🇺🇸
TPI-Abuse
2026-09-04 15:22:27
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.39.93.212 (212.93.39.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.39.93.212 (212.93.39.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 11:22:20.007599 2026] [security2:error] [pid 22728:tid 22728] [client 34.39.93.212:57370] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.coloradofingerprinting.com"] [uri "/.env.save"] [unique_id "apriLPNYNRtvvumfN9rFugAAACU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
poundawebsiteltd
2026-09-04 15:18:19
(1 day ago)
Malicious activity in general-malicious. Evidence: (apache_probe) Failed Access (403/404) 34.39.93.2 ...
show more
Malicious activity in general-malicious. Evidence: (apache_probe) Failed Access (403/404) 34.39.93.212 (GB/United Kingdom/[REDACTED_DOMAIN]): 20 in the last 3600 secs | UA: (apache_probe) Failed Access (403/404) 34.39.93.212 (GB/United Kingdom/212.93.39.34.bc.googleusercontent.com): 20 in the last 3600 secs
show less
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 14:05:39
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.39.93.212 (212.93.39.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.39.93.212 (212.93.39.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 10:05:32.824001 2026] [security2:error] [pid 31194:tid 31194] [client 34.39.93.212:51006] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.pierrebastin.com"] [uri "/.env.example"] [unique_id "aprQLB63D5Riq1IJ0PpUYQAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
dynamix
2026-09-04 13:43:10
(1 day ago)
Multiple WAF Violations
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 13:02:06
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.39.93.212 (212.93.39.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.39.93.212 (212.93.39.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 09:01:58.849072 2026] [security2:error] [pid 20541:tid 20541] [client 34.39.93.212:52538] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "shellyfamily.com"] [uri "/.env.prod"] [unique_id "aprBRg9dYXWrSB5_ELLrXQAAACA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇮🇩
IndoAbuse
2026-09-04 12:55:07
(1 day ago)
Malicious web crawling, scanning for vulnerabilities and hidden files (404 flood).
Port Scan
Brute-Force
Bad Web Bot
🇳🇱
WeCloudit-Anti-Abuse
2026-09-04 12:31:42
(1 day ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-04 11:22:57
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.39.93.212 (212.93.39.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.39.93.212 (212.93.39.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 07:22:50.255499 2026] [security2:error] [pid 18720:tid 18720] [client 34.39.93.212:58132] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "esad.com"] [uri "/.env"] [unique_id "apqqCk3dQy_6Ref8ybeoegAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
raph
2026-09-04 10:37:32
(1 day ago)
[Wordpress] crawler /wp-admin/*, /wp-content/*, etc.
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 10:22:25
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.39.93.212 (212.93.39.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.39.93.212 (212.93.39.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 06:22:20.868490 2026] [security2:error] [pid 15578:tid 15578] [client 34.39.93.212:58540] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "oldmaninthepeanut.com"] [uri "/.env.production"] [unique_id "apqb3Cnos87Of8gjY_SlwgAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 08:23:00
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.39.93.212 (212.93.39.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.39.93.212 (212.93.39.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 04:22:54.921125 2026] [security2:error] [pid 4692:tid 4777] [client 34.39.93.212:52678] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.certifiedecommerceconsultant.com"] [uri "/wp-config.php.bak"] [unique_id "app_3qTWtaz_ebYj_UumQQAAAVc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
debestelapp
2026-09-04 08:05:10
(1 day ago)
Web App Attack
🇹🇼
kk_it_man
2026-09-04 07:53:03
(1 day ago)
ET INFO Request to Hidden Environment File - Inbound
ET WEB_SERVER Tilde in URI - potential .php~ ...
show more
ET INFO Request to Hidden Environment File - Inbound
ET WEB_SERVER Tilde in URI - potential .php~ source disclosure vulnerability
show less
Port Scan
🇩🇪
tsZero
2026-09-04 07:35:58
(1 day ago)
Scan example: path=/.env.local status=403
Hacking
🇺🇸
TPI-Abuse
2026-09-04 07:29:25
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.39.93.212 (212.93.39.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.39.93.212 (212.93.39.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 03:29:18.731270 2026] [security2:error] [pid 8673:tid 8673] [client 34.39.93.212:39606] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "brodyworks.com"] [uri "/wp-config.php.bak"] [unique_id "appzTqxKW-IJhK2pu8C__wAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack