🇩🇪
Séfora Srl
2026-09-08 16:07:42
(41 minutes ago)
crowdsecurity/http-sensitive-files detected by CrowdSec
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 11:19:27
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.48.85.93 (93.85.48.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.48.85.93 (93.85.48.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 07:19:22.207932 2026] [security2:error] [pid 1714858:tid 1715293] [client 34.48.85.93:45248] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ftp.sloveniaflyfishing.com"] [uri "/.env.dev"] [unique_id "ap_vOn0bCZPretB_348hJgAAAc8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 10:57:48
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.48.85.93 (93.85.48.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.48.85.93 (93.85.48.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 06:57:41.556096 2026] [security2:error] [pid 15076:tid 15076] [client 34.48.85.93:44578] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ftp.emiliofatuzzo.com"] [uri "/.env.dev"] [unique_id "ap_qJQmW6HedDM0gjesPSAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
consul.to
2026-09-08 10:15:04
(6 hours ago)
Web attack/malicious scanning detected
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 06:23:07
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.48.85.93 (93.85.48.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.48.85.93 (93.85.48.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 02:23:01.198065 2026] [security2:error] [pid 14361:tid 14361] [client 34.48.85.93:47586] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ftp.joqlawn.com"] [uri "/.env.backup"] [unique_id "ap-pxVmxQvek9LlhQRfimQAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇿
Antinson
2026-09-08 06:17:00
(10 hours ago)
Scraping with a high error ratio and request rate
Bad Web Bot
🇳🇱
e.fierstra
2026-09-08 04:32:22
(12 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
🇳🇱
homeshowdomain.nl
2026-09-07 21:59:22
(18 hours ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-09-06.
show less
Web App Attack
SSH
Hacking
🇺🇸
chronos
2026-09-07 20:18:08
(20 hours ago)
[AUTORAVALT][[07/09/2026 - 17:18:08 -03:00 UTC]
Attack from [Google LLC]
[34.48.85.93][93.85.48.34.b ...
show more
[AUTORAVALT][[07/09/2026 - 17:18:08 -03:00 UTC]
Attack from [Google LLC]
[34.48.85.93][93.85.48.34.bc.googleusercontent.com]
Action: BLocKed
DDoS Attack -> Participating in distributed denial-of-service.
Phishing -> Phishing websites and/or email.
Web Spam -> Comment/forum spam, HTTP referer spam, or other CMS spam.
Blog Spam -> CMS blog comment spam.
Web App]
...
show less
DDoS Attack
Phishing
Web Spam
Blog Spam
Web App Attack
🇳🇱
tpjg
2026-09-07 20:10:15
(20 hours ago)
Automated: 15 requests with error status in 120s window from 34.48.85.93.
Evidence: /wp-config.php.b ...
show more
Automated: 15 requests with error status in 120s window from 34.48.85.93.
Evidence: /wp-config.php.bak:301,/_ignition/health-check:301,/actuator/configprops:301,/.env.dev:301,/actuator/env:301,/env:301,/.env.old:301,/.env.example:301,/.env.save:301,/.env.local:301,/.env.bak:301,/.env.backup:301,/.env.production:301,/.env.prod:301,/.env:301
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 03:52:07
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.48.85.93 (93.85.48.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.48.85.93 (93.85.48.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 23:52:01.491374 2026] [security2:error] [pid 3720258:tid 3720258] [client 34.48.85.93:53514] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.hartflicker.com"] [uri "/.env"] [unique_id "apzjYZXnigms-YgfAmY2rQAAAJM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
LRob
2026-09-06 03:50:59
(2 days ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /wp-config.php.bak (+9 more) | 2026-09-06 03:50 UTC
show less
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 02:59:30
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.48.85.93 (93.85.48.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.48.85.93 (93.85.48.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 22:59:22.051645 2026] [security2:error] [pid 24741:tid 24741] [client 34.48.85.93:33146] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.oncuegraphics.com"] [uri "/.env.dev"] [unique_id "apzXCsPkl4mQSXmYAGRuTgAAACo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 01:47:28
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.48.85.93 (93.85.48.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.48.85.93 (93.85.48.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 21:47:21.277229 2026] [security2:error] [pid 6085:tid 6085] [client 34.48.85.93:41734] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.entetanimiento.com"] [uri "/.env.dev"] [unique_id "apzGKRaGOjHrWu8XC0RKRAAAADw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
consul.to
2026-09-06 01:46:04
(2 days ago)
Web attack/malicious scanning detected
Web App Attack