Anonymous
2026-09-04 08:32:27
(48 minutes ago)
34.7.76.76 - - [04/Sep/2026:03:32:26 -0500] "GET /.env HTTP/1.1" 301 258 "-" "Mozilla/5.0 (compatibl ...
show more
34.7.76.76 - - [04/Sep/2026:03:32:26 -0500] "GET /.env HTTP/1.1" 301 258 "-" "Mozilla/5.0 (compatible; Amazonbot/0.1; +https://developer.amazon.com/support/amazonbot)" 172.71.95.37
34.7.76.76 - - [04/Sep/2026:03:32:26 -0500] "GET /.env.backup HTTP/1.1" 301 258 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; Applebot/0.1; +http://www.apple.com/go/applebot" 104.23.170.32
34.7.76.76 - - [04/Sep/2026:03:32:26 -0500] "GET /.env.development HTTP/1.1" 301 258 "-" "Mozilla/5.0 (Linux; Android 14; Pixel 8) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/109.0.85.95 Mobile Safari/537.36; compatible; Claude-User/1.0; +https://www.anthropic.com/claude-user" 172.71.102.86
34.7.76.76 - - [04/Sep/2026:03:32:26 -0500] "GET /.env.old HTTP/1.1" 301 258 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_5 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.6 Mobile/15E148 Safari/604.1; compatible; Amazonbot/0.1; +https://developer.amazon.com/support/amazonbot" 104.22.109.97
34.7
...
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
Steve
2026-09-04 07:29:34
(1 hour ago)
Repeated attempts against wordpress site
Brute-Force
Web App Attack
🇩🇪
Live Home Cams
2026-09-04 07:27:06
(1 hour ago)
WebApp brute force attack detected. Multiple file scanning attempts from 34.7.76.76. Detected by fai ...
show more
WebApp brute force attack detected. Multiple file scanning attempts from 34.7.76.76. Detected by fail2ban.
show less
Web App Attack
Brute-Force
🇺🇸
TPI-Abuse
2026-09-04 07:05:45
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.7.76.76 (76.76.7.34.bc.googleusercontent.com ...
show more
(mod_security) mod_security (id:210492) triggered by 34.7.76.76 (76.76.7.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 03:05:39.663493 2026] [security2:error] [pid 31926:tid 31926] [client 34.7.76.76:12902] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "proboundary.com"] [uri "/@fs/.env"] [unique_id "apptw4ErYIsGQ8Z8N43ZmQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 06:07:59
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.7.76.76 (76.76.7.34.bc.googleusercontent.com ...
show more
(mod_security) mod_security (id:210492) triggered by 34.7.76.76 (76.76.7.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 02:07:49.758348 2026] [security2:error] [pid 13851:tid 13851] [client 34.7.76.76:63488] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "inwriting.buzz"] [uri "/@fs/.env.local"] [unique_id "appgNWLBaB_nA7PElpd7VwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 05:46:53
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.7.76.76 (76.76.7.34.bc.googleusercontent.com ...
show more
(mod_security) mod_security (id:210492) triggered by 34.7.76.76 (76.76.7.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 01:46:49.911131 2026] [security2:error] [pid 11445:tid 11445] [client 34.7.76.76:18468] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.abeltours.com"] [uri "/@fs/.env"] [unique_id "appbSaVcKGLGe6tpQy_gyQAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 05:28:13
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.7.76.76 (76.76.7.34.bc.googleusercontent.com ...
show more
(mod_security) mod_security (id:210492) triggered by 34.7.76.76 (76.76.7.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 01:28:05.679695 2026] [security2:error] [pid 23302:tid 23302] [client 34.7.76.76:51460] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.thommesen.net"] [uri "/@fs/.env"] [unique_id "appW5Txv-GbpZ7KWHLT83wAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇨🇭
🇨🇭 Hosting
2026-09-04 05:10:36
(4 hours ago)
Automated WAF report: 125-150 blocked requests from this IP detected by our WAF.
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 05:08:41
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.7.76.76 (76.76.7.34.bc.googleusercontent.com ...
show more
(mod_security) mod_security (id:210492) triggered by 34.7.76.76 (76.76.7.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 01:08:37.958872 2026] [security2:error] [pid 1502:tid 1502] [client 34.7.76.76:15108] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.keysenterprise.net"] [uri "/@fs/.env"] [unique_id "appSVQvLAACdeu3HkJe-ZQAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 04:46:25
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.7.76.76 (76.76.7.34.bc.googleusercontent.com ...
show more
(mod_security) mod_security (id:210492) triggered by 34.7.76.76 (76.76.7.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 00:46:17.939595 2026] [security2:error] [pid 3847:tid 3847] [client 34.7.76.76:24938] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.maleein.com"] [uri "/@fs/.env"] [unique_id "appNGSxTsI48JLjrM1YpmwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇧🇪
taivas.nl
2026-09-04 04:33:31
(4 hours ago)
Many_bad_calls
Web App Attack
🇫🇷
masterguru
2026-09-04 04:25:48
(4 hours ago)
Restricted File Access Attempt. Matched phrase ".env" at REQUEST_FILENAME. (930130-195)
Hacking
Web App Attack
🇬🇧
consul.to
2026-09-04 03:21:56
(5 hours ago)
Web attack/malicious scanning detected
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 03:17:17
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.7.76.76 (76.76.7.34.bc.googleusercontent.com ...
show more
(mod_security) mod_security (id:210492) triggered by 34.7.76.76 (76.76.7.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 23:17:09.418880 2026] [security2:error] [pid 5582:tid 5582] [client 34.7.76.76:12876] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.possmartterminal.com"] [uri "/@fs/.env"] [unique_id "apo4NY-3VzNxWShJzhlY3gAAACw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
big-cloud.nl
2026-09-04 03:01:16
(6 hours ago)
Try to access /brandpreventie//@fs/..%252f..%252f..%252f..%252f..%252fapp/.env?raw??
Web App Attack