🇩🇪
XICTRON
2026-09-06 06:05:04
(10 hours ago)
ModSecurity rule violation detected by Fail2Ban
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 03:52:17
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.105.126.94 (94.126.105.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.105.126.94 (94.126.105.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 23:52:12.389792 2026] [security2:error] [pid 26204:tid 26212] [client 34.105.126.94:55596] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.sandiegosamband.com"] [uri "/.env.backup"] [unique_id "apzjbNBbnM4DZJ7oJiN9SwAAAQU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
SiyCah
2026-09-06 03:00:02
(13 hours ago)
IP banned by fail2ban; banned in jail apache-modsecurity. Report generated by fail2abuseipdb.
Hacking
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 02:58:28
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.105.126.94 (94.126.105.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.105.126.94 (94.126.105.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 22:58:24.685136 2026] [security2:error] [pid 23759:tid 23759] [client 34.105.126.94:58762] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.hiscreativedesign.com"] [uri "/.env"] [unique_id "apzW0Du9VPhYsSKn32MiZAAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 02:42:58
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.105.126.94 (94.126.105.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.105.126.94 (94.126.105.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 22:42:51.957710 2026] [security2:error] [pid 14119:tid 14119] [client 34.105.126.94:49088] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "afjm.info"] [uri "/.env.save"] [unique_id "apzTK4kvjAShO2OD-N-MDAAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
FeG Deutschland
2026-09-06 02:34:04
(14 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
🇬🇧
consul.to
2026-09-06 02:31:05
(14 hours ago)
Web attack/malicious scanning detected
Web App Attack
🇺🇸
mnsf
2026-09-06 02:05:02
(14 hours ago)
Scanning/Probing (20)
Brute-Force
Web App Attack
🇧🇷
Halux
2026-09-06 00:02:09
(16 hours ago)
34.105.126.94 Probing protected path or service
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 23:42:44
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.105.126.94 (94.126.105.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.105.126.94 (94.126.105.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 19:42:40.349422 2026] [security2:error] [pid 30984:tid 30984] [client 34.105.126.94:57172] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "15cherryavenue.com"] [uri "/.env.backup"] [unique_id "apyo8HA6c6o55RxObURtAgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 22:57:09
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.105.126.94 (94.126.105.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.105.126.94 (94.126.105.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 18:57:02.179597 2026] [security2:error] [pid 26731:tid 26731] [client 34.105.126.94:58492] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.derek-stites.com"] [uri "/.env.example"] [unique_id "apyePgKAq3mKBxBg5tkR_AAAAB8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 22:36:17
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.105.126.94 (94.126.105.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.105.126.94 (94.126.105.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 18:36:10.075235 2026] [security2:error] [pid 2919:tid 2940] [client 34.105.126.94:34812] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "g3-contracting.com"] [uri "/wp-config.php.bak"] [unique_id "apyZWmfyfRzPytDxxPZ58AAAAFM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-05 22:32:54
(18 hours ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-05 22:20:08
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.105.126.94 (94.126.105.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.105.126.94 (94.126.105.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 18:20:04.700378 2026] [security2:error] [pid 5831:tid 5831] [client 34.105.126.94:49054] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cyberclubcoin.com.crazycoin.net"] [uri "/.env.dev"] [unique_id "apyVlMszIE_lwogzXdy2JAAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
e.fierstra
2026-09-05 21:57:34
(18 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack