
2026-09-01 09:57:05
(1 day ago)
URL Probing: /.env
Web App Attack
๐ฌ๐ง
Aetherweb Ark
2026-09-01 08:51:05
(1 day ago)
(mod_security) mod_security (id:949110) triggered by 34.24.213.219 (US/United States/219.213.24.34.b ...
show more
(mod_security) mod_security (id:949110) triggered by 34.24.213.219 (US/United States/219.213.24.34.bc.googleusercontent.com): N in the last X secs
show less
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-09-01 08:44:33
(1 day ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐ณ๐ฑ
sernate
2026-09-01 07:51:04
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.24.213.219 (US/United States/219.213.24.34.b ...
show more
(mod_security) mod_security (id:210492) triggered by 34.24.213.219 (US/United States/219.213.24.34.bc.googleusercontent.com): 10 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_MODSEC
show less
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-09-01 07:46:08
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.24.213.219 (219.213.24.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.24.213.219 (219.213.24.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 03:46:03.524834 2026] [security2:error] [pid 23963:tid 23963] [client 34.24.213.219:33760] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ftp.guarinofurnituredesigns.com"] [uri "/.env.dev"] [unique_id "apaCu0xDrakfPNWLGHVs3wAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐น๐ผ
kk_it_man
2026-09-01 07:13:06
(1 day ago)
ET INFO Request to Hidden Environment File - Inbound
ET WEB_SERVER Tilde in URI - potential .php~ ...
show more
ET INFO Request to Hidden Environment File - Inbound
ET WEB_SERVER Tilde in URI - potential .php~ source disclosure vulnerability
show less
Port Scan
๐ฉ๐ช
yitzhaq
2026-09-01 07:08:20
(1 day ago)
34.24.213.219 - - [01/Sep/2026:09:08:18 +0200] "GET /wp-config.php.bak HTTP/1.1" 404 4414 "-" "crusa ...
show more
34.24.213.219 - - [01/Sep/2026:09:08:18 +0200] "GET /wp-config.php.bak HTTP/1.1" 404 4414 "-" "crusader-worker/1.0"
34.24.213.219 - - [01/Sep/2026:09:08:18 +0200] "GET /wp-config.php~ HTTP/1.1" 404 4415 "-" "crusader-worker/1.0"
34.24.213.219 - - [01/Sep/2026:09:08:18 +0200] "GET /.env.example HTTP/1.1" 404 4415 "-" "crusader-worker/1.0"
34.24.213.219 - - [01/Sep/2026:09:08:18 +0200] "GET /actuator/env HTTP/1.1" 404 4415 "-" "crusader-worker/1.0"
34.24.213.219 - - [01/Sep/2026:09:08:18 +0200] "GET /.env.prod HTTP/1.1" 404 4414 "-" "crusader-worker/1.0"
34.24.213.219 - - [01/Sep/2026:09:08:18 +0200] "GET /.env.backup HTTP/1.1" 404 4413 "-" "crusader-worker/1.0"
34.24.213.219 - - [01/Sep/2026:09:08:18 +0200] "GET /.env.save HTTP/1.1" 404 4413 "-" "crusader-worker/1.0"
34.24.213.219 - - [01/Sep/2026:09:08:18 +0200] "GET /.env HTTP/1.1" 404 4414 "-" "crusader-worker/1.0"
34.24.213.219 - - [01/Sep/2026:09:08:18 +0200] "GET /.env.bak HTTP/1.1" 404 4415 "-" "crusader-worker/1.0"
34.24.213.219
show less
Web App Attack
Brute-Force
๐ฉ๐ช
Marc
2026-09-01 05:43:16
(1 day ago)
34.24.213.219 - - [01/Sep/2026:07:43:16 +0200] "GET /wp-config.php.bak HTTP/1.1" 404 4616 "-" "crusa ...
show more
34.24.213.219 - - [01/Sep/2026:07:43:16 +0200] "GET /wp-config.php.bak HTTP/1.1" 404 4616 "-" "crusader-worker/1.0" 34.24.213.219 - - [01/Sep/2026:07:43:16 +0200] "GET /.env.bak HTTP/1.1" 404 4616 "-" "crusader-worker/1.0" 34.24.213.219 - - [01/Sep/2026:07:43:16 +0200] "GET /env HTTP/1.1" 404 4616 "-" "crusader-worker/1.0"
show less
Brute-Force
Anonymous
2026-09-01 05:25:56
(1 day ago)
34.24.213.219 - - [01/Sep/2026:05:25:56 +0000] "GET /.env.prod HTTP/1.1" 404 7053 "-" "crusader-work ...
show more
34.24.213.219 - - [01/Sep/2026:05:25:56 +0000] "GET /.env.prod HTTP/1.1" 404 7053 "-" "crusader-worker/1.0"
...
show less
Bad Web Bot
Web App Attack