🇺🇸
TPI-Abuse
2026-09-04 15:21:20
(23 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.88.129.47 (47.129.88.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.88.129.47 (47.129.88.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 11:21:14.149934 2026] [security2:error] [pid 6526:tid 6526] [client 34.88.129.47:48428] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.techimprints.com"] [uri "/.env.backup"] [unique_id "aprh6nIUOXsvBuCgYhiaCwAAAF8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
Interceptor_HQ
2026-09-04 14:34:45
(1 day ago)
request_uri: /.env.prod -- automatic report --
Brute-Force
Hacking
🇺🇸
TPI-Abuse
2026-09-04 14:12:31
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.88.129.47 (47.129.88.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.88.129.47 (47.129.88.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 10:12:27.396373 2026] [security2:error] [pid 30530:tid 30530] [client 34.88.129.47:43144] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.13waggoners.com"] [uri "/.env.dev"] [unique_id "aprRy8AQ0fdXG8ERQ2gi7gAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 13:50:52
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.88.129.47 (47.129.88.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.88.129.47 (47.129.88.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 09:50:44.513866 2026] [security2:error] [pid 26765:tid 26765] [client 34.88.129.47:37982] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "aics.alitcogroup.com"] [uri "/wp-config.php.swp"] [unique_id "aprMtCMAlKXQJnr8NxXhbgAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 12:55:50
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.88.129.47 (47.129.88.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.88.129.47 (47.129.88.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 08:55:44.093844 2026] [security2:error] [pid 6780:tid 6780] [client 34.88.129.47:60916] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "marisa-mcphee.com"] [uri "/.env.example"] [unique_id "apq_0NjMWk8W4WfYDWLoOQAAACA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
SCHAPPY
2026-09-04 12:47:55
(1 day ago)
Malicious activity from IP detected: crowdsecurity/http-probing.
Web App Attack
Hacking
🇫🇷
masterguru
2026-09-04 11:48:10
(1 day ago)
URL file extension is restricted by policy. String match within ".ani/ .asa/ .asax/ .ascx/ .backup/ ...
show more
URL file extension is restricted by policy. String match within ".ani/ .asa/ .asax/ .ascx/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .compositefont/ .config/ .conf/ .crt/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dist/ .dll/ .dos/ .dpkg-dist/ .drv/ .gadget/ .hta/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .inf/ .ini/ .jse/ .key/ .licx/ .lnk/ .log/ .mdb/ .msc/ .ocx/ .old/ .pass/ .pdb/ .pfx/ .pif/ .pem/ .pol/ .prf/ .printer/ .pwd/ .rdb/ .rdp/ .reg/ .resources/ .resx/ .scr/ .sct/ .shs/ .sql/ .swp/ .sys/ .tlb/ .tmp/ .url/ .vb/ .vbe/ .vbs/ .vbproj/ .vsdisco/ .vxd/ .webinfo/ .ws/ .wsc/ .wsf/ .wsh/ .xsd/ .xsx/" at TX:extension. (920440-195)
show less
Hacking
🇳🇱
debestelapp
2026-09-04 11:25:11
(1 day ago)
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 11:22:25
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.88.129.47 (47.129.88.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.88.129.47 (47.129.88.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 07:22:18.992175 2026] [security2:error] [pid 21551:tid 21551] [client 34.88.129.47:60970] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "eovdcconsulting.eu"] [uri "/.env.backup"] [unique_id "apqp6j57PEbawCgekwoxgAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 10:53:21
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.88.129.47 (47.129.88.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.88.129.47 (47.129.88.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 06:53:15.803525 2026] [security2:error] [pid 6245:tid 6245] [client 34.88.129.47:40318] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "narrowacresbees.com"] [uri "/.env.prod"] [unique_id "apqjG63yfWhRGLZ06Vh6ngAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-04 10:42:02
(1 day ago)
Bot / scanning and/or hacking attempts: GET /.env.backup HTTP/1.1, GET /.env.save HTTP/1.1
Hacking
Web App Attack
🇧🇷
Halux
2026-09-04 10:33:36
(1 day ago)
34.88.129.47 Probing protected path or service
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 10:22:08
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.88.129.47 (47.129.88.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.88.129.47 (47.129.88.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 06:22:01.325935 2026] [security2:error] [pid 2824999:tid 2825126] [client 34.88.129.47:54056] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "photo.gallery.the-aquifer.com"] [uri "/.env.prod"] [unique_id "apqbyVpNFp6v8WbXhINJKgAAAMo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇲🇾
Rizzy
2026-09-04 10:15:24
(1 day ago)
Multiple WAF Violations
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 10:03:10
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.88.129.47 (47.129.88.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.88.129.47 (47.129.88.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 06:03:03.374492 2026] [security2:error] [pid 487238:tid 487238] [client 34.88.129.47:37574] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.gcigmbh.com"] [uri "/.env.prod"] [unique_id "apqXV_1B8k9P-liznhXMMwAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack