๐บ๐ธ
TPI-Abuse
2026-09-01 13:51:36
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.48.157.242 (242.157.48.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.48.157.242 (242.157.48.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 09:51:32.562103 2026] [security2:error] [pid 3370:tid 3370] [client 34.48.157.242:48718] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.randyshelly.com"] [uri "/.env"] [unique_id "apbYZGjOJpIKrXNczxy3zwAAAD0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 13:00:55
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.48.157.242 (242.157.48.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.48.157.242 (242.157.48.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 09:00:51.381174 2026] [security2:error] [pid 11221:tid 11221] [client 34.48.157.242:39600] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "preskitpc.com"] [uri "/.env.old"] [unique_id "apbMg6i7KUkbRG51aYz2LAAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-09-01 12:19:05
(1 day ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 12:03:27
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.48.157.242 (242.157.48.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.48.157.242 (242.157.48.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 08:03:22.784012 2026] [security2:error] [pid 15419:tid 15419] [client 34.48.157.242:47610] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "dentsville398.org"] [uri "/wp-config.php~"] [unique_id "apa_CuHDR9sL8Hs0l5roMwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 11:04:31
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.48.157.242 (242.157.48.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.48.157.242 (242.157.48.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 07:04:27.561135 2026] [security2:error] [pid 13644:tid 13644] [client 34.48.157.242:48420] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.guardiancns.com"] [uri "/.env"] [unique_id "apaxO7ChLMohyHiN4wu4vgAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Dominik Lysiak
2026-09-01 10:20:38
(1 day ago)
34.48.157.242 - - [01/Sep/2026:12:20:38 +0200] "GET /.env HTTP/1.1" 444 0 "-" "crusader-worker/1.0"
...
show more
34.48.157.242 - - [01/Sep/2026:12:20:38 +0200] "GET /.env HTTP/1.1" 444 0 "-" "crusader-worker/1.0"
34.48.157.242 - - [01/Sep/2026:12:20:38 +0200] "GET /wp-config.php.swp HTTP/1.1" 444 0 "-" "crusader-worker/1.0"
34.48.157.242 - - [01/Sep/2026:12:20:38 +0200] "GET /.env.production HTTP/1.1" 444 0 "-" "crusader-worker/1.0"
...
show less
Web App Attack
๐ฌ๐ง
consul.to
2026-09-01 10:16:18
(1 day ago)
Web attack/malicious scanning detected
Web App Attack
๐ธ๐ช
vaia.cloud
2026-09-01 09:25:02
(1 day ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
๐ฉ๐ช
LRob
2026-09-01 09:20:58
(1 day ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /.env.backup (+12 more) | 2026-09-01 09:20 UTC
show less
Hacking
Web App Attack
๐ณ๐ฑ
MyGlobalFlowers
2026-09-01 09:14:27
(1 day ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 07:40:55
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.48.157.242 (242.157.48.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.48.157.242 (242.157.48.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 03:40:51.231288 2026] [security2:error] [pid 3891:tid 3891] [client 34.48.157.242:43954] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "yacher.com"] [uri "/.env.old"] [unique_id "apaBg72FK97EF8rU9CXeJwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ต๐ฑ
swiszczu
2026-09-01 07:15:35
(1 day ago)
Fail2Ban automatic report:
Multiple forbidden requests in short amount of time:
34.48.157.242 - - [0 ...
show more
Fail2Ban automatic report:
Multiple forbidden requests in short amount of time:
34.48.157.242 - - [01/Sep/2026:09:15:34 +0200] "GET /actuator/configprops HTTP/1.1" 403 153 "-" "crusader-worker/1.0" "-"
34.48.157.242 - - [01/Sep/2026:09:15:34 +0200] "GET /.env.local HTTP/1.1" 403 153 "-" "crusader-worker/1.0" "-"
34.48.157.242 - - [01/Sep/2026:09:15:34 +0200] "GET /_ignition/health-check HTTP/1.1" 403 153 "-" "crusader-worker/1.0" "-"
34.48.157.242 - - [01/Sep/2026:09:15:34 +0200] "GET /.env.old HTTP/1.1" 403 153 "-" "crusader-worker/1.0" "-"
34.48.157.242 - - [01/Sep/2026:09:15:34 +0200] "GET /.env.save HTTP/1.1" 403 153 "-" "crusader-worker/1.0" "-"
34.48.157.242 - - [01/Sep/2026:09:15:34 +0200] "GET /wp-config.php.swp HTTP/1.1" 403 153 "-" "crusader-worker/1.0" "-"
34.48.157.242 - - [01/Sep/2026:09:15:34 +0200] "GET /actuator/env HTTP
show less
Hacking
Web App Attack
๐ฉ๐ช
yitzhaq
2026-09-01 07:07:42
(1 day ago)
34.48.157.242 - - [01/Sep/2026:09:07:39 +0200] "GET /wp-config.php~ HTTP/1.1" 404 4425 "-" "crusader ...
show more
34.48.157.242 - - [01/Sep/2026:09:07:39 +0200] "GET /wp-config.php~ HTTP/1.1" 404 4425 "-" "crusader-worker/1.0"
34.48.157.242 - - [01/Sep/2026:09:07:39 +0200] "GET /wp-config.php.bak HTTP/1.1" 404 4426 "-" "crusader-worker/1.0"
34.48.157.242 - - [01/Sep/2026:09:07:39 +0200] "GET /.env.backup HTTP/1.1" 404 4425 "-" "crusader-worker/1.0"
34.48.157.242 - - [01/Sep/2026:09:07:39 +0200] "GET /env HTTP/1.1" 404 4424 "-" "crusader-worker/1.0"
34.48.157.242 - - [01/Sep/2026:09:07:39 +0200] "GET /.env.example HTTP/1.1" 404 4424 "-" "crusader-worker/1.0"
34.48.157.242 - - [01/Sep/2026:09:07:39 +0200] "GET /_ignition/health-check HTTP/1.1" 404 4426 "-" "crusader-worker/1.0"
34.48.157.242 - - [01/Sep/2026:09:07:39 +0200] "GET /.env.bak HTTP/1.1" 404 4425 "-" "crusader-worker/1.0"
34.48.157.242 - - [01/Sep/2026:09:07:39 +0200] "GET /wp-config.php.swp HTTP/1.1" 404 4426 "-" "crusader-worker/1.0"
34.48.157.242 - - [01/Sep/2026:09:07:39 +0200] "GET /.env HTTP/1.1" 404 4425 "-" "crusader-worker/1.0"
3
show less
Web App Attack
Brute-Force
๐ฒ๐พ
Rizzy
2026-09-01 06:28:10
(2 days ago)
Multiple WAF Violations
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 06:19:45
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.48.157.242 (242.157.48.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.48.157.242 (242.157.48.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 02:19:38.427473 2026] [security2:error] [pid 22606:tid 22606] [client 34.48.157.242:35010] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.andrsn.com"] [uri "/.env.production"] [unique_id "apZuevW-ssFSklFHZPjvZQAAADA"]
show less
Brute-Force
Bad Web Bot
Web App Attack