🇺🇸
TPI-Abuse
2026-09-06 06:35:05
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.50.98.16 (16.98.50.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.50.98.16 (16.98.50.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 02:34:57.736036 2026] [security2:error] [pid 7476:tid 7476] [client 34.50.98.16:38294] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "dodgersboosterclub.com"] [uri "/wp-config.php.bak"] [unique_id "ap0JkTxXgWAAknQgc-YpCAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 02:57:33
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.50.98.16 (16.98.50.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.50.98.16 (16.98.50.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 22:57:27.534019 2026] [security2:error] [pid 22132:tid 22132] [client 34.50.98.16:44380] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.synercom.org"] [uri "/.env"] [unique_id "apzWl2EwxndJNh2CM-DXWgAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
kosada.com
2026-09-06 02:29:07
(1 day ago)
Repeated exploit attempts, for example: /.env.save /.env (HTTP/1.1 port 443)
Web App Attack
🇫🇷
dynamix
2026-09-06 02:09:45
(1 day ago)
Multiple WAF Violations
Web App Attack
🇳🇱
javierin
2026-09-06 02:02:10
(1 day ago)
34.50.98.16 - mazda.javierin.com - - [06/Sep/2026:02:02:09 +0000] "GET /.env.backup HTTP/1.1" 404 73 ...
show more
34.50.98.16 - mazda.javierin.com - - [06/Sep/2026:02:02:09 +0000] "GET /.env.backup HTTP/1.1" 404 7362 "-" "crusader-worker/1.0"
34.50.98.16 - mazda.javierin.com - - [06/Sep/2026:02:02:09 +0000] "GET /.env.local HTTP/1.1" 404 7362 "-" "crusader-worker/1.0"
...
show less
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-06 01:49:22
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.50.98.16 (16.98.50.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.50.98.16 (16.98.50.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 21:49:15.929720 2026] [security2:error] [pid 24517:tid 24517] [client 34.50.98.16:58706] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "samuelcurtis.com"] [uri "/.env"] [unique_id "apzGm6XL17Qy4vqNLw7NcQAAAC8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-06 01:44:30
(1 day ago)
Aggressive web scan
Web App Attack
🇳🇱
BlueWire Hosting
2026-09-06 01:14:07
(1 day ago)
Probing websites for vulnerabilities
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 01:08:40
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.50.98.16 (16.98.50.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.50.98.16 (16.98.50.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 21:08:35.449696 2026] [security2:error] [pid 6886:tid 6886] [client 34.50.98.16:37904] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.ohiobabe.com"] [uri "/.env.local"] [unique_id "apy9E0C9YrFBVxN2yvTiEAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇧🇷
noconex
2026-09-06 00:45:12
(1 day ago)
Wazuh Alert | Rule ID: 110100 | Desc: Suricata: Exploit (ET WEB_SERVER Tilde in URI - potential .php ...
show more
Wazuh Alert | Rule ID: 110100 | Desc: Suricata: Exploit (ET WEB_SERVER Tilde in URI - potential .php~ source disclosure vulnerability) 34.50.98.16
show less
Port Scan
Brute-Force
SSH
🇺🇸
TPI-Abuse
2026-09-05 23:23:34
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.50.98.16 (16.98.50.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.50.98.16 (16.98.50.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 19:23:30.416548 2026] [security2:error] [pid 3505775:tid 3505882] [client 34.50.98.16:34194] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "liquido.cocoonprojects.com"] [uri "/.env.backup"] [unique_id "apykcr8ERl7gWgWoAPLM8wAAAZg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 22:53:51
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.50.98.16 (16.98.50.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.50.98.16 (16.98.50.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 18:53:46.477869 2026] [security2:error] [pid 5574:tid 5574] [client 34.50.98.16:54740] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.thequakes.com"] [uri "/.env.production"] [unique_id "apydehIuOB9LABf8iOlFmwAAAGo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 22:28:00
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.50.98.16 (16.98.50.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.50.98.16 (16.98.50.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 18:27:55.027627 2026] [security2:error] [pid 14708:tid 14708] [client 34.50.98.16:35346] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.brianbrock.com"] [uri "/.env.bak"] [unique_id "apyXa9n96XmRboT5qhOuEgAAAHk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
raph
2026-09-05 20:57:18
(1 day ago)
[DOT FILES] crawler *.env*, .git*, .config*, etc.
Bad Web Bot
Web App Attack
🇺🇦
URAN Publishing Service
2026-09-05 20:48:37
(1 day ago)
[05/Sep/2026:23:48:37 +0300] -- 34.50.98.16 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET /.e ...
show more
[05/Sep/2026:23:48:37 +0300] -- 34.50.98.16 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET /.env HTTP/1.1
show less
Bad Web Bot
Web App Attack