🇺🇸
TPI-Abuse
2026-09-04 15:16:27
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.64.115.243 (243.115.64.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.64.115.243 (243.115.64.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 11:16:22.087794 2026] [security2:error] [pid 16686:tid 16686] [client 34.64.115.243:36832] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.securityzonepr.com"] [uri "/.env"] [unique_id "aprgxldXbM7dnUx7lNdcPAAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 14:37:58
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.64.115.243 (243.115.64.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.64.115.243 (243.115.64.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 10:37:52.308790 2026] [security2:error] [pid 23006:tid 23128] [client 34.64.115.243:56978] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "deyyoungart.com"] [uri "/.env.save"] [unique_id "aprXwOK_eLa5AsS1DMl-igAAARg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇮
YF
2026-09-04 14:31:06
(15 hours ago)
WordPress config file probe
Web App Attack
Anonymous
2026-09-04 14:08:04
(15 hours ago)
Bot / scanning and/or hacking attempts: GET /_ignition/health-check HTTP/1.1, GET /.env.production H ...
show more
Bot / scanning and/or hacking attempts: GET /_ignition/health-check HTTP/1.1, GET /.env.production HTTP/1.1, GET /crusader-404-probe HTTP/1.1, GET /.env.bak HTTP/1.1, GET /.env.prod HTTP/1.1, GET /.env.dev HTTP/1.1, GET /wp-config.php.swp HTTP/1.1, GET /.env.local HTTP/1.1, GET /.env.example HTTP/1.1, GET /storage/logs/laravel.log HTTP/1.1, GET /.env.old HTTP/1.1, GET /.env HTTP/1.1, GET /wp-config.php~ HTTP/1.1, GET /actuator/configprops HTTP/1.1, GET /.env.save HTTP/1.1, GET /wp-config.php.bak HTTP/1.1, GET /actuator/env HTTP/1.1
show less
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 14:06:56
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.64.115.243 (243.115.64.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.64.115.243 (243.115.64.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 10:06:49.332235 2026] [security2:error] [pid 4355:tid 4364] [client 34.64.115.243:59760] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.clicktojammarketplace.com"] [uri "/.env.example"] [unique_id "aprQecKZoYaNsgIbwhu9WgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-04 13:40:03
(15 hours ago)
suspicious request in access.log
Web App Attack
🇬🇧
consul.to
2026-09-04 13:23:53
(16 hours ago)
Web attack/malicious scanning detected
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 13:21:01
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.64.115.243 (243.115.64.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.64.115.243 (243.115.64.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 09:20:55.262086 2026] [security2:error] [pid 29459:tid 29459] [client 34.64.115.243:54078] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "colbygrenier.com.jimgrenier.com"] [uri "/.env.save"] [unique_id "aprFtz5dJrdQyb2ejIY5MwAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 12:47:33
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.64.115.243 (243.115.64.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.64.115.243 (243.115.64.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 08:47:30.258304 2026] [security2:error] [pid 27443:tid 27443] [client 34.64.115.243:56980] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "atm.michaelpmcgrath.com"] [uri "/.env"] [unique_id "apq94gb8rGVEJi-Lq52dRgAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
WeCloudit-Anti-Abuse
2026-09-04 12:32:17
(17 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
🇸🇪
vaia.cloud
2026-09-04 12:30:02
(17 hours ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
🇫🇷
dynamix
2026-09-04 12:20:52
(17 hours ago)
Multiple WAF Violations
Web App Attack
🇺🇸
mnsf
2026-09-04 12:05:25
(17 hours ago)
Scanning/Probing (20)
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 11:49:15
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.64.115.243 (243.115.64.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.64.115.243 (243.115.64.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 07:49:10.882328 2026] [security2:error] [pid 2825000:tid 2825123] [client 34.64.115.243:33902] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.anthonydalessandro.com"] [uri "/wp-config.php~"] [unique_id "apqwNkGr36Bd67PuxWTkTQAAAQY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-04 11:20:11
(18 hours ago)
| Suspicious URL access.
Web App Attack
Hacking
SQL Injection