๐บ๐ธ
TPI-Abuse
2026-09-22 16:59:40
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.48.213.160 (160.213.48.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.48.213.160 (160.213.48.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 12:59:36.783994 2026] [security2:error] [pid 29649:tid 29737] [client 34.48.213.160:48120] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "securitymediaservices.com"] [uri "/.env.prod"] [unique_id "arKz-DF92H0yjAQ_UaA-9gAAAJA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
consul.to
2026-09-22 16:56:46
(1 week ago)
Web attack/malicious scanning detected
Web App Attack
๐ธ๐ช
vaia.cloud
2026-09-22 16:50:02
(1 week ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
๐ฉ๐ช
neckaralb-admin.de
2026-09-22 16:42:48
(1 week ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 16:34:34
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.48.213.160 (160.213.48.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.48.213.160 (160.213.48.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 12:34:31.088855 2026] [security2:error] [pid 26395:tid 26395] [client 34.48.213.160:43932] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ralphharris.org"] [uri "/.env.bak"] [unique_id "arKuF4nWjyeDwmM87M_ptgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
aranguren.org
2026-09-22 16:22:24
(1 week ago)
34.48.213.160 - - [23/Sep/2026:02:22:23 +1000] "GET /actuator/env HTTP/1.1" 404 993 "-" "crusader-wo ...
show more
34.48.213.160 - - [23/Sep/2026:02:22:23 +1000] "GET /actuator/env HTTP/1.1" 404 993 "-" "crusader-worker/1.0"
34.48.213.160 - - [23/Sep/2026:02:22:23 +1000] "GET /.env HTTP/1.1" 404 993 "-" "crusader-worker/1.0"
34.48.213.160 - - [23/Sep/2026:02:22:23 +1000] "GET /.env.prod HTTP/1.1" 404 993 "-" "crusader-worker/1.0"
34.48.213.160 - - [23/Sep/2026:02:22:23 +1000] "GET /.env.production HTTP/1.1" 404 993 "-" "crusader-worker/1.0"
34.48.213.160 - - [23/Sep/2026:02:22:23 +1000] "GET /.env.backup HTTP/1.1" 404 993 "-" "crusader-worker/1.0"
34.48.213.160 - - [23/Sep/2026:02:22:23 +1000] "GET /.env.save HTTP/1.1" 404 993 "-" "crusader-worker/1.0"
...
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-22 15:46:18
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.48.213.160 (160.213.48.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.48.213.160 (160.213.48.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 11:46:14.563603 2026] [security2:error] [pid 22695:tid 22695] [client 34.48.213.160:35810] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ohwaitiforgot.com"] [uri "/.env.bak"] [unique_id "arKixiGiEEjHu5vWF2sFuwAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-09-22 15:42:05
(1 week ago)
[22/Sep/2026:18:42:04 +0300] -- 34.48.213.160 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET / ...
show more
[22/Sep/2026:18:42:04 +0300] -- 34.48.213.160 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET /.env.bak HTTP/1.1
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 14:30:50
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.48.213.160 (160.213.48.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.48.213.160 (160.213.48.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 10:30:46.779861 2026] [security2:error] [pid 30638:tid 30638] [client 34.48.213.160:53912] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "lifestylemedica.com"] [uri "/.env.old"] [unique_id "arKRFlQZJh4zb-H43IAzMgAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-09-22 14:29:38
(1 week ago)
Multiple WAF Violations
Web App Attack
๐ณ๐ฑ
debestelapp
2026-09-22 14:20:11
(1 week ago)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 14:14:12
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.48.213.160 (160.213.48.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.48.213.160 (160.213.48.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 10:14:09.393462 2026] [security2:error] [pid 11264:tid 11264] [client 34.48.213.160:43290] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "k9team.org"] [uri "/.env.bak"] [unique_id "arKNMcrdINmExqYTPOAV3wAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 13:21:03
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.48.213.160 (160.213.48.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.48.213.160 (160.213.48.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 09:20:59.512830 2026] [security2:error] [pid 6277:tid 6277] [client 34.48.213.160:51482] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "garnetcreek.com"] [uri "/.env.production"] [unique_id "arKAu2I-TdLWcHAXpAx7ewAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-09-22 12:55:38
(1 week ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
๐ฌ๐ง
Yosi
2026-09-22 12:07:43
(1 week ago)
RdpGuard detected brute-force attempt on HTTP
Brute-Force