🇺🇸
TPI-Abuse
2026-09-04 15:20:00
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.87.171.78 (78.171.87.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.87.171.78 (78.171.87.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 11:19:55.216151 2026] [security2:error] [pid 2694:tid 2694] [client 34.87.171.78:46528] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.mrbaystreet.com"] [uri "/.env.dev"] [unique_id "aprhm5uatuTBpA9qbs73AwAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇦🇺
Bay13
2026-09-04 14:57:51
(1 hour ago)
CrowdSec:custom/http-sensitive-files
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 14:04:38
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.87.171.78 (78.171.87.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.87.171.78 (78.171.87.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 10:04:34.271534 2026] [security2:error] [pid 24394:tid 24394] [client 34.87.171.78:39046] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "patanthony.com"] [uri "/.env.production"] [unique_id "aprP8kYSE7IYE5_UITAeMgAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇹🇷
Detmach
2026-09-04 13:52:11
(2 hours ago)
Security attack detected. Multiple failed attempts from 34.87.171.78. IP banned for 1440 minutes at ...
show more
Security attack detected. Multiple failed attempts from 34.87.171.78. IP banned for 1440 minutes at 04.09.2026 16:52:11. Failed attempts: 1
show less
Brute-Force
🇷🇴
iulianh
2026-09-04 13:21:07
(3 hours ago)
80,443
Brute-Force
SSH
Anonymous
2026-09-04 13:12:24
(3 hours ago)
Scanner hitting /.env on 176.31.46.240 (GOOGL-2) — aaguard
Brute-Force
Port Scan
🇺🇸
TPI-Abuse
2026-09-04 12:52:57
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.87.171.78 (78.171.87.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.87.171.78 (78.171.87.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 08:52:51.271589 2026] [security2:error] [pid 11145:tid 11160] [client 34.87.171.78:50944] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "maroontribe.com"] [uri "/.env.local"] [unique_id "apq_I3rzwxXVEFl6VeBoCwAAAQ0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 11:43:52
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.87.171.78 (78.171.87.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.87.171.78 (78.171.87.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 07:43:49.217076 2026] [security2:error] [pid 20246:tid 20246] [client 34.87.171.78:38356] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.ridgecrestrealtors.com"] [uri "/.env.save"] [unique_id "apqu9aue0ww8XqCH02fT-wAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
macrob
2026-09-04 11:19:16
(5 hours ago)
2026/09/04 11:19:14 [error] 754821#754821: *555576842 access forbidden by rule, client: 34.87.171.78 ...
show more
2026/09/04 11:19:14 [error] 754821#754821: *555576842 access forbidden by rule, client: 34.87.171.78, server: fn.binixo.es, request: "GET /.env HTTP/2.0", host: "email.fastcredit.net.ua"
2026/09/04 11:19:14 [error] 754821#754821: *555576845 access forbidden by rule, client: 34.87.171.78, server: fn.binixo.es, request: "GET /.env.production HTTP/2.0", host: "email.fastcredit.net.ua"
2026/09/04 11:19:14 [error] 754821#754821: *555576848 access forbidden by rule, client: 34.87.171.78, server: fn.binixo.es, request: "GET /.env.old HTTP/2.0", host: "email.fastcredit.net.ua"
...
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 11:15:50
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.87.171.78 (78.171.87.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.87.171.78 (78.171.87.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 07:15:45.756167 2026] [security2:error] [pid 10324:tid 10324] [client 34.87.171.78:33498] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.pswebsite.com"] [uri "/.env.local"] [unique_id "apqoYT8HSisOlTuHMVuffQAAACY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
raph
2026-09-04 10:38:45
(5 hours ago)
[DOT FILES] crawler *.env*, .git*, .config*, etc.
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 10:06:15
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.87.171.78 (78.171.87.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.87.171.78 (78.171.87.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 06:06:08.443680 2026] [security2:error] [pid 19690:tid 19690] [client 34.87.171.78:43118] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.studioarmanni.com"] [uri "/.env.bak"] [unique_id "apqYEMwhUiZc_FOQhWkkwAAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
consul.to
2026-09-04 09:37:15
(6 hours ago)
Web attack/malicious scanning detected
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 09:18:03
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.87.171.78 (78.171.87.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.87.171.78 (78.171.87.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 05:17:56.485214 2026] [security2:error] [pid 27014:tid 27014] [client 34.87.171.78:57056] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jiggajones.indie100.com"] [uri "/.env.old"] [unique_id "apqMxPIPNMPsignb6VVvnQAAAB8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇨🇦
Anytech
2026-09-04 08:45:08
(7 hours ago)
Blocked by Conn-Monitor: env-probing
Web App Attack
Hacking