🇺🇸
TPI-Abuse
2026-09-04 13:47:15
(31 minutes ago)
(mod_security) mod_security (id:210492) triggered by 34.95.169.32 (32.169.95.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.95.169.32 (32.169.95.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 09:47:12.994893 2026] [security2:error] [pid 28761:tid 28761] [client 34.95.169.32:53144] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "aguaflot.aguasolar.com"] [uri "/.env.local"] [unique_id "aprL4Nba5NMCuIaE8Y6UwwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 12:31:22
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.95.169.32 (32.169.95.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.95.169.32 (32.169.95.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 08:31:15.464720 2026] [security2:error] [pid 16419:tid 16419] [client 34.95.169.32:54428] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ftp.zenmonkeyproject.com"] [uri "/.env.save"] [unique_id "apq6E27jctqiQlcHWjCr3wAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
COMAITE
2026-09-04 12:01:51
(2 hours ago)
Suspicious URL access.
Web App Attack
🇺🇸
nyt
2026-09-04 11:13:39
(3 hours ago)
Sensitive File Probe
Web App Attack
🇩🇪
raph
2026-09-04 11:01:15
(3 hours ago)
[Wordpress] crawler /wp-admin/*, /wp-content/*, etc.
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 10:39:46
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.95.169.32 (32.169.95.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.95.169.32 (32.169.95.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 06:39:38.239241 2026] [security2:error] [pid 30272:tid 30272] [client 34.95.169.32:56030] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "andrewmcgrath.com"] [uri "/.env"] [unique_id "apqf6gJkT3eujUz101pxxgAAADU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-04 10:19:38
(3 hours ago)
34.95.169.32 - - [04/Sep/2026:10:19:36 +0000] "GET /.env.bak HTTP/1.1" 404 51544 "-" "crusader-worke ...
show more
34.95.169.32 - - [04/Sep/2026:10:19:36 +0000] "GET /.env.bak HTTP/1.1" 404 51544 "-" "crusader-worker/1.0"
...
show less
Bad Web Bot
Web App Attack
🇪🇸
alferez
2026-09-04 09:27:23
(4 hours ago)
Searching .(env|sql|zip|tar|rar) files
Hacking
Exploited Host
Web App Attack
🇳🇱
e.fierstra
2026-09-04 09:08:09
(5 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 08:40:00
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.95.169.32 (32.169.95.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.95.169.32 (32.169.95.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 04:39:56.796889 2026] [security2:error] [pid 9070:tid 9070] [client 34.95.169.32:52354] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "reneehill.net"] [uri "/.env.prod"] [unique_id "apqD3Cha1Lt3wVTH8OFAIgAAACY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 08:19:11
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.95.169.32 (32.169.95.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.95.169.32 (32.169.95.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 04:19:04.438354 2026] [security2:error] [pid 1579:tid 1579] [client 34.95.169.32:46724] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.zmgmt.com"] [uri "/wp-config.php~"] [unique_id "app--ARt7cN7sxQR0izdyAAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
WeCloudit-Anti-Abuse
2026-09-04 08:05:38
(6 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
🇺🇦
URAN Publishing Service
2026-09-04 08:02:08
(6 hours ago)
[04/Sep/2026:11:02:08 +0300] -- 34.95.169.32 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.env. ...
show more
[04/Sep/2026:11:02:08 +0300] -- 34.95.169.32 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.env.production HTTP/1.1
show less
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 07:51:55
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.95.169.32 (32.169.95.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.95.169.32 (32.169.95.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 03:51:50.016432 2026] [security2:error] [pid 25434:tid 25434] [client 34.95.169.32:55744] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "tech-servusa.com"] [uri "/wp-config.php~"] [unique_id "app4lkTjSXB7hNqzjvk4kgAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-04 05:23:23
(8 hours ago)
34.95.169.32 detected on srv01
Brute-Force