๐บ๐ธ
TPI-Abuse
2026-09-01 02:39:42
(12 minutes ago)
(mod_security) mod_security (id:210492) triggered by 34.97.120.211 (211.120.97.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.97.120.211 (211.120.97.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 22:39:34.123751 2026] [security2:error] [pid 18667:tid 18667] [client 34.97.120.211:56334] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.shawnlayne.com"] [uri "/.env.local"] [unique_id "apY65ioZUclGVha1P7Iq1gAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-01 02:31:50
(20 minutes ago)
34.97.120.211 - - [01/Sep/2026:10:31:50 +0800] "GET /.env.dev HTTP/1.1" 404 196 "-" "crusader-worker ...
show more
34.97.120.211 - - [01/Sep/2026:10:31:50 +0800] "GET /.env.dev HTTP/1.1" 404 196 "-" "crusader-worker/1.0"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 00:14:14
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.97.120.211 (211.120.97.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.97.120.211 (211.120.97.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 20:14:07.001610 2026] [security2:error] [pid 6163:tid 6163] [client 34.97.120.211:48398] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.chiggerland.com"] [uri "/wp-config.php.swp"] [unique_id "apYYz5JldQJ1jBFZupxTygAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Roderic
2026-09-01 00:10:24
(2 hours ago)
(mod_security) mod_security triggered on hostname [redacted])
SQL Injection
๐บ๐ธ
TPI-Abuse
2026-08-31 23:14:39
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.97.120.211 (211.120.97.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.97.120.211 (211.120.97.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 19:14:32.059392 2026] [security2:error] [pid 9740:tid 9740] [client 34.97.120.211:44244] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "butkiewiczfamilyfarm.com"] [uri "/.env"] [unique_id "apYK2IgZKiwyNE-uacJWNwAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ธ๐ช
vaia.cloud
2026-08-31 22:45:04
(4 hours ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
๐ฉ๐ช
Gwyneth Llewelyn
2026-08-31 22:41:40
(4 hours ago)
2026/08/31 23:41:22 [error] 380595#380595: *1929284 access forbidden by rule, client: 34.97.120.211, ...
show more
2026/08/31 23:41:22 [error] 380595#380595: *1929284 access forbidden by rule, client: 34.97.120.211, server: betatechnologies.info, request: "GET /.env HTTP/2.0", host: "betatechnologies.info"
34.97.120.211 - - [31/Aug/2026:23:41:22 +0100] "GET /.env HTTP/2.0" 403 1045 "-" "crusader-worker/1.0"
2026/08/31 23:41:38 [error] 380594#380594: *1929282 access forbidden by rule, client: 34.97.120.211, server: betatechnologies.info, request: "GET //.env HTTP/2.0", host: "betatechnologies.info"
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-31 22:20:57
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.97.120.211 (211.120.97.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.97.120.211 (211.120.97.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 18:20:50.121893 2026] [security2:error] [pid 19911:tid 19911] [client 34.97.120.211:47252] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.panadata.com"] [uri "/.env.old"] [unique_id "apX-QjbVKXjVMDC21GeEdgAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
VHosting
2026-08-31 22:15:04
(4 hours ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-31 21:34:40
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.97.120.211 (211.120.97.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.97.120.211 (211.120.97.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 17:34:34.274985 2026] [security2:error] [pid 25999:tid 25999] [client 34.97.120.211:39228] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ahelfrick.com"] [uri "/.env.backup"] [unique_id "apXzaqPimh18vtlOQCE01AAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
gws-hostmaster
2026-08-31 21:23:54
(5 hours ago)
ModSecurity OWASP CRS (Anomaly Score: 10): Attempt to access a backup or working file;Restricted Fil ...
show more
ModSecurity OWASP CRS (Anomaly Score: 10): Attempt to access a backup or working file;Restricted File Access Attempt;URL file extension is restricted by policy;
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-31 17:19:15
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.97.120.211 (211.120.97.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.97.120.211 (211.120.97.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 13:19:08.584717 2026] [security2:error] [pid 25558:tid 25558] [client 34.97.120.211:36222] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "17thstreetrealty.com"] [uri "/.env.old"] [unique_id "apW3jMkP8UeMuYYJWgXeIwAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack