๐บ๐ธ
TPI-Abuse
2026-09-01 13:48:16
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.41.164.24 (24.164.41.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.41.164.24 (24.164.41.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 09:48:09.941945 2026] [security2:error] [pid 18960:tid 18960] [client 34.41.164.24:50756] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.beckersystems.net"] [uri "/.env.save"] [unique_id "apbXmTtSxVnY7wkIMFMJwAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ท๐ด
iulianh
2026-09-01 13:07:25
(7 hours ago)
80,443
Brute-Force
SSH
๐ณ๐ฑ
thedreamer.nl
2026-09-01 13:03:50
(7 hours ago)
34.41.164.24 - - [01/Sep/2026:15:02:19 +0200] "GET /wp-config.php~ HTTP/1.1" 403 85 "-" "crusader-wo ...
show more
34.41.164.24 - - [01/Sep/2026:15:02:19 +0200] "GET /wp-config.php~ HTTP/1.1" 403 85 "-" "crusader-worker/1.0" "US" "Council Bluffs" "41.25910" "-95.85170"
34.41.164.24 - - [01/Sep/2026:15:02:19 +0200] "GET /.env.local HTTP/1.1" 403 85 "-" "crusader-worker/1.0" "US" "Council Bluffs" "41.25910" "-95.85170"
34.41.164.24 - - [01/Sep/2026:15:02:19 +0200] "GET /.env.backup HTTP/1.1" 403 85 "-" "crusader-worker/1.0" "US" "Council Bluffs" "41.25910" "-95.85170"
34.41.164.24 - - [01/Sep/2026:15:02:19 +0200] "GET /.env.production HTTP/1.1" 403 85 "-" "crusader-worker/1.0" "US" "Council Bluffs" "41.25910" "-95.85170"
...
show less
Hacking
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
big-cloud.nl
2026-09-01 12:12:57
(8 hours ago)
Try to access /.env
Web App Attack
๐ฉ๐ช
todix
2026-09-01 11:08:04
(9 hours ago)
WebAttack or semilar from 34.41.164.24
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 11:01:25
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.41.164.24 (24.164.41.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.41.164.24 (24.164.41.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 07:01:20.434848 2026] [security2:error] [pid 9833:tid 9833] [client 34.41.164.24:46366] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.allisonannestudios.com"] [uri "/wp-config.php.bak"] [unique_id "apawgOpYVAh_NyXtP6S06AAAADE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-01 10:46:11
(10 hours ago)
(mod_security) mod_security triggered on hostname [redacted] 34.41.164.24 (US/United States/24.164.4 ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.41.164.24 (US/United States/24.164.41.34.bc.googleusercontent.com)
show less
SQL Injection
๐ง๐ช
FrankNeirynck
2026-09-01 10:15:56
(10 hours ago)
aisofico.ttl.be 34.41.164.24 - - [01/Sep/2026:12:15:55 +0200] "GET /.env.bak HTTP/1.1" 404 162 "-" " ...
show more
aisofico.ttl.be 34.41.164.24 - - [01/Sep/2026:12:15:55 +0200] "GET /.env.bak HTTP/1.1" 404 162 "-" "crusader-worker/1.0" 0.000
aisofico.ttl.be 34.41.164.24 - - [01/Sep/2026:12:15:55 +0200] "GET /storage/logs/laravel.log HTTP/1.1" 404 1267 "-" "crusader-worker/1.0" 0.001
aisofico.ttl.be 34.41.164.24 - - [01/Sep/2026:12:15:55 +0200] "GET /actuator/configprops HTTP/1.1" 404 1267 "-" "crusader-worker/1.0" 0.001
...
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 10:06:12
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.41.164.24 (24.164.41.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.41.164.24 (24.164.41.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 06:06:07.753274 2026] [security2:error] [pid 30902:tid 30902] [client 34.41.164.24:49076] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "tugofwarrior.com.teamwakimphotography.com"] [uri "/wp-config.php~"] [unique_id "apajj-VszZkoOqwLPHcOpgAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ด
jad-abuse
2026-09-01 09:35:11
(11 hours ago)
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: ignition_ ...
show more
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: ignition_debug, scanner_ua, env_probe, source_backup, actuator, config_backup. Observed by 1 sensor(s); 19 hits.
show less
Hacking
Web App Attack
๐ฌ๐ง
Aetherweb Ark
2026-09-01 08:53:05
(12 hours ago)
(mod_security) mod_security (id:949110) triggered by 34.41.164.24 (US/United States/24.164.41.34.bc. ...
show more
(mod_security) mod_security (id:949110) triggered by 34.41.164.24 (US/United States/24.164.41.34.bc.googleusercontent.com): N in the last X secs
show less
Web App Attack
๐ฉ๐ช
Bedios GmbH
2026-09-01 08:51:25
(12 hours ago)
Login credentials theft attempt
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-01 08:25:35
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.41.164.24 (24.164.41.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.41.164.24 (24.164.41.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 04:25:33.009340 2026] [security2:error] [pid 226456:tid 226585] [client 34.41.164.24:44350] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "malvadocuaderno.com"] [uri "/.env.local"] [unique_id "apaL_SrdEraH6Tx-Bu-YvAAAAQ4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
paissangroup
2026-09-01 08:15:44
(12 hours ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 07:52:47
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.41.164.24 (24.164.41.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.41.164.24 (24.164.41.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 03:52:39.465887 2026] [security2:error] [pid 26278:tid 26278] [client 34.41.164.24:38726] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.ohnosound.com"] [uri "/.env.example"] [unique_id "apaER5CINtGq5RQ8F1uVdAAAADc"]
show less
Brute-Force
Bad Web Bot
Web App Attack