🇺🇸
TPI-Abuse
2026-09-04 15:22:34
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.97.7.155 (155.7.97.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.97.7.155 (155.7.97.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 11:22:25.854749 2026] [security2:error] [pid 20324:tid 20324] [client 34.97.7.155:45376] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.mispar.solutions"] [uri "/.env.save"] [unique_id "apriMYTBiNG-JXxgGuB4RgAAAFw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
Zundapper
2026-09-04 13:52:54
(11 hours ago)
34.97.7.155 - - [04/Sep/2026:15:52:53 +0200] "GET /wp-config.php~ HTTP/1.1" 404 146 "-" "crusader-wo ...
show more
34.97.7.155 - - [04/Sep/2026:15:52:53 +0200] "GET /wp-config.php~ HTTP/1.1" 404 146 "-" "crusader-worker/1.0"
34.97.7.155 - - [04/Sep/2026:15:52:53 +0200] "GET /_ignition/health-check HTTP/1.1" 404 146 "-" "crusader-worker/1.0"
34.97.7.155 - - [04/Sep/2026:15:52:53 +0200] "GET /actuator/configprops HTTP/1.1" 404 146 "-" "crusader-worker/1.0"
34.97.7.155 - - [04/Sep/2026:15:52:53 +0200] "GET /storage/logs/laravel.log HTTP/1.1" 404 146 "-" "crusader-worker/1.0"
34.97.7.155 - - [04/Sep/2026:15:52:53 +0200] "GET /crusader-404-probe HTTP/1.1" 404 146 "-" "crusader-worker/1.0"
...
show less
Web App Attack
Port Scan
🇸🇪
vaia.cloud
2026-09-04 13:30:11
(11 hours ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 12:56:04
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.97.7.155 (155.7.97.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.97.7.155 (155.7.97.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 08:55:55.774994 2026] [security2:error] [pid 7335:tid 7335] [client 34.97.7.155:49276] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "marveldirectory.com"] [uri "/.env.example"] [unique_id "apq_22QDrnYeIYbu1agYSQAAAE0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 11:18:35
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.97.7.155 (155.7.97.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.97.7.155 (155.7.97.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 07:18:29.131840 2026] [security2:error] [pid 11973:tid 11973] [client 34.97.7.155:45764] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "economy-cleaners.com"] [uri "/.env.old"] [unique_id "apqpBQy1wR3mcOWlTHYYXQAAAC8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
masterguru
2026-09-04 10:22:34
(15 hours ago)
Restricted File Access Attempt. Matched phrase ".env" at REQUEST_FILENAME. (930130-201)
Hacking
Web App Attack
🇩🇪
Bedios GmbH
2026-09-04 10:07:36
(15 hours ago)
Login credentials theft attempt
Hacking
🇺🇸
TPI-Abuse
2026-09-04 10:06:19
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.97.7.155 (155.7.97.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.97.7.155 (155.7.97.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 06:06:15.300101 2026] [security2:error] [pid 23854:tid 23854] [client 34.97.7.155:47972] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.imbrasacademic.com"] [uri "/.env.production"] [unique_id "apqYF3dfFxd-Ufeu6HbNlwAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
masterguru
2026-09-04 09:58:43
(15 hours ago)
Restricted File Access Attempt. Matched phrase ".env" at REQUEST_FILENAME. (930130-193)
Hacking
Web App Attack
Anonymous
2026-09-04 09:18:52
(16 hours ago)
PSCSERV WPSCAN 34.97.7.155
Bad Web Bot
Web App Attack
🇫🇷
dynamix
2026-09-04 08:45:16
(16 hours ago)
Multiple WAF Violations
Web App Attack
🇪🇸
alferez
2026-09-04 08:42:19
(16 hours ago)
Searching .(env|sql|zip|tar|rar) files
Hacking
Exploited Host
Web App Attack
🇳🇱
WeCloudit-Anti-Abuse
2026-09-04 08:35:55
(16 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
Anonymous
2026-09-04 07:59:52
(17 hours ago)
apache-auth
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 06:29:51
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.97.7.155 (155.7.97.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.97.7.155 (155.7.97.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 02:29:47.912314 2026] [security2:error] [pid 10051:tid 10051] [client 34.97.7.155:49004] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bathound.batw.net"] [uri "/.env.dev"] [unique_id "applWyRFhI3CDAB7TH6QIQAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack