Anonymous
2026-09-04 15:20:02
(39 minutes ago)
suspicious request in access.log
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 15:18:03
(41 minutes ago)
(mod_security) mod_security (id:210492) triggered by 34.76.131.23 (23.131.76.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.76.131.23 (23.131.76.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 11:17:54.750038 2026] [security2:error] [pid 27978:tid 27978] [client 34.76.131.23:49824] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.luckydawgs.com"] [uri "/.env.production"] [unique_id "aprhIhRCd_4UAVivzobUCwAAAD4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
raph
2026-09-04 15:00:14
(59 minutes ago)
[Wordpress] crawler /wp-admin/*, /wp-content/*, etc.
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 14:01:39
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.76.131.23 (23.131.76.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.76.131.23 (23.131.76.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 10:01:35.079814 2026] [security2:error] [pid 26556:tid 26632] [client 34.76.131.23:45424] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "oswgr.com.wwwhst.com"] [uri "/.env.save"] [unique_id "aprPPxGE3qyeT5IYYBD6lwAAAYk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 13:36:47
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.76.131.23 (23.131.76.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.76.131.23 (23.131.76.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 09:36:42.051449 2026] [security2:error] [pid 3074849:tid 3074875] [client 34.76.131.23:51790] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "fevini.com"] [uri "/.env.example"] [unique_id "aprJagjXAH3cjr1k_gTuAQAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇷🇴
clauss
2026-09-04 12:33:56
(3 hours ago)
34.76.131.23 - - [04/Sep/2026:15:33:56 +0300] "GET /wp-config.php.bak HTTP/1.1" 403 10361 "-" "crusa ...
show more
34.76.131.23 - - [04/Sep/2026:15:33:56 +0300] "GET /wp-config.php.bak HTTP/1.1" 403 10361 "-" "crusader-worker/1.0"
34.76.131.23 - - [04/Sep/2026:15:33:56 +0300] "GET /.env.production HTTP/1.1" 403 10357 "-" "crusader-worker/1.0"
...
show less
Web App Attack
🇩🇪
netclix.gr
2026-09-04 12:25:57
(3 hours ago)
(mod_security) mod_security triggered on hostname [redacted] 34.76.131.23 (BE/Belgium/23.131.76.34.b ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.76.131.23 (BE/Belgium/23.131.76.34.bc.googleusercontent.com): (CF_ENABLE)
show less
SQL Injection
🇺🇸
TPI-Abuse
2026-09-04 12:00:08
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.76.131.23 (23.131.76.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.76.131.23 (23.131.76.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 08:00:03.798947 2026] [security2:error] [pid 5220:tid 5220] [client 34.76.131.23:56874] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "taekwondoit.com"] [uri "/.env.example"] [unique_id "apqyw1OuTItFz4XB-gdS4gAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
Aetherweb Ark
2026-09-04 11:23:58
(4 hours ago)
(mod_security) mod_security (id:949110) triggered by 34.76.131.23 (BE/Belgium/23.131.76.34.bc.google ...
show more
(mod_security) mod_security (id:949110) triggered by 34.76.131.23 (BE/Belgium/23.131.76.34.bc.googleusercontent.com): N in the last X secs
show less
Web App Attack
Anonymous
2026-09-04 11:23:03
(4 hours ago)
Bot / scanning and/or hacking attempts: GET /actuator/configprops HTTP/1.1, GET /_ignition/health-ch ...
show more
Bot / scanning and/or hacking attempts: GET /actuator/configprops HTTP/1.1, GET /_ignition/health-check HTTP/1.1, GET /.env HTTP/1.1, GET /.env.production HTTP/1.1, GET /wp-config.php~ HTTP/1.1, GET /.env.example HTTP/1.1, GET /wp-config.php.bak HTTP/1.1, GET /actuator/env HTTP/1.1, GET /.env.dev HTTP/1.1, GET /.env.backup HTTP/1.1
show less
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 11:14:59
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.76.131.23 (23.131.76.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.76.131.23 (23.131.76.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 07:14:54.556876 2026] [security2:error] [pid 12240:tid 12240] [client 34.76.131.23:43410] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.pages4you.com"] [uri "/.env.backup"] [unique_id "apqoLomP8Jz5WV8sRMoNawAAACM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 10:50:03
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.76.131.23 (23.131.76.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.76.131.23 (23.131.76.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 06:49:56.136032 2026] [security2:error] [pid 12530:tid 12530] [client 34.76.131.23:53664] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "virttee.title26.com"] [uri "/.env.prod"] [unique_id "apqiVMrS6P9vVB9ToeFGkQAAAEU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇵🇫
www.gregorymariani.com
2026-09-04 09:54:50
(6 hours ago)
34.76.131.23 - - [04/Sep/2026:09:54:49 +0000] "GET /.env HTTP/1.1" 404 12182 "-" "crusader-worker/1. ...
show more
34.76.131.23 - - [04/Sep/2026:09:54:49 +0000] "GET /.env HTTP/1.1" 404 12182 "-" "crusader-worker/1.0" 399 0.001 [default-cv-service-80] [] 10.244.41.139:3000 12182 0.001 404 cb232378026d61c218b5dcea3b65fe46
34.76.131.23 - - [04/Sep/2026:09:54:49 +0000] "GET /actuator/env HTTP/1.1" 404 12182 "-" "crusader-worker/1.0" 407 0.002 [default-cv-service-80] [] 10.244.41.150:3000 12182 0.002 404 3fb2de7ac21ab61ed94008be521a1fad
34.76.131.23 - - [04/Sep/2026:09:54:49 +0000] "GET /.env.dev HTTP/1.1" 404 12182 "-" "crusader-worker/1.0" 403 0.005 [default-cv-service-80] [] 10.244.41.150:3000 12182 0.004 404 17e314439563d6297fbc306b630d3c69
34.76.131.23 - - [04/Sep/2026:09:54:49 +0000] "GET /.env.old HTTP/1.1" 404 12182 "-" "crusader-worker/1.0" 403 0.010 [default-cv-service-80] [] 10.244.41.139:3000 12182 0.010 404 c124e7048decea11397521eaad01a3f2
34.76.131.23 - - [04/Sep/2026:09:54:49 +0000] "GET /.env.production HTTP/1.1" 404 12182 "-" "crusader-worker/1.0" 410 0.005 [default-cv-service-80] [] 1
...
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 09:54:27
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.76.131.23 (23.131.76.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.76.131.23 (23.131.76.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 05:54:23.404180 2026] [security2:error] [pid 11145:tid 11162] [client 34.76.131.23:46642] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "gw.absurdotron.com"] [uri "/.env.save"] [unique_id "apqVT3rzwxXVEFl6VeBSPQAAAQ8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 09:17:57
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.76.131.23 (23.131.76.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.76.131.23 (23.131.76.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 05:17:52.577592 2026] [security2:error] [pid 28353:tid 28353] [client 34.76.131.23:41424] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kevinjewell.com"] [uri "/.env.save"] [unique_id "apqMwG4hAu_jvRSGeVk74AAAADs"]
show less
Brute-Force
Bad Web Bot
Web App Attack