๐บ๐ธ
TPI-Abuse
2026-09-01 13:59:54
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.38.120.3 (3.120.38.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.38.120.3 (3.120.38.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 09:59:46.559641 2026] [security2:error] [pid 27235:tid 27235] [client 34.38.120.3:40580] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.gapanda.com"] [uri "/.env.example"] [unique_id "apbaUpnCAi_txu0JsFkWvQAAAEA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 10:55:43
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.38.120.3 (3.120.38.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.38.120.3 (3.120.38.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 06:55:39.657469 2026] [security2:error] [pid 22238:tid 22267] [client 34.38.120.3:40926] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.sellmantitle.com"] [uri "/.env"] [unique_id "apavKxMcZO0zCjph-eGwowAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
gadix
2026-09-01 10:26:42
(5 hours ago)
[01/Sep/2026:12:26:41.077242 +0200] apaoYZvcE3gkp4zUnok4mgAAAFI 34.38.120.3 34130 127.0.0.1 7081
[01 ...
show more
[01/Sep/2026:12:26:41.077242 +0200] apaoYZvcE3gkp4zUnok4mgAAAFI 34.38.120.3 34130 127.0.0.1 7081
[01/Sep/2026:12:26:41.079678 +0200] apaoYY7gw4UCWgJHZpfWlgAAAAM 34.38.120.3 34154 127.0.0.1 7081
[01/Sep/2026:12:26:41.086937 +0200] apaoYY7gw4UCWgJHZpfWmgAAABE 34.38.120.3 34172 127.0.0.1 7081
...
show less
Web App Attack
Anonymous
2026-09-01 10:09:43
(5 hours ago)
Blocked by ModSec and CSF
Port Scan
๐จ๐ญ
zynex
2026-09-01 09:32:50
(6 hours ago)
URL Probing: /wp-config.php.bak
Web App Attack
๐ฎ๐ณ
nadnitin
2026-09-01 08:44:35
(7 hours ago)
Automated trigger via Nginx Police. Reason: PATH-PROBER. Trigger Log: 34.38.120.3 - - [01/Sep/2026:1 ...
show more
Automated trigger via Nginx Police. Reason: PATH-PROBER. Trigger Log: 34.38.120.3 - - [01/Sep/2026:14:14:34 +0530] "GET /.env.production HTTP/1.1" 200 6853 "-" "crusader-worker/1.0"
show less
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-09-01 08:30:43
(7 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
Anonymous
2026-09-01 07:52:13
(8 hours ago)
[osotir.org] httpd-config-scan: logs=/var/log/httpd/access_log; samples=/.env.example | /wp-config.p ...
show more
[osotir.org] httpd-config-scan: logs=/var/log/httpd/access_log; samples=/.env.example | /wp-config.php.bak | /.env.old
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 07:51:58
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.38.120.3 (3.120.38.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.38.120.3 (3.120.38.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 03:51:52.959769 2026] [security2:error] [pid 5501:tid 5501] [client 34.38.120.3:42774] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ftp.pdc14.com"] [uri "/.env.bak"] [unique_id "apaEGM5KMPPJ48n-ekMWhQAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
ecode hosting
2026-09-01 07:04:05
(8 hours ago)
Domain : sunnavturkey.com
Rule : env
2026-09-01 06:27:24 10.100.1.20 GET /.env.local - 443 - 34.38.1 ...
show more
Domain : sunnavturkey.com
Rule : env
2026-09-01 06:27:24 10.100.1.20 GET /.env.local - 443 - 34.38.120.3 HTTP/1.1 crusader-worker/1.0 - sunnavturkey.com 301 0 0 396 98 58 - -
show less
Hacking
SQL Injection
๐ฎ๐ฉ
Burayot
2026-09-01 06:15:31
(9 hours ago)
LF_MODSEC: (mod_security) mod_security (id:949110) triggered by 34.38.120.3 (BE/Belgium/3.120.38.34. ...
show more
LF_MODSEC: (mod_security) mod_security (id:949110) triggered by 34.38.120.3 (BE/Belgium/3.120.38.34.bc.googleusercontent.com): 2 in the last 3600 secs
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 06:04:49
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.38.120.3 (3.120.38.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.38.120.3 (3.120.38.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 02:04:41.536225 2026] [security2:error] [pid 10554:tid 10554] [client 34.38.120.3:48294] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.darrowco.com"] [uri "/.env.dev"] [unique_id "apZq-RAeXvp0WtVfz2FcygAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-09-01 05:17:12
(10 hours ago)
Restricted File Access Attempt. Matched phrase ".env" at REQUEST_FILENAME. (930130-193)
Hacking
Web App Attack
๐ฉ๐ช
mondor.ro
2026-09-01 05:05:23
(10 hours ago)
Cluster member 148.251.176.225 (DE/Germany/antares.webyouridea.ro) said, DENY 34.38.120.3, Reason:[( ...
show more
Cluster member 148.251.176.225 (DE/Germany/antares.webyouridea.ro) said, DENY 34.38.120.3, Reason:[(mod_security) mod_security (id:210492) triggered by 34.38.120.3 (BE/Belgium/3.120.38.34.bc.googleusercontent.com): 3 in the last 3600 secs]; Ports: *; Direction: inout; Trigger: LF_CLUSTER; Logs:
show less
Port Scan
๐ฌ๐ง
foxxelabs
2026-09-01 04:32:10
(11 hours ago)
Automated report from FoxxeLabs Sentinel. Path probed: /.env | Project: anseo | Reason(s): Known exp ...
show more
Automated report from FoxxeLabs Sentinel. Path probed: /.env | Project: anseo | Reason(s): Known exploit path: /.env | User-Agent: crusader-worker/1.0
show less
Web App Attack