๐บ๐ธ
TPI-Abuse
2026-09-01 14:04:26
(13 minutes ago)
(mod_security) mod_security (id:210492) triggered by 34.84.43.149 (149.43.84.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.84.43.149 (149.43.84.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 10:04:19.356291 2026] [security2:error] [pid 20875:tid 20875] [client 34.84.43.149:36840] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.soonerstone.com"] [uri "/.env.save"] [unique_id "apbbY83xrPZ2rww84qGYIQAAACU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 12:49:50
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.84.43.149 (149.43.84.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.84.43.149 (149.43.84.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 08:49:46.889106 2026] [security2:error] [pid 29425:tid 29425] [client 34.84.43.149:52172] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "portfolio-realestate.com"] [uri "/.env.prod"] [unique_id "apbJ6rDG1L4ZyT70Qc82EwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-09-01 11:23:55
(2 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 11:02:06
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.84.43.149 (149.43.84.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.84.43.149 (149.43.84.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 07:01:59.612263 2026] [security2:error] [pid 4031:tid 4051] [client 34.84.43.149:49640] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.ep-dh.com"] [uri "/.env.old"] [unique_id "apawp1RhYWwYeDsFkLvvngAAAUc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฐ๐ท
doll.gl
2026-09-01 10:15:57
(4 hours ago)
CrowdSec: Ip 34.84.43.149 performed 'crowdsecurity/http-sensitive-files' (5 events over 7.2763ms) at ...
show more
CrowdSec: Ip 34.84.43.149 performed 'crowdsecurity/http-sensitive-files' (5 events over 7.2763ms) at 2026-09-01 10:15:57.084080854 +0000 UTC (scenario: crowdsecurity/http-sensitive-files)
show less
Port Scan
Web App Attack
๐ฉ๐ช
LRob
2026-09-01 09:52:45
(4 hours ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /.env.local (+12 more) | 2026-09-01 09:52 UTC
show less
Hacking
Web App Attack
๐บ๐ธ
ersei.net
2026-09-01 09:47:43
(4 hours ago)
Web app exploiting
Web App Attack
Anonymous
2026-09-01 07:52:41
(6 hours ago)
GET /.env.production HTTP/1.1
...
Web App Attack
Anonymous
2026-09-01 07:45:02
(6 hours ago)
suspicious request in access.log
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 06:32:18
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.84.43.149 (149.43.84.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.84.43.149 (149.43.84.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 02:32:14.065267 2026] [security2:error] [pid 19737:tid 19737] [client 34.84.43.149:45808] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "stinecapital.net.anthonyanimalclinic.net"] [uri "/.env.bak"] [unique_id "apZxbpx4kpZZor-vc925oQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐น๐ผ
kk_it_man
2026-09-01 05:13:02
(9 hours ago)
ET INFO Request to Hidden Environment File - Inbound
ET WEB_SERVER Tilde in URI - potential .php~ ...
show more
ET INFO Request to Hidden Environment File - Inbound
ET WEB_SERVER Tilde in URI - potential .php~ source disclosure vulnerability
show less
Port Scan
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-09-01 05:11:20
(9 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-01 05:10:19
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.84.43.149 (149.43.84.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.84.43.149 (149.43.84.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 01:10:14.287636 2026] [security2:error] [pid 13846:tid 13846] [client 34.84.43.149:37256] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ebys-de-listeerg-acctioned.rasuki.com"] [uri "/wp-config.php~"] [unique_id "apZeNpm5Cel6O7IYfyFliQAAACI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
consul.to
2026-09-01 04:48:28
(9 hours ago)
Web attack/malicious scanning detected
Web App Attack
Anonymous
2026-09-01 04:42:03
(9 hours ago)
Bot / scanning and/or hacking attempts: GET /wp-config.php~ HTTP/1.1, GET /.env.backup HTTP/1.1, GET ...
show more
Bot / scanning and/or hacking attempts: GET /wp-config.php~ HTTP/1.1, GET /.env.backup HTTP/1.1, GET /.env HTTP/1.1, GET /.env.old HTTP/1.1, GET /crusader-404-probe HTTP/1.1, GET /.env.dev HTTP/1.1
show less
Hacking
Web App Attack