๐บ๐ธ
TPI-Abuse
2026-09-04 00:02:09
(35 minutes ago)
(mod_security) mod_security (id:210492) triggered by 34.87.45.132 (132.45.87.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.87.45.132 (132.45.87.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 20:02:02.790457 2026] [security2:error] [pid 1884174:tid 1884201] [client 34.87.45.132:58200] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.powercoupling.com"] [uri "/@fs/app/.env"] [unique_id "apoKeu0JGMRJeDczWep4hAAAAMU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
JimArchon72
2026-09-03 23:25:01
(1 hour ago)
2026/09/03 23:23:39 "GET /wp-admin/ HTTP/1.1"
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-03 23:17:59
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.87.45.132 (132.45.87.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.87.45.132 (132.45.87.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 19:17:56.144632 2026] [security2:error] [pid 19159:tid 19159] [client 34.87.45.132:24458] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.fingps.com"] [uri "/@fs/.env"] [unique_id "apoAJOFsxvD4qGlJjrxIBQAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
cmbplf
2026-09-03 23:09:55
(1 hour ago)
8.946 requests from abuseipdb.com blacklisted IP (1mo4w1d)
Brute-Force
Bad Web Bot
๐ฉ๐ช
TheDjRider
2026-09-03 23:00:47
(1 hour ago)
CrowdSec detected Sensitive file or backup discovery attempt. Scenario: local/apache-sensitive-paths ...
show more
CrowdSec detected Sensitive file or backup discovery attempt. Scenario: local/apache-sensitive-paths. Automatic ban triggered. Detection time (UTC): 2026-09-03T23:00:39.451463234Z. Context: http_status=404
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-03 22:55:47
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.87.45.132 (132.45.87.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.87.45.132 (132.45.87.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 18:55:42.836863 2026] [security2:error] [pid 24778:tid 24778] [client 34.87.45.132:20684] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.calvarycavaliers.org"] [uri "/@fs/root/.env"] [unique_id "apn67kfPlUU4YN-Q8Gi94gAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-03 22:25:15
(2 hours ago)
(mod_security) mod_security (id:243420) triggered by 34.87.45.132 (132.45.87.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:243420) triggered by 34.87.45.132 (132.45.87.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 18:25:06.899869 2026] [security2:error] [pid 18371:tid 18371] [client 34.87.45.132:27746] ModSecurity: Access denied with code 403 (phase 3). Match of "validateByteRange 0-31" against "ARGS:raw??" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "6640"] [id "243420"] [rev "4"] [msg "COMODO WAF: Information disclosure vulnerability in Eclipse Jetty before 9.2.9.v20150224 (CVE-2015-2080)||turquoisetidestravel.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "turquoisetidestravel.com"] [uri "/.env"] [unique_id "apnzwh0DE1xrtjbi-hh7rgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Lacrimosa99
2026-09-03 22:13:41
(2 hours ago)
34.87.45.132 - - [04/Sep/2026:00:13:12 +0200] "GET /@fs/home/admin/.aws/credentials?raw?? HTTP/1.1" ...
show more
34.87.45.132 - - [04/Sep/2026:00:13:12 +0200] "GET /@fs/home/admin/.aws/credentials?raw?? HTTP/1.1" 404 927 "-" "Mozilla/5.0 (compatible; Claude-User/1.0; +https://www.anthropic.com/claude-user)"
34.87.45.132 - - [04/Sep/2026:00:13:27 +0200] "GET /@fs/root/.config/gcloud/credentials.db?raw?? HTTP/1.1" 404 927 "-" "Mozilla/5.0 (compatible; GrokBot/1.0; +https://x.ai/grokbot)"
34.87.45.132 - - [04/Sep/2026:00:13:40 +0200] "GET /admin/.env HTTP/1.1" 404 927 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_4 like Mac OS X) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.8255.137 Mobile Safari/537.36; compatible; Discordbot/2.0; +https://discordapp.com"
...
show less
Web Spam
๐ธ๐ช
vaia.cloud
2026-09-03 21:55:02
(2 hours ago)
crowdsecurity/http-path-traversal-probing
Brute-Force
Web App Attack
๐ฉ๐ช
updown.io
2026-09-03 21:16:39
(3 hours ago)
{"level":"info","ts":1788470156.2397523,"logger":"http.log.access.log0","msg":"handled request","req ...
show more
{"level":"info","ts":1788470156.2397523,"logger":"http.log.access.log0","msg":"handled request","request":{"remote_ip":"34.87.45.132","remote_port":"29082","client_ip":"34.87.45.132","proto":"HTTP/1.1","method":"GET","host":"x4ug.status.updown.io","uri":"/","headers":{"Accept-Encoding":["gzip"],"User-Agent":["Mozilla/5.0 (Macintosh; Intel Mac OS X 14_5) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.5 Safari/605.1.15"],"Accept":["*/*"]}},"bytes_read":0,"user_id":"","duration":0.00011512,"size":0,"status":308,"resp_headers":{"Server":["Caddy"],"Connection":["close"],"Location":["https://x4ug.status.updown.io/"],"Content-Type":[]}}
{"level":"info","ts":1788470164.0461977,"logger":"http.log.access.log0","msg":"handled request","request":{"remote_ip":"34.87.45.132","remote_port":"36988","client_ip":"34.87.45.132","proto":"HTTP/1.1","method":"GET","host":"x4ug.status.updown.io","uri":"/@fs/src/.env?raw??","headers":{"User-Agent":["Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:105.5) Gec
...
show less
DDoS Attack
Web App Attack
๐บ๐ธ
daveoctober
2026-09-03 20:57:28
(3 hours ago)
October Sentinel: honeypot triggered
Bad Web Bot
Web App Attack
๐ซ๐ท
Octopuce
2026-09-03 20:27:06
(4 hours ago)
Aggressive web search of vulnerable pages: /api/.env /.env /images../.env /app/.env /_nuxt/../.env ...
show more
Aggressive web search of vulnerable pages: /api/.env /.env /images../.env /app/.env /_nuxt/../.env ...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-03 20:23:43
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.87.45.132 (132.45.87.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.87.45.132 (132.45.87.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 16:23:38.787378 2026] [security2:error] [pid 31250:tid 31288] [client 34.87.45.132:49106] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.boxwoodgarden.com"] [uri "/@fs/src/.env"] [unique_id "apnXStTfhmzPoe1gYwOsQgAAAUg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-03 20:17:11
(4 hours ago)
Bot / seems abusive / Apache connections: 74
DDoS Attack
Web Spam
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-03 20:05:54
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.87.45.132 (132.45.87.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.87.45.132 (132.45.87.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 16:05:48.387079 2026] [security2:error] [pid 6377:tid 6377] [client 34.87.45.132:58860] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.rwfrancis.com"] [uri "/@fs/.env"] [unique_id "apnTHBWOXX8XbbnzAoORIwAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack