🇺🇸
TPI-Abuse
2026-09-06 03:50:47
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.88.230.20 (20.230.88.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.88.230.20 (20.230.88.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 23:50:40.750848 2026] [security2:error] [pid 12860:tid 12860] [client 34.88.230.20:57076] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.duermaseaprisa.com"] [uri "/.env.save"] [unique_id "apzjEOrY7SaqVKnatyj-hwAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇦🇺
paulshipley.com.au
2026-09-06 03:05:44
(16 hours ago)
[Sun Sep 06 13:05:44.054210 2026] [security2:error] [pid 888618] [client 34.88.230.20:53956] [client ...
show more
[Sun Sep 06 13:05:44.054210 2026] [security2:error] [pid 888618] [client 34.88.230.20:53956] [client 34.88.230.20] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/modsecurity/crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "winesbydesign.com.au"] [uri "/.env.local"] [unique_id "apzYiLLkP3oNZIcH0tZ9oAAAAA0"]
...
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 03:01:28
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.88.230.20 (20.230.88.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.88.230.20 (20.230.88.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 23:01:24.443898 2026] [security2:error] [pid 32628:tid 32628] [client 34.88.230.20:58394] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.marketask.com"] [uri "/.env.backup"] [unique_id "apzXhEG_dsLBt1C7O9m1vgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
masterguru
2026-09-06 02:31:01
(17 hours ago)
Restricted File Access Attempt. Matched phrase ".env" at REQUEST_FILENAME. (930130-193)
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 02:24:06
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.88.230.20 (20.230.88.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.88.230.20 (20.230.88.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 22:24:01.634842 2026] [security2:error] [pid 8810:tid 8810] [client 34.88.230.20:33188] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "combustionlogic.com"] [uri "/.env.bak"] [unique_id "apzOwU1HdR9QZUPWMOfJlAAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 01:44:52
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.88.230.20 (20.230.88.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.88.230.20 (20.230.88.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 21:44:48.452490 2026] [security2:error] [pid 651:tid 651] [client 34.88.230.20:40108] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "gdhlgroup.com"] [uri "/.env.backup"] [unique_id "apzFkGRlDnzzQpStGuZH8AAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
andypiper
2026-09-06 01:00:11
(19 hours ago)
CrowdSec ban for AbuseIPDB Top List
Brute-Force
Web App Attack
🇩🇪
LRob
2026-09-06 00:24:01
(19 hours ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /.env.backup (+12 more) | 2026-09-06 00:24 UTC
show less
Hacking
Web App Attack
🇩🇪
raph
2026-09-06 00:16:57
(19 hours ago)
[DOT FILES] crawler *.env*, .git*, .config*, etc.
Bad Web Bot
Web App Attack
Anonymous
2026-09-06 00:11:28
(19 hours ago)
Multiple web server 400 error codes from same source ip
Web App Attack
🇮🇳
evicky2002
2026-09-06 00:02:40
(19 hours ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
🇺🇸
TPI-Abuse
2026-09-05 23:50:01
(20 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.88.230.20 (20.230.88.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.88.230.20 (20.230.88.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 19:49:55.482502 2026] [security2:error] [pid 15227:tid 15227] [client 34.88.230.20:59442] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "healingworksmassage.studio"] [uri "/wp-config.php.swp"] [unique_id "apyqo3G47PltCH-o1MiqmgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-05 23:27:31
(20 hours ago)
(config_exploit_scan) Configuratie Scanner / Nep GPTBot 34.88.230.20 (20.230.88.34.bc.googleusercont ...
show more
(config_exploit_scan) Configuratie Scanner / Nep GPTBot 34.88.230.20 (20.230.88.34.bc.googleusercontent.com): 3 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 34.88.230.20 - - [06/Sep/2026:01:27:27 +0200] "GET /.env.dev HTTP/1.1" 406 4829 "-" "crusader-worker/1.0"
34.88.230.20 - - [06/Sep/2026:01:27:27 +0200] "GET /.env.save HTTP/1.1" 406 4831 "-" "crusader-worker/1.0"
34.88.230.20 - - [06/Sep/2026:01:27:27 +0200] "GET /.env.bak HTTP/1.1" 406 4829 "-" "crusader-worker/1.0"
show less
Port Scan
🇳🇱
WeCloudit-Anti-Abuse
2026-09-05 23:05:10
(20 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
🇩🇪
mondor.ro
2026-09-05 23:00:19
(21 hours ago)
Cluster member 148.251.176.225 (DE/Germany/antares.webyouridea.ro) said, DENY 34.88.230.20, Reason:[ ...
show more
Cluster member 148.251.176.225 (DE/Germany/antares.webyouridea.ro) said, DENY 34.88.230.20, Reason:[(mod_security) mod_security (id:210492) triggered by 34.88.230.20 (FI/Finland/20.230.88.34.bc.googleusercontent.com): 3 in the last 3600 secs]; Ports: *; Direction: inout; Trigger: LF_CLUSTER; Logs:
show less
Port Scan