🇷🇴
SpamStopper
2026-09-04 15:36:28
(1 day ago)
Fail2Ban - WordPress Bruteforce and Badbots
Hacking
Bad Web Bot
🇬🇧
Aetherweb Ark
2026-09-04 15:25:12
(1 day ago)
(mod_security) mod_security (id:949110) triggered by 34.125.155.211 (US/United States/211.155.125.34 ...
show more
(mod_security) mod_security (id:949110) triggered by 34.125.155.211 (US/United States/211.155.125.34.bc.googleusercontent.com): N in the last X secs
show less
Web App Attack
🇳🇱
ConsulHosting
2026-09-04 15:04:55
(1 day ago)
Excessive failed CAPTCHA attempts (CAPTCHA DoS)
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 14:42:52
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.125.155.211 (211.155.125.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.125.155.211 (211.155.125.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 10:42:45.350072 2026] [security2:error] [pid 14522:tid 14522] [client 34.125.155.211:10782] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.pamelalambert.com"] [uri "/@fs/app/.env"] [unique_id "aprY5RJLDX5A--v5OTli5AAAAEQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
mnsf
2026-09-04 14:05:29
(1 day ago)
Abuse Detected (10)
Brute-Force
Web App Attack
Anonymous
2026-09-04 10:50:02
(1 day ago)
suspicious request in access.log
Web App Attack
🇩🇰
RhQM
2026-09-04 10:36:23
(1 day ago)
Bad Web Bot
Exploited Host
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 10:11:02
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.125.155.211 (211.155.125.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.125.155.211 (211.155.125.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 06:10:58.233600 2026] [security2:error] [pid 26924:tid 26924] [client 34.125.155.211:46622] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.ladymfashion.com"] [uri "/@fs/.env"] [unique_id "apqZMgzVwtk_z22UKJUBIAAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-04 09:43:34
(1 day ago)
34.125.155.211 - - [04/Sep/2026:04:43:34 -0500] "GET /.env.local HTTP/1.1" 403 199 "-" "Mozilla/5.0 ...
show more
34.125.155.211 - - [04/Sep/2026:04:43:34 -0500] "GET /.env.local HTTP/1.1" 403 199 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; OAI-SearchBot/1.3; +https://openai.com/searchbot)" 34.125.155.211
34.125.155.211 - - [04/Sep/2026:04:43:34 -0500] "GET /.env.production HTTP/1.1" 403 199 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_4 like Mac OS X) AppleWebKit/537.36 (KHTML, like Gecko; compatible; TelegramBot/1.0) Chrome/151.0.2070.151 Mobile Safari/537.36" 34.125.155.211
34.125.155.211 - - [04/Sep/2026:04:43:34 -0500] "GET /.env.staging HTTP/1.1" 403 199 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; Twitterbot/1.0" 34.125.155.211
34.125.155.211 - - [04/Sep/2026:04:43:34 -0500] "GET /.env.old HTTP/1.1" 403 199 "-" "Mozilla/5.0 (Windows NT 10.0; rv:149.0) Gecko/20100101 Firefox/149.0; compatible; OAI-SearchBot/1.3; +https://openai.com/searchbot" 34.125.155.211
34.125.155.211 - - [04/Sep/2026:04:43:34 -0500] "GET /.env.development HTTP/1.1" 403 199 "
...
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 09:31:04
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.125.155.211 (211.155.125.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.125.155.211 (211.155.125.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 05:30:59.037239 2026] [security2:error] [pid 32677:tid 32677] [client 34.125.155.211:46054] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.sarahsmith.ws"] [uri "/@fs/app/.env"] [unique_id "apqP01mnMCCnORsMZFpXZwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
IRISIO
2026-09-04 09:12:58
(1 day ago)
scans/SQL injection/spam posts : 925 queries
Web App Attack
SQL Injection
🇺🇸
TPI-Abuse
2026-09-04 09:11:58
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.125.155.211 (211.155.125.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.125.155.211 (211.155.125.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 05:11:52.737954 2026] [security2:error] [pid 24559:tid 24559] [client 34.125.155.211:37142] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.mikechilders.me"] [uri "/@fs/..%252f..%252f..%252f..%252f..%252froot/.env"] [unique_id "apqLWAldS33AUubTZ2H2wAAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇰
HostingGroup
2026-09-04 08:41:53
(1 day ago)
Automated malicious activity (Honeypot Trap) detected and blocked at the CDN edge by NordicCDN Shiel ...
show more
Automated malicious activity (Honeypot Trap) detected and blocked at the CDN edge by NordicCDN Shield. Offenses: 9. First blocked: 2026-09-04.
show less
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 07:27:40
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.125.155.211 (211.155.125.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.125.155.211 (211.155.125.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 03:27:34.696290 2026] [security2:error] [pid 28434:tid 28434] [client 34.125.155.211:24976] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.crearetest.com"] [uri "/@fs/app/.env"] [unique_id "appy5lVUwV-OgTea3xh2CwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 06:16:43
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.125.155.211 (211.155.125.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.125.155.211 (211.155.125.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 02:16:36.989118 2026] [security2:error] [pid 6335:tid 6335] [client 34.125.155.211:51538] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.senji.me"] [uri "/@fs/.env"] [unique_id "appiRLkfFRQ4B8Qu-InxhgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack