🇺🇸
TPI-Abuse
2026-09-04 15:17:06
(22 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.96.179.133 (133.179.96.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.96.179.133 (133.179.96.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 11:16:59.532619 2026] [security2:error] [pid 10134:tid 10134] [client 34.96.179.133:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.forsaleincr.com"] [uri "/.env.bak"] [unique_id "aprg6-aXo_zNwakmRLJeRAAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇨🇦
polycoda
2026-09-04 15:06:09
(22 hours ago)
AutoBlock: 🎯 Vulnerability Scanner (Non Decay-Based) - ⚙️ Configuration File Access (Non Decay-Based ...
show more
AutoBlock: 🎯 Vulnerability Scanner (Non Decay-Based) - ⚙️ Configuration File Access (Non Decay-Based) - ↪️ Excessive 30X Errors (Decay-Based)
show less
Hacking
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 14:50:21
(22 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.96.179.133 (133.179.96.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.96.179.133 (133.179.96.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 10:50:13.629543 2026] [security2:error] [pid 4566:tid 4566] [client 34.96.179.133:38104] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "carjinn.net"] [uri "/.env"] [unique_id "aprapY6MEcvTSIqJgVuC7gAAADw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
ruusvuu
2026-09-04 13:00:39
(1 day ago)
Automated abuse report: 15 attack/probe requests from Google LLC / HK.
Targeted paths: /actuator/env ...
show more
Automated abuse report: 15 attack/probe requests from Google LLC / HK.
Targeted paths: /actuator/env, /.env.example, /wp-config.php~, /wp-config.php.swp, /.env.bak.
Sample log lines:
[signerauthority] 34.96.179.133 - - [04/Sep/2026:06:00:38 -0700] "GET /.env.production HTTP/1.1" 404 5421 "-" "crusader-worker/1.0"
[signerauthority] 34.96.179.133 - - [04/Sep/2026:06:00:38 -0700] "GET /_ignition/health-check HTTP/1.1" 404 5428 "-" "crusader-worker/1.0"
[signerauthority] 34.96.179.133 - - [04/Sep/2026:06:00:38 -0700] "GET /wp-config.php.bak HTTP/1.1" 404 5423 "-" "crusader-worker/1.0"
Detected by an automated web-server log monitor.
show less
Web App Attack
🇩🇪
filstal.org
2026-09-04 12:34:56
(1 day ago)
Web reconnaissance detected: automated probing for sensitive files, backup archives, admin panels an ...
show more
Web reconnaissance detected: automated probing for sensitive files, backup archives, admin panels and known vulnerability paths.
show less
Hacking
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 12:20:13
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.96.179.133 (133.179.96.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.96.179.133 (133.179.96.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 08:20:10.256857 2026] [security2:error] [pid 31292:tid 31384] [client 34.96.179.133:38426] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mooks.chat.n2play.net"] [uri "/.env.prod"] [unique_id "apq3er90LOuTT4ybG6cAJgAAAdU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
yitzhaq
2026-09-04 12:13:16
(1 day ago)
34.96.179.133 - - [04/Sep/2026:14:13:01 +0200] "GET /wp-config.php.bak HTTP/1.1" 404 4438 "-" "crusa ...
show more
34.96.179.133 - - [04/Sep/2026:14:13:01 +0200] "GET /wp-config.php.bak HTTP/1.1" 404 4438 "-" "crusader-worker/1.0"
34.96.179.133 - - [04/Sep/2026:14:13:01 +0200] "GET /wp-config.php~ HTTP/1.1" 404 4437 "-" "crusader-worker/1.0"
34.96.179.133 - - [04/Sep/2026:14:13:01 +0200] "GET /actuator/env HTTP/1.1" 404 4437 "-" "crusader-worker/1.0"
34.96.179.133 - - [04/Sep/2026:14:13:01 +0200] "GET /wp-config.php.swp HTTP/1.1" 404 4437 "-" "crusader-worker/1.0"
34.96.179.133 - - [04/Sep/2026:14:13:01 +0200] "GET /.env.save HTTP/1.1" 404 4438 "-" "crusader-worker/1.0"
34.96.179.133 - - [04/Sep/2026:14:13:01 +0200] "GET /env HTTP/1.1" 404 4437 "-" "crusader-worker/1.0"
34.96.179.133 - - [04/Sep/2026:14:13:01 +0200] "GET /.env.backup HTTP/1.1" 404 4437 "-" "crusader-worker/1.0"
34.96.179.133 - - [04/Sep/2026:14:13:01 +0200] "GET /.env.bak HTTP/1.1" 404 4437 "-" "crusader-worker/1.0"
34.96.179.133 - - [04/Sep/2026:14:13:01 +0200] "GET /.env.production HTTP/1.1" 404 4437 "-" "crusader-worker/1.0"
34.
show less
Web App Attack
Brute-Force
🇹🇭
Andro
2026-09-04 11:29:00
(1 day ago)
Automated malicious reconnaissance attempting to locate exposed environment files, secrets, configur ...
show more
Automated malicious reconnaissance attempting to locate exposed environment files, secrets, configuration data, and other sensitive application resources. The source is systematically probing for files that may contain credentials, API keys, database connections, or other valuable configuration information. Nice try. Nothing sensitive was left lying around.
show less
Bad Web Bot
Web App Attack
Web Spam
🇺🇸
TPI-Abuse
2026-09-04 10:47:42
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.96.179.133 (133.179.96.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.96.179.133 (133.179.96.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 06:47:38.371805 2026] [security2:error] [pid 17926:tid 17926] [client 34.96.179.133:41062] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "victorg.me"] [uri "/.env.dev"] [unique_id "apqhyqS7yC72h_f5cl2xTwAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 10:00:38
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 34.96.179.133 (133.179.96.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.96.179.133 (133.179.96.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 06:00:31.926853 2026] [security2:error] [pid 14110:tid 14110] [client 34.96.179.133:58824] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||autodiscover.pknucklejones.com|F|2"] [data ".log"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "autodiscover.pknucklejones.com"] [uri "/storage/logs/laravel.log"] [unique_id "apqWv1EoeaXD4RkSI0l-OgAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
e.fierstra
2026-09-04 09:54:59
(1 day ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
🇬🇧
consul.to
2026-09-04 09:50:27
(1 day ago)
Web attack/malicious scanning detected
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 09:26:05
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.96.179.133 (133.179.96.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.96.179.133 (133.179.96.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 05:26:01.665060 2026] [security2:error] [pid 9034:tid 9034] [client 34.96.179.133:36792] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.newenglandchristmascards.com"] [uri "/.env.production"] [unique_id "apqOqbUJIj-u7jrb9Za-BAAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
dynamix
2026-09-04 08:27:56
(1 day ago)
Multiple WAF Violations
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 07:33:53
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.96.179.133 (133.179.96.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.96.179.133 (133.179.96.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 03:33:50.316706 2026] [security2:error] [pid 2447673:tid 2447690] [client 34.96.179.133:37168] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "torreymanagement.com"] [uri "/.env"] [unique_id "app0XmckBefvsU_zC6xU9AAAAso"]
show less
Brute-Force
Bad Web Bot
Web App Attack