🇺🇸
TPI-Abuse
2026-09-04 15:19:40
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.89.116.109 (109.116.89.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.89.116.109 (109.116.89.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 11:19:33.629569 2026] [security2:error] [pid 8048:tid 8048] [client 34.89.116.109:41046] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.trixieotoole.com"] [uri "/.env"] [unique_id "aprhhYYtOQAUngiRcZtLeQAAAJU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
FeG Deutschland
2026-09-04 15:01:13
(7 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
Anonymous
2026-09-04 14:51:41
(7 hours ago)
[ssd5.kdns.gr] httpd-config-scan: sites=www.cancelletto.gr; logs=/var/log/httpd/domains/cancelletto. ...
show more
[ssd5.kdns.gr] httpd-config-scan: sites=www.cancelletto.gr; logs=/var/log/httpd/domains/cancelletto.gr.log; samples=/.env.local | /actuator/configprops | /.env.dev
show less
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 14:08:09
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.89.116.109 (109.116.89.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.89.116.109 (109.116.89.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 10:08:01.641324 2026] [security2:error] [pid 7404:tid 7404] [client 34.89.116.109:48022] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.ajvaage.com"] [uri "/.env"] [unique_id "aprQwer8ftOH543SqY6cIQAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇮🇪
AutosOnShow
2026-09-04 13:55:07
(8 hours ago)
blocked for webapp attack | path requested: /.env | seen at 2026-09-04 13:54:41.666 |
Web App Attack
🇩🇪
Petros Stefanakis
2026-09-04 13:50:47
(8 hours ago)
(mod_security) mod_security triggered on hostname [redacted] 34.89.116.109 (GB/United Kingdom/109.11 ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.89.116.109 (GB/United Kingdom/109.116.89.34.bc.googleusercontent.com)
show less
SQL Injection
🇺🇸
TPI-Abuse
2026-09-04 12:13:39
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.89.116.109 (109.116.89.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.89.116.109 (109.116.89.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 08:13:30.279962 2026] [security2:error] [pid 29248:tid 29248] [client 34.89.116.109:38550] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mjkhan.com"] [uri "/.env.prod"] [unique_id "apq16p3Lfrm92PEZ0tIyggAAADE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 11:13:07
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.89.116.109 (109.116.89.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.89.116.109 (109.116.89.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 07:13:03.642319 2026] [security2:error] [pid 4689:tid 4720] [client 34.89.116.109:40110] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "aapm.aafm.us"] [uri "/.env.example"] [unique_id "apqnv74lvAgpmFrx0QPTyQAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
XICTRON
2026-09-04 10:55:08
(11 hours ago)
ModSecurity rule violation detected by Fail2Ban
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 10:43:50
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.89.116.109 (109.116.89.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.89.116.109 (109.116.89.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 06:43:46.718325 2026] [security2:error] [pid 29037:tid 29037] [client 34.89.116.109:52608] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "lancehancock.com"] [uri "/.env.bak"] [unique_id "apqg4tVgb2XXkTeclDw17wAAACE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 10:16:13
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.89.116.109 (109.116.89.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.89.116.109 (109.116.89.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 06:16:07.885503 2026] [security2:error] [pid 16227:tid 16227] [client 34.89.116.109:57488] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jwilder.com"] [uri "/.env.old"] [unique_id "apqaZwwjs4poPNEz3_nKBwAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇹🇷
pashait
2026-09-04 09:55:54
(12 hours ago)
Auto-blocked by Seczar SecureOps — IPS Web Attack Signature (1 events in 5min) at 2026-09-04 09:55
Web App Attack
Bad Web Bot
🇳🇱
MyGlobalFlowers
2026-09-04 09:34:46
(12 hours ago)
Multiple WAF Violations
Web App Attack
🇳🇱
SysAdmin Dylan
2026-09-04 09:24:51
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.89.116.109 (109.116.89.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.89.116.109 (109.116.89.34.bc.googleusercontent.com): 10 in the last 3600 secs
show less
Brute-Force
🇩🇪
LRob
2026-09-04 08:44:07
(13 hours ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /.env (+6 more) | 2026-09-04 08:44 UTC
show less
Hacking
Web App Attack