🇺🇸
TPI-Abuse
2026-09-08 13:19:41
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.39.196.224 (224.196.39.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.39.196.224 (224.196.39.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 09:19:34.640269 2026] [security2:error] [pid 16426:tid 16426] [client 34.39.196.224:35396] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.addisonchiropracticcenter.com"] [uri "/.env.backup"] [unique_id "aqALZkmCLJCMxjZMURugmQAAACw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
DEV-DNS
2026-09-08 12:37:06
(1 day ago)
(mod_security) mod_security triggered on hostname [redacted])
SQL Injection
Anonymous
2026-09-08 12:00:06
(1 day ago)
Bot / scanning and/or hacking attempts: GET /.env.production HTTP/1.1, GET /.env.save HTTP/1.1, GET ...
show more
Bot / scanning and/or hacking attempts: GET /.env.production HTTP/1.1, GET /.env.save HTTP/1.1, GET /env HTTP/1.1, GET /actuator/configprops HTTP/1.1, GET /.env.old HTTP/1.1, GET /.env.dev HTTP/1.1, GET /actuator/env HTTP/1.1, GET /.env HTTP/1.1, GET /wp-config.php~ HTTP/1.1, GET /crusader-404-probe HTTP/1.1, GET /.env.local HTTP/1.1, GET /_ignition/health-check HTTP/1.1, GET /.env.backup HTTP/1.1, GET /wp-config.php.swp HTTP/1.1
show less
Hacking
Web App Attack
🇩🇪
FD-IX
2026-09-08 04:38:47
(1 day ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
🇳🇱
WeCloudit-Anti-Abuse
2026-09-08 04:18:25
(1 day ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-08 03:52:46
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.39.196.224 (224.196.39.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.39.196.224 (224.196.39.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 23:52:42.385009 2026] [security2:error] [pid 27509:tid 27509] [client 34.39.196.224:39738] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.sunscreenz.com"] [uri "/.env.prod"] [unique_id "ap-GikoGRaZlgS-Nc7prJQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
LRob
2026-09-07 11:22:59
(2 days ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /.env (+1 more) | 2026-09-07 11:22 UTC
show less
Hacking
Web App Attack
🇳🇱
oisecnet
2026-09-06 21:02:59
(3 days ago)
Automated report: Unauthorized vulnerability scanning detected on 2026-09-06. 6629 requests from thi ...
show more
Automated report: Unauthorized vulnerability scanning detected on 2026-09-06. 6629 requests from this IP.
show less
Port Scan
Hacking
Web App Attack
🇧🇾
lns.bz
2026-09-06 06:09:41
(3 days ago)
.env scanning [BY]
Web App Attack
🇩🇪
raph
2026-09-06 02:57:35
(3 days ago)
[Wordpress] crawler /wp-admin/*, /wp-content/*, etc.
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 02:56:06
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.39.196.224 (224.196.39.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.39.196.224 (224.196.39.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 22:56:01.687831 2026] [security2:error] [pid 6874:tid 6874] [client 34.39.196.224:40498] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.itbmsinc.com"] [uri "/.env.dev"] [unique_id "apzWQXYD8zzrJa9ABHeHFwAAACY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 02:35:54
(3 days ago)
(mod_security) mod_security (id:210730) triggered by 34.39.196.224 (224.196.39.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.39.196.224 (224.196.39.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 22:35:51.131670 2026] [security2:error] [pid 30359:tid 30359] [client 34.39.196.224:35246] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||ericgwin.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "ericgwin.com"] [uri "/dump.sql"] [unique_id "apzRhzL0mgPDMPdabVFbGAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 01:33:16
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.39.196.224 (224.196.39.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.39.196.224 (224.196.39.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 21:33:12.171906 2026] [security2:error] [pid 30052:tid 30052] [client 34.39.196.224:47108] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mp3tracks.com"] [uri "/.env.local"] [unique_id "apzC2PnNFT0TGC7zJO2Z-gAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 00:14:14
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.39.196.224 (224.196.39.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.39.196.224 (224.196.39.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 20:14:08.685725 2026] [security2:error] [pid 3480297:tid 3480297] [client 34.39.196.224:41754] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ic1.ic1.biz"] [uri "/.env.prod"] [unique_id "apywUOtaZKuMSjA5Z2aOqQAAACg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 23:48:38
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.39.196.224 (224.196.39.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.39.196.224 (224.196.39.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 19:48:33.720279 2026] [security2:error] [pid 32702:tid 32702] [client 34.39.196.224:55842] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "hatfulofrain.com"] [uri "/.env.production"] [unique_id "apyqUZ_fsmVNjULfg3_3ZQAAAHk"]
show less
Brute-Force
Bad Web Bot
Web App Attack