๐บ๐ธ
TPI-Abuse
2026-08-28 15:51:46
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.48.34.62 (62.34.48.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.48.34.62 (62.34.48.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 11:51:41.585119 2026] [security2:error] [pid 31892:tid 31892] [client 34.48.34.62:59098] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "revidiego.com"] [uri "/.env.prod"] [unique_id "apGujR7c6KBMo7eBErS4eAAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-08-28 15:23:54
(9 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-08-28 15:19:38
(9 hours ago)
Multiple WAF Violations
Web App Attack
๐ซ๐ท
aldene.info
2026-08-28 15:02:51
(9 hours ago)
[librenms] Banned by Fail2ban (Jail: syswarden-secretshunter)
Web App Attack
Port Scan
Bad Web Bot
Hacking
๐บ๐ธ
TPI-Abuse
2026-08-28 14:43:58
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.48.34.62 (62.34.48.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.48.34.62 (62.34.48.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 10:43:53.790713 2026] [security2:error] [pid 10927:tid 10984] [client 34.48.34.62:52310] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "onernet.com"] [uri "/.env.old"] [unique_id "apGeqYUXMKUZ2_QkMQ4ypQAAAcc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
Aetherweb Ark
2026-08-28 14:04:28
(10 hours ago)
(mod_security) mod_security (id:949110) triggered by 34.48.34.62 (US/United States/62.34.48.34.bc.go ...
show more
(mod_security) mod_security (id:949110) triggered by 34.48.34.62 (US/United States/62.34.48.34.bc.googleusercontent.com): N in the last X secs
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 13:53:24
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.48.34.62 (62.34.48.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.48.34.62 (62.34.48.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 09:53:19.488328 2026] [security2:error] [pid 3992:tid 3992] [client 34.48.34.62:40316] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.wetheparty.org.stlouisdave.com"] [uri "/.env"] [unique_id "apGSzzcQEnCCcpMV_aOclAAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
london2038.com
2026-08-28 13:49:07
(11 hours ago)
Probing for exploits
34.48.34.62 - - [28/Aug/2026:15:49:03 +0200] "GET /.env.local HTTP/1.1" 422 0 " ...
show more
Probing for exploits
34.48.34.62 - - [28/Aug/2026:15:49:03 +0200] "GET /.env.local HTTP/1.1" 422 0 "-" "crusader-worker/1.0"
34.48.34.62 - - [28/Aug/2026:15:49:03 +0200] "GET /.env.bak HTTP/1.1" 422 0 "-" "crusader-worker/1.0"
show less
Hacking
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-08-28 13:33:44
(11 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
๐ซ๐ท
LoneRider
2026-08-28 13:28:38
(11 hours ago)
[28/Aug/2026:15:28:37.004506 +0200] apGNBcze00L0wcDrMJKZjAAAAAE 34.48.34.62 52886 127.0.0.1 7081
[28 ...
show more
[28/Aug/2026:15:28:37.004506 +0200] apGNBcze00L0wcDrMJKZjAAAAAE 34.48.34.62 52886 127.0.0.1 7081
[28/Aug/2026:15:28:37.016329 +0200] apGNBa14HlOIJ86bKzJnUQAAAAc 34.48.34.62 52914 127.0.0.1 7081
[28/Aug/2026:15:28:37.019710 +0200] apGNBTNXXOXojvI9MZ7YwAAAAAs 34.48.34.62 52918 127.0.0.1 7081
...
show less
Hacking
๐ฉ๐ช
4server
2026-08-28 13:26:56
(11 hours ago)
[FriAug2815:26:50.3250932026][security2:error][pid2705739:tid2705828][client34.48.34.62:0]ModSecurit ...
show more
[FriAug2815:26:50.3250932026][security2:error][pid2705739:tid2705828][client34.48.34.62:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Patternmatch\"\(\?i\)\(\?:/\(\?:\^\|/\)\\\\\\\\.\(env\|git\|svn\|hg\|DS_Store\)\|/\(\?:wp-config\|\\\\\\\\.htaccess\|\\\\\\\\.htpasswd\)\|\\\\\\\\.\(\?:sql\|bak\|old\|log\)\$\)\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"156\"][id\"960720\"][msg\"Forbiddenfileaccessattempt\"][severity\"CRITICAL\"][hostname\"www.immobiliaretrentino.it\"][uri\"/.env.bak\"][unique_id\"apGMmryUDMsezmTKwjUP-AAAAMM\"]
show less
Port Scan
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 13:19:05
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.48.34.62 (62.34.48.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.48.34.62 (62.34.48.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 09:19:01.538054 2026] [security2:error] [pid 8832:tid 8832] [client 34.48.34.62:38106] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.binasplace.thinkingepic.com"] [uri "/.env.save"] [unique_id "apGKxR0hFHNo4jS6H9y-TAAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 12:53:04
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.48.34.62 (62.34.48.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.48.34.62 (62.34.48.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 08:52:58.836649 2026] [security2:error] [pid 26637:tid 26637] [client 34.48.34.62:38456] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "elizabeth-furlow.com"] [uri "/.env.bak"] [unique_id "apGEqsxkbJTJN9k5AzhRcQAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 12:24:37
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.48.34.62 (62.34.48.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.48.34.62 (62.34.48.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 08:24:29.428943 2026] [security2:error] [pid 515:tid 515] [client 34.48.34.62:45022] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "lenosillevis.com"] [uri "/.env.prod"] [unique_id "apF9_ZPAvGJTd-21bTLWJwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-08-28 12:06:55
(12 hours ago)
Scanning/Probing (20)
Brute-Force
Web App Attack