🇺🇸
TPI-Abuse
2026-08-29 02:29:24
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.55.212.98 (98.212.55.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.55.212.98 (98.212.55.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 22:29:18.439662 2026] [security2:error] [pid 12528:tid 12528] [client 34.55.212.98:48128] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "music.grhall.com"] [uri "/.env.old"] [unique_id "apJD_ju-h00mITqseBhG2AAAACU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
MatCat
2026-08-29 02:05:13
(15 hours ago)
Banned by fail2ban: apache-webprobe
Port Scan
Bad Web Bot
🇦🇺
A.i.D.A.N.N
2026-08-29 01:22:33
(15 hours ago)
A.i.D.A.N.N: Anomaly Detected - Signature match Web Service - Web application attack detected
Web App Attack
🇩🇪
FD-IX
2026-08-29 00:24:46
(16 hours ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-29 00:00:22
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.55.212.98 (98.212.55.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.55.212.98 (98.212.55.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 20:00:13.070409 2026] [security2:error] [pid 19181:tid 19181] [client 34.55.212.98:55712] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cubicearth.com"] [uri "/.env.backup"] [unique_id "apIhDdB0XlH6c_bpPVlGWwAAAD8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇦
Olexiy Backend
2026-08-28 23:29:51
(17 hours ago)
34.55.212.98
...
Bad Web Bot
Web App Attack
🇮🇹
Inartis
2026-08-28 22:57:58
(18 hours ago)
34.55.212.98 - - [29/Aug/2026:00:57:57 +0200] "GET /.env.save HTTP/1.1" 403 5515 "-" "crusader-worke ...
show more
34.55.212.98 - - [29/Aug/2026:00:57:57 +0200] "GET /.env.save HTTP/1.1" 403 5515 "-" "crusader-worker/1.0"
34.55.212.98 - - [29/Aug/2026:00:57:57 +0200] "GET /.env.backup HTTP/1.1" 403 5515 "-" "crusader-worker/1.0"
34.55.212.98 - - [29/Aug/2026:00:57:57 +0200] "GET /.env HTTP/1.1" 403 5515 "-" "crusader-worker/1.0"
...
show less
Brute-Force
Bad Web Bot
Web App Attack
🇸🇪
vaia.cloud
2026-08-28 22:30:02
(18 hours ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-08-28 21:49:48
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.55.212.98 (98.212.55.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.55.212.98 (98.212.55.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 17:49:42.792161 2026] [security2:error] [pid 8014:tid 8014] [client 34.55.212.98:59314] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.qxz.rcto.us"] [uri "/.env.old"] [unique_id "apICdoBxIJLi5EvCoN0qwgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
4server
2026-08-28 21:34:34
(19 hours ago)
[FriAug2823:34:30.5765492026][security2:error][pid3199925:tid3199988][client34.55.212.98:0]ModSecuri ...
show more
[FriAug2823:34:30.5765492026][security2:error][pid3199925:tid3199988][client34.55.212.98:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Patternmatch\"\(\?i\)\(\?:/\(\?:\^\|/\)\\\\\\\\.\(env\|git\|svn\|hg\|DS_Store\)\|/\(\?:wp-config\|\\\\\\\\.htaccess\|\\\\\\\\.htpasswd\)\|\\\\\\\\.\(\?:sql\|bak\|old\|log\)\$\)\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"156\"][id\"960720\"][msg\"Forbiddenfileaccessattempt\"][severity\"CRITICAL\"][hostname\"fitnessgallery.ch.136-243-54-122.cpanel.site\"][uri\"/.env.bak\"][unique_id\"apH-5gVRBhQ0cX7nyeUUiwAAAFM\"]
show less
Port Scan
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-08-28 21:33:06
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.55.212.98 (98.212.55.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.55.212.98 (98.212.55.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 17:33:01.693737 2026] [security2:error] [pid 9244:tid 9244] [client 34.55.212.98:57222] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.cles-fonctionnel.com"] [uri "/.env.dev"] [unique_id "apH-jXYOaLJpQ7msf3RsaQAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇦
URAN Publishing Service
2026-08-28 21:30:59
(19 hours ago)
[29/Aug/2026:00:30:59 +0300] -- 34.55.212.98 Ban reason: Scanner [CMS_GENERIC] | Request: GET /wp-co ...
show more
[29/Aug/2026:00:30:59 +0300] -- 34.55.212.98 Ban reason: Scanner [CMS_GENERIC] | Request: GET /wp-config.php~ HTTP/1.1
show less
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-28 21:03:14
(20 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.55.212.98 (98.212.55.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.55.212.98 (98.212.55.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 17:03:09.326639 2026] [security2:error] [pid 9118:tid 9118] [client 34.55.212.98:38748] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sendera.imerka.com.mx"] [uri "/.env.bak"] [unique_id "apH3jYub0SDqpVM5Rx6k-wAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-28 19:58:33
(21 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.55.212.98 (98.212.55.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.55.212.98 (98.212.55.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 15:58:29.168954 2026] [security2:error] [pid 20482:tid 20482] [client 34.55.212.98:45188] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.hk.zunosaki.com"] [uri "/wp-config.php.swp"] [unique_id "apHoZYRt5_4psj6BcMUobAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-28 17:33:45
(23 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.55.212.98 (98.212.55.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.55.212.98 (98.212.55.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 13:33:41.685662 2026] [security2:error] [pid 22120:tid 22120] [client 34.55.212.98:51014] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.amybeam.info.amybeam.com"] [uri "/.env.save"] [unique_id "apHGdS2lgdlMO2L4chyxmQAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack