🇺🇸
TPI-Abuse
2026-09-06 03:50:03
(10 minutes ago)
(mod_security) mod_security (id:210492) triggered by 130.211.252.109 (109.252.211.130.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 130.211.252.109 (109.252.211.130.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 23:49:58.995656 2026] [security2:error] [pid 17660:tid 17660] [client 130.211.252.109:47338] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.kemela.com"] [uri "/wp-config.php~"] [unique_id "apzi5nNAWhTqfu6KpKZwCAAAADc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-06 03:49:21
(11 minutes ago)
Aggressive web scan
Web App Attack
🇺🇸
MatCat
2026-09-06 03:05:09
(55 minutes ago)
Banned by fail2ban: apache-webprobe
Port Scan
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-06 03:01:39
(58 minutes ago)
(mod_security) mod_security (id:210492) triggered by 130.211.252.109 (109.252.211.130.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 130.211.252.109 (109.252.211.130.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 23:01:34.663784 2026] [security2:error] [pid 20715:tid 20715] [client 130.211.252.109:40992] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.renju.net"] [uri "/.env.production"] [unique_id "apzXjqT8trqVwXW2TE8QngAAADQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
SwinT
2026-09-06 03:00:07
(1 hour ago)
WAF repeated trigger detected by Fail2Ban in plesk-modsecurity jail
Web App Attack
🇺🇸
kosada.com
2026-09-06 02:28:59
(1 hour ago)
Repeated requests for suspicious nonexistent URLs, for example: /.env.local (HTTP/1.1 port 443, bogu ...
show more
Repeated requests for suspicious nonexistent URLs, for example: /.env.local (HTTP/1.1 port 443, bogus vhost, user agent: "crusader-worker/1.0")
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 02:21:04
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 130.211.252.109 (109.252.211.130.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 130.211.252.109 (109.252.211.130.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 22:20:59.451992 2026] [security2:error] [pid 25069:tid 25069] [client 130.211.252.109:40136] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "supportourlibrary.org"] [uri "/.env.bak"] [unique_id "apzOC7ygOJokcJ_iKe2KagAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
masterguru
2026-09-06 01:36:05
(2 hours ago)
Restricted File Access Attempt. Matched phrase ".env" at REQUEST_FILENAME. (930130-196)
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 01:32:59
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 130.211.252.109 (109.252.211.130.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 130.211.252.109 (109.252.211.130.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 21:32:51.380365 2026] [security2:error] [pid 21826:tid 21826] [client 130.211.252.109:37670] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mrobertsignaturehomes.com.globalsolutions.technology"] [uri "/.env.backup"] [unique_id "apzCw4rvHGkUiNEbM96AUAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 00:47:21
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 130.211.252.109 (109.252.211.130.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 130.211.252.109 (109.252.211.130.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 20:47:15.670098 2026] [security2:error] [pid 31422:tid 31422] [client 130.211.252.109:44296] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.professorjunk.com"] [uri "/wp-config.php.bak"] [unique_id "apy4E5kdquNJBo3RHfJq7wAAAG4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
dynamix
2026-09-06 00:42:57
(3 hours ago)
Multiple WAF Violations
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 23:57:02
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 130.211.252.109 (109.252.211.130.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 130.211.252.109 (109.252.211.130.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 19:56:57.738793 2026] [security2:error] [pid 26419:tid 26419] [client 130.211.252.109:45666] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.iyp-home.com"] [uri "/.env.backup"] [unique_id "apysSY14SW2FOc9wmvcJfAAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
e.fierstra
2026-09-05 23:00:48
(4 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 22:54:30
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 130.211.252.109 (109.252.211.130.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 130.211.252.109 (109.252.211.130.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 18:54:23.925282 2026] [security2:error] [pid 20386:tid 20386] [client 130.211.252.109:39178] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.siciliafamily.com"] [uri "/wp-config.php.swp"] [unique_id "apydn1JCtuYGCHuMAUjA5wAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-05 22:38:56
(5 hours ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack