🇺🇸
TPI-Abuse
2026-09-04 15:20:46
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.87.209.39 (39.209.87.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.87.209.39 (39.209.87.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 11:20:41.035842 2026] [security2:error] [pid 24148:tid 24148] [client 34.87.209.39:58606] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.jvcsat.com"] [uri "/.env"] [unique_id "aprhyYn3TqfIJYryrX2FLQAAADA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
FeG Deutschland
2026-09-04 15:00:54
(2 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 14:05:16
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.87.209.39 (39.209.87.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.87.209.39 (39.209.87.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 10:05:09.220067 2026] [security2:error] [pid 30869:tid 30869] [client 34.87.209.39:42498] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.janton.com"] [uri "/wp-config.php.bak"] [unique_id "aprQFe2YZD2F4F-6ty72CQAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇸🇪
vaia.cloud
2026-09-04 13:30:03
(3 hours ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
🇵🇱
Budyn
2026-09-04 13:15:58
(3 hours ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: CRITICAL: ModSecurity WAF Exploit ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: CRITICAL: ModSecurity WAF Exploit Block. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: teddypot.store | URI: /.env.prod | UA: crusader-worker/1.0 | BODY: [Empty / GET Request]
show less
Hacking
Web App Attack
🇩🇪
webanyone
2026-09-04 12:32:27
(4 hours ago)
WAF repeated trigger detected by Fail2Ban in plesk-modsecurity jail
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 11:45:15
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.87.209.39 (39.209.87.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.87.209.39 (39.209.87.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 07:45:08.151124 2026] [security2:error] [pid 5522:tid 5522] [client 34.87.209.39:50774] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.garthp.com"] [uri "/wp-config.php.bak"] [unique_id "apqvRFoin4C9YqNEJwlATgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
e.fierstra
2026-09-04 10:36:42
(6 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
🇩🇪
raph
2026-09-04 10:09:33
(7 hours ago)
[DOT FILES] crawler *.env*, .git*, .config*, etc.
Bad Web Bot
Web App Attack
🇩🇪
Petros Stefanakis
2026-09-04 09:49:38
(7 hours ago)
(mod_security) mod_security triggered on hostname [redacted] 34.87.209.39 (AU/Australia/39.209.87.34 ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.87.209.39 (AU/Australia/39.209.87.34.bc.googleusercontent.com)
show less
SQL Injection
🇫🇷
Baking333
2026-09-04 09:21:46
(7 hours ago)
[redacted] 34.87.209.39 - - [04/Sep/2026:10:21:45 +0100] "GET /.env HTTP/1.1" 302 6768 0/49196 "-" " ...
show more
[redacted] 34.87.209.39 - - [04/Sep/2026:10:21:45 +0100] "GET /.env HTTP/1.1" 302 6768 0/49196 "-" "crusader-worker/1.0" [redacted] 34.87.209.39 - - [04/Sep/2026:10:21:45 +0100] "GET /.[redacted] HTTP/1.1" 302 6768 0/52586 "-" "crusader-worker/1.0"
show less
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 09:19:13
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.87.209.39 (39.209.87.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.87.209.39 (39.209.87.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 05:19:06.760205 2026] [security2:error] [pid 31156:tid 31174] [client 34.87.209.39:56250] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kiehnefamily.us"] [uri "/.env.backup"] [unique_id "apqNCrXaduj_y9pQpylSSAAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-04 08:28:43
(8 hours ago)
(config_exploit_scan) Configuratie Scanner / Nep GPTBot 34.87.209.39 (39.209.87.34.bc.googleusercont ...
show more
(config_exploit_scan) Configuratie Scanner / Nep GPTBot 34.87.209.39 (39.209.87.34.bc.googleusercontent.com): 3 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 34.87.209.39 - - [04/Sep/2026:10:28:41 +0200] "GET /.env HTTP/1.1" 406 4830 "-" "crusader-worker/1.0"
34.87.209.39 - - [04/Sep/2026:10:28:41 +0200] "GET /.env.dev HTTP/1.1" 406 4831 "-" "crusader-worker/1.0"
34.87.209.39 - - [04/Sep/2026:10:28:41 +0200] "GET /.env.bak HTTP/1.1" 406 4830 "-" "crusader-worker/1.0"
show less
Port Scan
🇳🇱
WeCloudit-Anti-Abuse
2026-09-04 08:20:20
(8 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-04 08:19:09
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.87.209.39 (39.209.87.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.87.209.39 (39.209.87.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 04:19:05.024321 2026] [security2:error] [pid 20017:tid 20017] [client 34.87.209.39:40740] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.greywall.org"] [uri "/wp-config.php.bak"] [unique_id "app--SufmYgxZ_2AfmVtowAAAC8"]
show less
Brute-Force
Bad Web Bot
Web App Attack