🇺🇸
TPI-Abuse
2026-09-06 03:01:21
(7 minutes ago)
(mod_security) mod_security (id:210492) triggered by 34.106.160.72 (72.160.106.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.106.160.72 (72.160.106.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 23:01:16.707259 2026] [security2:error] [pid 16784:tid 16784] [client 34.106.160.72:51946] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.adamsclothiers.com"] [uri "/.env.production"] [unique_id "apzXfICTDXK0-ls8NYowpwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
FD-IX
2026-09-06 02:56:49
(11 minutes ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
🇺🇦
URAN Publishing Service
2026-09-06 02:54:40
(13 minutes ago)
[06/Sep/2026:05:54:40 +0300] -- 34.106.160.72 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.env ...
show more
[06/Sep/2026:05:54:40 +0300] -- 34.106.160.72 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.env.old HTTP/1.1
show less
Bad Web Bot
Web App Attack
🇸🇪
SkyDancer
2026-09-06 02:35:12
(33 minutes ago)
Multiple unauthorized attempts to access using wrong credentials. Attack automatically blocked by Sk ...
show more
Multiple unauthorized attempts to access using wrong credentials. Attack automatically blocked by SkyDancer Ai. EXT-SYS-Vx
show less
Hacking
Brute-Force
SSH
🇺🇸
Gabriel Camargo
2026-09-06 01:20:04
(1 hour ago)
34.106.160.72 - - [05/Sep/2026:20:20:03 -0500] "GET /.env.bak HTTP/1.1" 301 178 "-" "crusader-worker ...
show more
34.106.160.72 - - [05/Sep/2026:20:20:03 -0500] "GET /.env.bak HTTP/1.1" 301 178 "-" "crusader-worker/1.0"
34.106.160.72 - - [05/Sep/2026:20:20:03 -0500] "GET /.env.old HTTP/1.1" 301 178 "-" "crusader-worker/1.0"
34.106.160.72 - - [05/Sep/2026:20:20:03 -0500] "GET /actuator/configprops HTTP/1.1" 301 178 "-" "crusader-worker/1.0"
...
show less
Brute-Force
SSH
🇺🇸
TPI-Abuse
2026-09-06 01:09:32
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.106.160.72 (72.160.106.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.106.160.72 (72.160.106.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 21:09:28.259746 2026] [security2:error] [pid 31564:tid 31564] [client 34.106.160.72:39864] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.kentsmithfamily.com"] [uri "/wp-config.php.swp"] [unique_id "apy9SER-1dTq0GN7f2WkbgAAACY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
consul.to
2026-09-06 00:29:26
(2 hours ago)
Web attack/malicious scanning detected
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 00:12:37
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.106.160.72 (72.160.106.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.106.160.72 (72.160.106.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 20:12:30.068237 2026] [security2:error] [pid 10370:tid 10370] [client 34.106.160.72:44416] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "1st-advantage-arkansas-real-estate-school.com"] [uri "/.env"] [unique_id "apyv7oaM7WErVSJVD3dtogAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
mnsf
2026-09-06 00:05:54
(3 hours ago)
Scanning/Probing (20)
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 23:55:03
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.106.160.72 (72.160.106.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.106.160.72 (72.160.106.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 19:54:56.596224 2026] [security2:error] [pid 19384:tid 19384] [client 34.106.160.72:51294] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.walterjhoodco.com"] [uri "/.env.production"] [unique_id "apyr0Ik5IG8nGGPjpqTsIgAAAC8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
dynamix
2026-09-05 23:38:11
(3 hours ago)
Multiple WAF Violations
Web App Attack
🇩🇪
Skyrider
2026-09-05 23:13:15
(3 hours ago)
crowdsecurity/http-sensitive-files
Web App Attack
🇩🇪
maxpower
2026-09-05 22:54:46
(4 hours ago)
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 34.106.160.72 (US/United States/72.160.1 ...
show more
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 34.106.160.72 (US/United States/72.160.106.34.bc.googleusercontent.com): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 34.106.160.72 - - [06/Sep/2026:00:54:42 +0200] "GET /wp-config.php.bak HTTP/1.1" 403 146 "-" "crusader-worker/1.0" "-" host=mail.lasfiziosapizzeria.it
show less
Port Scan
🇩🇪
on-com
2026-09-05 22:44:20
(4 hours ago)
URL scan
Brute-Force
Web App Attack
🇳🇱
WeCloudit-Anti-Abuse
2026-09-05 22:38:51
(4 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking