๐ฉ๐ช
4server
2026-06-07 11:12:10
(2 weeks ago)
[SunJun0713:12:08.2827342026][security2:error][pid3748272:tid3748369][client34.121.118.169:0]ModSecu ...
show more
[SunJun0713:12:08.2827342026][security2:error][pid3748272:tid3748369][client34.121.118.169:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Patternmatch\"\(\?i\)\(curl\|wget\|python\|nikto\|sqlmap\|acunetix\|fimap\|dirbuster\|cmsmap\)\"atREQUEST_HEADERS:User-Agent.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"217\"][id\"990210\"][msg\"Suspicioususer-agentblocked\"][hostname\"laumeiconsulting.com\"][uri\"/.env\"][unique_id\"aiVSCJyh4BQxaC8M1wJO2gAAAFc\"]
show less
Port Scan
Brute-Force
Web App Attack
๐ซ๐ท
Allolatr
2026-06-06 13:19:21
(2 weeks ago)
Jun 6 15:19:20 [redacted] j443: ::ffff:34.121.118.169 [redacted].com "GET /.env HTTP/1.1" 400 0 "-" ...
show more
Jun 6 15:19:20 [redacted] j443: ::ffff:34.121.118.169 [redacted].com "GET /.env HTTP/1.1" 400 0 "-" "python-requests/2.28.1" Jun 6 15:19:21 [redacted] j443: ::ffff:34.121.118.169 [redacted].com "GET /.env.production HTTP/1.1" 400 146 "-" "python-requests/2.28.1"...
show less
Web App Attack
๐ฑ๐ป
garmtech.com
2026-06-06 11:44:24
(2 weeks ago)
IM360 WAF: Direct access to sensitive file or dotfile MV:/.env
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-05 19:05:42
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 34.121.118.169 (169.118.121.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.121.118.169 (169.118.121.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 05 15:05:37.709299 2026] [security2:error] [pid 9377:tid 9377] [client 34.121.118.169:37138] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "geo-modal.com"] [uri "/.env"] [unique_id "aiMeAVPKxOXr--7XkiUnugAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
BlueWire Hosting
2026-06-05 19:00:02
(2 weeks ago)
Bad bot ignoring robot.txt
Bad Web Bot
๐ฎ๐น
abuseiphack
2026-06-05 18:35:43
(2 weeks ago)
Automatic report for brute force attack
Bad Web Bot
๐ณ๐ฑ
juutis
2026-06-05 18:07:50
(2 weeks ago)
Multiple WAF abuses - IP blocked
Hacking
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-05 18:07:42
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 34.121.118.169 (169.118.121.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.121.118.169 (169.118.121.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 05 14:07:38.356731 2026] [security2:error] [pid 17066:tid 17066] [client 34.121.118.169:40460] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "lakeviewbewdley.com"] [uri "/.env"] [unique_id "aiMQarps6kDYTIZIkYZIZAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
screwlooseit.com.au
2026-06-05 17:48:17
(2 weeks ago)
Blocked by CSF 13 firewall - Rule: config-dotfile
US/United States/169.118.121.34.bc.googleuserconte ...
show more
Blocked by CSF 13 firewall - Rule: config-dotfile
US/United States/169.118.121.34.bc.googleusercontent.com
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-05 17:40:10
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 34.121.118.169 (169.118.121.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.121.118.169 (169.118.121.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 05 13:40:03.690170 2026] [security2:error] [pid 31791:tid 31791] [client 34.121.118.169:47300] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kunzteam.com"] [uri "/.env"] [unique_id "aiMJ87DnFpAL7h5n8zKJ7gAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-05 16:37:26
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 34.121.118.169 (169.118.121.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.121.118.169 (169.118.121.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 05 12:37:21.081284 2026] [security2:error] [pid 6184:tid 6184] [client 34.121.118.169:49872] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "leothecolorman.com"] [uri "/.env"] [unique_id "aiL7Qb0HyQMvtxbqd1Z68AAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-05 15:17:18
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 34.121.118.169 (169.118.121.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.121.118.169 (169.118.121.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 05 11:17:10.699741 2026] [security2:error] [pid 8863:tid 8863] [client 34.121.118.169:59296] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jeffautry.com"] [uri "/.env"] [unique_id "aiLodlXFN1v5VQnVXM2ebwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
4server
2026-06-05 15:08:55
(2 weeks ago)
[FriJun0517:08:52.6705052026][security2:error][pid926670:tid926759][client34.121.118.169:0]ModSecuri ...
show more
[FriJun0517:08:52.6705052026][security2:error][pid926670:tid926759][client34.121.118.169:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Patternmatch\"\(\?i\)\(curl\|wget\|python\|nikto\|sqlmap\|acunetix\|fimap\|dirbuster\|cmsmap\)\"atREQUEST_HEADERS:User-Agent.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"217\"][id\"990210\"][msg\"Suspicioususer-agentblocked\"][hostname\"laumeiconsulting.com\"][uri\"/.env\"][unique_id\"aiLmhIu6noXOhvAQU_RI7AAAAMM\"]
show less
Port Scan
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-05 14:56:12
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 34.121.118.169 (169.118.121.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.121.118.169 (169.118.121.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 05 10:56:04.872689 2026] [security2:error] [pid 22847:tid 22847] [client 34.121.118.169:50290] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jennlaurenphotography.com"] [uri "/.env"] [unique_id "aiLjhASCzRWj0-diTYJ4pAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
paissangroup
2026-06-05 14:04:46
(2 weeks ago)
Multiple WAF Violations
Web App Attack