🇮🇩
Burayot
2026-09-05 07:33:04
(12 hours ago)
LF_APACHE_403: 34.39.202.143 (BR/Brazil/143.202.39.34.bc.googleusercontent.com), more than 10 Apache ...
show more
LF_APACHE_403: 34.39.202.143 (BR/Brazil/143.202.39.34.bc.googleusercontent.com), more than 10 Apache 403 hits in the last 3600 secs
show less
Web App Attack
🇧🇾
lns.bz
2026-09-05 07:18:41
(12 hours ago)
.env scanning [BY]
Web App Attack
🇺🇸
etu brutus
2026-09-05 06:46:55
(13 hours ago)
34.39.202.143 Blocked by [Attack Vector List]
...
Hacking
Brute-Force
Exploited Host
🇧🇪
holos.pt
2026-09-04 15:00:03
(1 day ago)
Blocked for WP Config File back-up probing in query string: /wp-config.php.swp
Web App Attack
🇩🇪
paissangroup
2026-09-04 14:38:02
(1 day ago)
Multiple WAF Violations
Web App Attack
🇳🇱
debestelapp
2026-09-04 14:20:12
(1 day ago)
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 13:45:14
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.39.202.143 (143.202.39.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.39.202.143 (143.202.39.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 09:45:08.400173 2026] [security2:error] [pid 3074853:tid 3074986] [client 34.39.202.143:60826] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ahmedalbanna.com"] [uri "/.env.old"] [unique_id "aprLZBBOMVLn240jkbtW9AAAARQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 13:27:38
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.39.202.143 (143.202.39.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.39.202.143 (143.202.39.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 09:27:33.503957 2026] [security2:error] [pid 5021:tid 5021] [client 34.39.202.143:52026] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "srosa.danged.com"] [uri "/.env.example"] [unique_id "aprHRUuMkCjSQiYINfHESwAAADg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-04 12:49:00
(1 day ago)
Spring.Boot.Actuator.Unauthorized.Access
Hacking
🇺🇸
TPI-Abuse
2026-09-04 12:38:39
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.39.202.143 (143.202.39.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.39.202.143 (143.202.39.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 08:38:34.143551 2026] [security2:error] [pid 679499:tid 679499] [client 34.39.202.143:57616] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "saltyrootsyogaco.com"] [uri "/wp-config.php.bak"] [unique_id "apq7yppVs4BL9SbZJhX8fgAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
Gabriel Camargo
2026-09-04 11:52:21
(1 day ago)
34.39.202.143 - - [04/Sep/2026:06:52:21 -0500] "GET /.env.production HTTP/1.1" 301 178 "-" "crusader ...
show more
34.39.202.143 - - [04/Sep/2026:06:52:21 -0500] "GET /.env.production HTTP/1.1" 301 178 "-" "crusader-worker/1.0"
34.39.202.143 - - [04/Sep/2026:06:52:21 -0500] "GET /.env HTTP/1.1" 301 178 "-" "crusader-worker/1.0"
34.39.202.143 - - [04/Sep/2026:06:52:21 -0500] "GET /.env.prod HTTP/1.1" 301 178 "-" "crusader-worker/1.0"
...
show less
Brute-Force
SSH
🇪🇸
alferez
2026-09-04 11:47:26
(1 day ago)
Searching .(env|sql|zip|tar|rar) files
Hacking
Exploited Host
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 11:46:14
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.39.202.143 (143.202.39.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.39.202.143 (143.202.39.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 07:46:09.062628 2026] [security2:error] [pid 14986:tid 14986] [client 34.39.202.143:51540] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.quinlaneducationfoundation.com"] [uri "/.env.save"] [unique_id "apqvgUdUoo3mkK8opFBvjwAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-04 11:23:31
(1 day ago)
GET /.env.old HTTP/1.1
...
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 11:16:19
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.39.202.143 (143.202.39.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.39.202.143 (143.202.39.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 07:16:11.970207 2026] [security2:error] [pid 13271:tid 13271] [client 34.39.202.143:43650] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cosplayculture.com"] [uri "/.env.backup"] [unique_id "apqoe7mRT1NkLUO5ATm0vAAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack