🇺🇸
TPI-Abuse
2026-09-04 11:51:00
(13 minutes ago)
(mod_security) mod_security (id:210492) triggered by 34.39.205.102 (102.205.39.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.39.205.102 (102.205.39.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 07:50:56.924059 2026] [security2:error] [pid 29222:tid 29222] [client 34.39.205.102:41940] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.artspacecleveland.org"] [uri "/.env.old"] [unique_id "apqwoPKcui-2ZbtryrsA8QAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-04 11:47:04
(17 minutes ago)
GET /.env.local HTTP/1.1
...
Web App Attack
🇨🇭
zynex
2026-09-04 11:19:23
(45 minutes ago)
URL Probing: /wp-config.php~
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 10:59:40
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.39.205.102 (102.205.39.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.39.205.102 (102.205.39.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 06:59:36.467671 2026] [security2:error] [pid 2707:tid 2707] [client 34.39.205.102:32824] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bostonmarathonstories.com"] [uri "/.env.local"] [unique_id "apqkmMy_Cs2XVsz92nExLwAAAE4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇸🇪
vaia.cloud
2026-09-04 10:20:02
(1 hour ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 08:25:56
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.39.205.102 (102.205.39.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.39.205.102 (102.205.39.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 04:25:52.369598 2026] [security2:error] [pid 4690:tid 4737] [client 34.39.205.102:53416] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.culturallyyours.org"] [uri "/.env.backup"] [unique_id "apqAkCaecgXyUbWMJYFBvwAAAEo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
webgobe
2026-09-04 08:18:56
(3 hours ago)
mae-17 : Block hidden directories=>/.env.example(/)
Hacking
🇺🇸
TPI-Abuse
2026-09-04 08:03:18
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.39.205.102 (102.205.39.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.39.205.102 (102.205.39.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 04:03:12.263097 2026] [security2:error] [pid 14125:tid 14125] [client 34.39.205.102:58836] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "doctorc.net"] [uri "/.env.example"] [unique_id "app7QK9tiN65ZRMgCiN3KwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
masterguru
2026-09-04 07:50:46
(4 hours ago)
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 34.39.205.102 (BR/Brazil/102.205.39.3 ...
show more
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 34.39.205.102 (BR/Brazil/102.205.39.34.bc.googleusercontent.com): 1 in the last 3600 secs (0-195)
show less
Hacking
🇺🇸
cwytech
2026-09-04 07:08:48
(4 hours ago)
Fleet-wide ban from the Ghostfleet 👻. Triggered by scenario: crowdsecurity/http-sensitive-files.
Bad Web Bot
Web App Attack
🇿🇦
conure.sh
2026-09-04 07:01:21
(5 hours ago)
csagent: score 24.5: 404 noise floor x2, wp-config backup grab x1, botnet path probe x1; 1 domain(s) ...
show more
csagent: score 24.5: 404 noise floor x2, wp-config backup grab x1, botnet path probe x1; 1 domain(s) in 0s
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 06:02:57
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.39.205.102 (102.205.39.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.39.205.102 (102.205.39.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 02:02:51.962942 2026] [security2:error] [pid 5836:tid 5836] [client 34.39.205.102:38980] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "qa.fluffmoo.org"] [uri "/wp-config.php.bak"] [unique_id "appfC6DNkncGD3OtHgIrZwAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 05:45:15
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.39.205.102 (102.205.39.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.39.205.102 (102.205.39.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 01:45:07.684133 2026] [security2:error] [pid 22746:tid 22746] [client 34.39.205.102:45294] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "intnlc.org"] [uri "/.env.dev"] [unique_id "appa47KDEipGcN8ibrr3XwAAACQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
LRob
2026-09-04 05:19:43
(6 hours ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /.env.example (+12 more) | 2026-09-04 05:19 UTC
show less
Hacking
Web App Attack
🇬🇧
Aetherweb Ark
2026-09-04 05:16:24
(6 hours ago)
(mod_security) mod_security (id:949110) triggered by 34.39.205.102 (BR/Brazil/102.205.39.34.bc.googl ...
show more
(mod_security) mod_security (id:949110) triggered by 34.39.205.102 (BR/Brazil/102.205.39.34.bc.googleusercontent.com): N in the last X secs
show less
Web App Attack