πΊπΈ
TPI-Abuse
2026-09-01 13:48:22
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.64.116.88 (88.116.64.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.64.116.88 (88.116.64.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 09:48:13.352895 2026] [security2:error] [pid 19668:tid 19668] [client 34.64.116.88:49496] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.primelb.com"] [uri "/wp-config.php.swp"] [unique_id "apbXnXAZJWs5E0g9QeXahgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-01 13:07:42
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.64.116.88 (88.116.64.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.64.116.88 (88.116.64.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 09:07:36.409931 2026] [security2:error] [pid 8340:tid 8340] [client 34.64.116.88:35918] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ppcspetsitting.com"] [uri "/wp-config.php~"] [unique_id "apbOGEc85RDLhCK64MlwJgAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
mravb
2026-09-01 12:42:20
(9 hours ago)
34.64.116.88 - - [01/Sep/2026:15:42:19 +0300] "GET /.env.bak HTTP/1.1" 404 3378 "-" "crusader-worker ...
show more
34.64.116.88 - - [01/Sep/2026:15:42:19 +0300] "GET /.env.bak HTTP/1.1" 404 3378 "-" "crusader-worker/1.0"
...
show less
Web App Attack
Hacking
π³π±
sernate
2026-09-01 11:20:38
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.64.116.88 (KR/South Korea/88.116.64.34.bc.go ...
show more
(mod_security) mod_security (id:210492) triggered by 34.64.116.88 (KR/South Korea/88.116.64.34.bc.googleusercontent.com): 10 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_MODSEC
show less
Brute-Force
πΊπΈ
TPI-Abuse
2026-09-01 11:09:38
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.64.116.88 (88.116.64.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.64.116.88 (88.116.64.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 07:09:33.302437 2026] [security2:error] [pid 2910:tid 2910] [client 34.64.116.88:57766] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.pinkrays.com"] [uri "/.env.local"] [unique_id "apaybUueIfupxFkCOVBqfAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
Dennis
2026-09-01 11:04:02
(11 hours ago)
34.64.116.88 has been banned for triggering http-sensitive-files (5 events over 29.812602ms).
Brute-Force
Web App Attack
πΈπͺ
vaia.cloud
2026-09-01 10:15:01
(12 hours ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
π¨π¦
polycoda
2026-09-01 10:07:38
(12 hours ago)
AutoBlock: π― Vulnerability Scanner (Non Decay-Based) - βοΈ Configuration File Access (Non Decay-Based ...
show more
AutoBlock: π― Vulnerability Scanner (Non Decay-Based) - βοΈ Configuration File Access (Non Decay-Based)
show less
Hacking
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-01 09:19:25
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.64.116.88 (88.116.64.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.64.116.88 (88.116.64.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 05:19:21.817856 2026] [security2:error] [pid 10316:tid 10316] [client 34.64.116.88:56602] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "stapleton.stapleton.productions"] [uri "/.env.example"] [unique_id "apaYmZB0ZxrH4DGJNWf6tAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-01 08:53:24
(13 hours ago)
34.64.116.88 - - [01/Sep/2026:10:53:16 +0200] "GET /wp-config.php.bak HTTP/1.1" 403 146 "-" "crusade ...
show more
34.64.116.88 - - [01/Sep/2026:10:53:16 +0200] "GET /wp-config.php.bak HTTP/1.1" 403 146 "-" "crusader-worker/1.0"
...
show less
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-01 07:41:00
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.64.116.88 (88.116.64.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.64.116.88 (88.116.64.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 03:40:55.620968 2026] [security2:error] [pid 31059:tid 31059] [client 34.64.116.88:37910] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "zenithxen.com"] [uri "/.env.dev"] [unique_id "apaBhyPfDJy33BjLPYgXQAAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
interbiznw.com
2026-09-01 06:42:43
(15 hours ago)
fail2ban-ban
Hacking
Brute-Force
Exploited Host
Web App Attack
π³π΄
jad-abuse
2026-09-01 06:33:32
(15 hours ago)
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: env_probe ...
show more
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: env_probe, scanner_ua, source_backup, actuator, ignition_debug, config_backup. Observed by 1 sensor(s); 43 hits.
show less
Hacking
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-01 06:04:39
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.64.116.88 (88.116.64.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.64.116.88 (88.116.64.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 02:04:33.999805 2026] [security2:error] [pid 29855:tid 29855] [client 34.64.116.88:60876] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.pintoresdecasascdmx.com"] [uri "/.env.old"] [unique_id "apZq8cu3lrbbkZzR99mJiQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π¨π
zynex
2026-09-01 04:27:03
(18 hours ago)
URL Probing: /wp-config.php~
Web App Attack