🇺🇸
TPI-Abuse
2026-09-06 03:52:25
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.96.251.161 (161.251.96.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.96.251.161 (161.251.96.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 23:52:20.205371 2026] [security2:error] [pid 305389:tid 305426] [client 34.96.251.161:52184] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.unitedonegroup.com"] [uri "/.env.bak"] [unique_id "apzjdOdZ4xRVqzYhVJzGNgAAAUw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
debestelapp
2026-09-06 02:40:11
(4 hours ago)
Web App Attack
🇨🇭
zynex
2026-09-06 02:35:08
(4 hours ago)
URL Probing: /.env
Web App Attack
🇳🇱
WeCloudit-Anti-Abuse
2026-09-06 01:47:51
(5 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-06 01:09:08
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.96.251.161 (161.251.96.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.96.251.161 (161.251.96.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 21:09:04.867864 2026] [security2:error] [pid 32088:tid 32088] [client 34.96.251.161:57006] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.jsdavison.com"] [uri "/.env.local"] [unique_id "apy9MJj40uNVM14wp1TtcgAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 00:47:22
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.96.251.161 (161.251.96.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.96.251.161 (161.251.96.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 20:47:16.084548 2026] [security2:error] [pid 23186:tid 23186] [client 34.96.251.161:45620] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.killigrewcompany.com"] [uri "/.env.save"] [unique_id "apy4FE03UTO7nAFz9O8LcQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
kosada.com
2026-09-06 00:36:24
(6 hours ago)
Repeated exploit attempts, for example: /.env.local /.env (HTTP/1.1 port 443)
Web App Attack
🇳🇱
tmiland
2026-09-05 23:28:01
(7 hours ago)
(nginx_404) Dot directory Honeypot Trap 34.96.251.161 (HK/Hong Kong/161.251.96.34.bc.googleuserconte ...
show more
(nginx_404) Dot directory Honeypot Trap 34.96.251.161 (HK/Hong Kong/161.251.96.34.bc.googleusercontent.com): 2 in the last 3600 secs; IP: 34.96.251.161; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 34.96.251.161 - - [06/Sep/2026:01:27:58 +0200] "GET /.env.example HTTP/1.1" 404 2992 "-" "crusader-worker/1.0" 34.96.251.161 - - [06/Sep/2026:01:27:58 +0200] "GET /.env.dev HTTP/1.1" 404 2992 "-" "crusader-worker/1.0"
show less
Brute-Force
🇺🇸
TPI-Abuse
2026-09-05 23:00:07
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.96.251.161 (161.251.96.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.96.251.161 (161.251.96.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 18:59:59.375299 2026] [security2:error] [pid 32512:tid 32512] [client 34.96.251.161:37442] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.intrinsicdiscovery.com"] [uri "/.env.dev"] [unique_id "apye7-W3mmttpqKUjh77DQAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 22:21:23
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.96.251.161 (161.251.96.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.96.251.161 (161.251.96.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 18:21:17.437617 2026] [security2:error] [pid 28677:tid 28677] [client 34.96.251.161:50440] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "customwww.com"] [uri "/.env"] [unique_id "apyV3XVRZ6esnnEXuPAjtAAAAGQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇲🇾
Rizzy
2026-09-05 21:55:41
(9 hours ago)
Multiple WAF Violations
Brute-Force
Web App Attack
🇦🇺
FireGuard Server
2026-09-05 21:40:03
(9 hours ago)
Blocked by os-abuseipdb; 76 hits, proto=tcp, ports=443
Port Scan
Hacking
🇮🇹
VHosting
2026-09-05 20:55:03
(10 hours ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
🇫🇮
6kilowatti
2026-09-05 20:48:34
(10 hours ago)
34.96.251.161 - - [05/Sep/2026:23:48:32 +0300] "GET /.env.save HTTP/1.1" 404 41 "-" "crusader-worker ...
show more
34.96.251.161 - - [05/Sep/2026:23:48:32 +0300] "GET /.env.save HTTP/1.1" 404 41 "-" "crusader-worker/1.0"
...
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 20:38:24
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.96.251.161 (161.251.96.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.96.251.161 (161.251.96.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 16:38:16.328748 2026] [security2:error] [pid 29408:tid 29408] [client 34.96.251.161:51998] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.otraes.com"] [uri "/wp-config.php.bak"] [unique_id "apx9uBCw2n7BfEuOBLIMSgAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack