๐บ๐ธ
TPI-Abuse
2026-09-01 11:10:26
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.7.157.39 (39.157.7.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.7.157.39 (39.157.7.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 07:10:21.029421 2026] [security2:error] [pid 3069:tid 3069] [client 34.7.157.39:51524] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.wonboyn.com"] [uri "/.env.old"] [unique_id "apaynd69r7VlVqpO-JqhsgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Catalin Negru
2026-09-01 11:02:38
(1 hour ago)
Recidive ban by fail2ban on server.blackbit.ro
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-09-01 10:55:19
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.7.157.39 (39.157.7.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.7.157.39 (39.157.7.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 06:55:10.330650 2026] [security2:error] [pid 18337:tid 18337] [client 34.7.157.39:56598] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ossinatm.pierrebastin.com"] [uri "/.env.backup"] [unique_id "apavDtw7gf16eImKEnsRqgAAACo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-01 10:30:15
(2 hours ago)
| Suspicious URL access.
Web App Attack
Hacking
SQL Injection
๐บ๐ธ
TPI-Abuse
2026-09-01 10:21:33
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.7.157.39 (39.157.7.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.7.157.39 (39.157.7.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 06:21:28.594257 2026] [security2:error] [pid 20027:tid 20027] [client 34.7.157.39:60780] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "agroeurocommodities.com.asiancommoditiescorporation.com"] [uri "/.env.backup"] [unique_id "apanKFuJjVTFiz5KRVa2xAAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ท๐ด
clauss
2026-09-01 09:32:33
(3 hours ago)
34.7.157.39 - - [01/Sep/2026:12:32:33 +0300] "GET /.env.local HTTP/1.1" 403 10351 "-" "crusader-work ...
show more
34.7.157.39 - - [01/Sep/2026:12:32:33 +0300] "GET /.env.local HTTP/1.1" 403 10351 "-" "crusader-worker/1.0"
34.7.157.39 - - [01/Sep/2026:12:32:33 +0300] "GET /.env.prod HTTP/1.1" 403 10349 "-" "crusader-worker/1.0"
...
show less
Web App Attack
๐ซ๐ท
mail.avx.gr
2026-09-01 09:16:05
(3 hours ago)
(nginxENVSCAN) nginx environment-file scanner detected from 34.7.157.39 (NL/The Netherlands/Groninge ...
show more
(nginxENVSCAN) nginx environment-file scanner detected from 34.7.157.39 (NL/The Netherlands/Groningen/Groningen/39.157.7.34.bc.googleusercontent.com)
show less
Hacking
๐ฎ๐ช
AutosOnShow
2026-09-01 08:58:05
(4 hours ago)
blocked for webapp attack | path requested: / | seen at 2026-09-01 08:57:44.817 |
Web App Attack
๐ฉ๐ช
FD-IX
2026-09-01 08:31:12
(4 hours ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
Anonymous
2026-09-01 08:19:55
(4 hours ago)
34.7.157.39 - - [01/Sep/2026:10:19:54 +0200] "GET /.env.old HTTP/1.1" 404 443 "-" "crusader-worker/1 ...
show more
34.7.157.39 - - [01/Sep/2026:10:19:54 +0200] "GET /.env.old HTTP/1.1" 404 443 "-" "crusader-worker/1.0"
34.7.157.39 - - [01/Sep/2026:10:19:54 +0200] "GET /.env.old HTTP/1.1" 404 294 "-" "crusader-worker/1.0"
34.7.157.39 - - [01/Sep/2026:10:19:54 +0200] "GET /.env.save HTTP/1.1" 404 443 "-" "crusader-worker/1.0"
34.7.157.39 - - [01/Sep/2026:10:19:54 +0200] "GET /.env.save HTTP/1.1" 404 294 "-" "crusader-worker/1.0"
34.7.157.39 - - [01/Sep/2026:10:19:54 +0200] "GET /.env.production HTTP/1.1" 404 443 "-" "crusader-worker/1.0"
34.7.157.39 - - [01/Sep/2026:10:19:54 +0200] "GET /.env.production HTTP/1.1" 404 294 "-" "crusader-worker/1.0"
34.7.157.39 - - [01/Sep/2026:10:19:54 +0200] "GET /env HTTP/1.1" 404 443 "-" "crusader-worker/1.0"
34.7.157.39 - - [01/Sep/2026:10:19:54 +0200] "GET /env HTTP/1.1" 404 294 "-" "crusader-worker/1.0"
34.7.157.39 - - [01/Sep/2026:10:19:54 +0200] "GET /.env.backup HTTP/1.1" 404 443 "-" "crusader-worker/1.0"
34.7.157.39 - - [01/Sep/2026:10:19:54 +0200] "GET /.env
...
show less
Bad Web Bot
Web App Attack
๐ฌ๐ง
consul.to
2026-09-01 07:43:22
(5 hours ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 06:48:27
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.7.157.39 (39.157.7.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.7.157.39 (39.157.7.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 02:48:23.665687 2026] [security2:error] [pid 1638:tid 1638] [client 34.7.157.39:54274] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "thesilverlegion.org.theknowledgemaster.com"] [uri "/wp-config.php.swp"] [unique_id "apZ1N-6H0DoEvkURyhXmmgAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 06:29:13
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.7.157.39 (39.157.7.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.7.157.39 (39.157.7.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 02:29:05.911108 2026] [security2:error] [pid 226456:tid 226591] [client 34.7.157.39:59304] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "surdick.com.faimreps.com"] [uri "/.env.production"] [unique_id "apZwsSrdEraH6Tx-Bu-OOwAAARQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 05:08:41
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.7.157.39 (39.157.7.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.7.157.39 (39.157.7.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 01:08:36.906082 2026] [security2:error] [pid 11350:tid 11350] [client 34.7.157.39:53854] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.barigby.com"] [uri "/.env.bak"] [unique_id "apZd1Bd0ejtybIxzxFt6sQAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-01 04:36:27
(8 hours ago)
Web scanner: GET /actuator/configprops
Web App Attack
Hacking