🇬🇧
andypiper
2026-09-06 01:00:26
(7 minutes ago)
CrowdSec ban for AbuseIPDB Top List
Brute-Force
Web App Attack
🇩🇪
FD-IX
2026-09-06 00:28:54
(38 minutes ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 00:23:30
(43 minutes ago)
(mod_security) mod_security (id:210492) triggered by 34.106.251.118 (118.251.106.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.106.251.118 (118.251.106.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 20:23:25.292985 2026] [security2:error] [pid 1626:tid 1626] [client 34.106.251.118:39878] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "knoxvillelimos.com"] [uri "/.env.bak"] [unique_id "apyyfTiQgxI-j1UEzAH9PQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
Philister11
2026-09-06 00:16:24
(51 minutes ago)
CrowdSec: crowdsecurity/http-probing (US/AS396982)
Web App Attack
Hacking
🇮🇳
evicky2002
2026-09-06 00:02:40
(1 hour ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
🇺🇸
TPI-Abuse
2026-09-05 23:56:09
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.106.251.118 (118.251.106.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.106.251.118 (118.251.106.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 19:56:03.859098 2026] [security2:error] [pid 27739:tid 27739] [client 34.106.251.118:43218] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.cmcgroup.us.com"] [uri "/.env"] [unique_id "apysEyqRjrhvRpK6DL3fjAAAAEs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 23:26:14
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.106.251.118 (118.251.106.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.106.251.118 (118.251.106.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 19:26:10.361001 2026] [security2:error] [pid 24324:tid 24324] [client 34.106.251.118:46884] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "xcingenieria.com"] [uri "/wp-config.php.swp"] [unique_id "apylEiT_EmemOkbsa0b0hgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
macrob
2026-09-05 22:56:47
(2 hours ago)
2026/09/05 22:56:46 [error] 1902787#1902787: *560875304 access forbidden by rule, client: 34.106.251 ...
show more
2026/09/05 22:56:46 [error] 1902787#1902787: *560875304 access forbidden by rule, client: 34.106.251.118, server: fn.binixo.es, request: "GET /.env.old HTTP/2.0", host: "mailgate.fastcredit.net.ua"
2026/09/05 22:56:46 [error] 1902787#1902787: *560875306 access forbidden by rule, client: 34.106.251.118, server: fn.binixo.es, request: "GET /.env.local HTTP/2.0", host: "mailgate.fastcredit.net.ua"
2026/09/05 22:56:46 [error] 1902787#1902787: *560875308 access forbidden by rule, client: 34.106.251.118, server: fn.binixo.es, request: "GET /.env.prod HTTP/2.0", host: "mailgate.fastcredit.net.ua"
...
show less
Web App Attack
🇫🇮
Shaik Sai Meera
2026-09-05 21:40:14
(3 hours ago)
IM360 WAF: Hidden file access
Brute-Force
Anonymous
2026-09-05 21:10:03
(3 hours ago)
suspicious request in access.log
Web App Attack
🇺🇸
mnsf
2026-09-05 21:05:18
(4 hours ago)
Scanning/Probing (20)
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 20:39:41
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.106.251.118 (118.251.106.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.106.251.118 (118.251.106.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 16:39:33.370686 2026] [security2:error] [pid 2801:tid 2801] [client 34.106.251.118:42846] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "meridianranchdrc.org"] [uri "/.env.backup"] [unique_id "apx-Bd8FFCOT05lP1Y2HXAAAACA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
big-cloud.nl
2026-09-05 20:38:30
(4 hours ago)
Try to access /.env
Web App Attack
🇫🇷
hxsain
2026-09-05 07:04:19
(18 hours ago)
Automated report from CrowdSec: probing for exposed configuration and credential files. 5 events obs ...
show more
Automated report from CrowdSec: probing for exposed configuration and credential files. 5 events observed.
show less
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 15:16:45
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.106.251.118 (118.251.106.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.106.251.118 (118.251.106.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 11:16:37.038202 2026] [security2:error] [pid 18040:tid 18040] [client 34.106.251.118:51314] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.pagewideprinting.com"] [uri "/.env.prod"] [unique_id "aprg1YVxpQ2Aazd5CJxMuwAAAFI"]
show less
Brute-Force
Bad Web Bot
Web App Attack