🇺🇸
TPI-Abuse
2026-09-04 15:23:20
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.126.166.248 (248.166.126.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.126.166.248 (248.166.126.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 11:23:13.618332 2026] [security2:error] [pid 7608:tid 7608] [client 34.126.166.248:31974] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.iconbizpromo.com"] [uri "/@fs/app/.env"] [unique_id "apriYScZypk5fUBsO2x2xAAAAIU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇪🇸
librebit
2026-09-04 15:22:45
(15 hours ago)
Bad guys doing bad things, bad crawling
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-04 14:57:40
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.126.166.248 (248.166.126.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.126.166.248 (248.166.126.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 10:57:34.629871 2026] [security2:error] [pid 18092:tid 18092] [client 34.126.166.248:12098] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "evtoy.danged.com"] [uri "/@fs/.env"] [unique_id "aprcXvWY8nDwUkYwCvaDSwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 14:03:20
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.126.166.248 (248.166.126.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.126.166.248 (248.166.126.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 10:03:15.934747 2026] [security2:error] [pid 29889:tid 29889] [client 34.126.166.248:46704] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.aivosminerals.com"] [uri "/@fs/.env"] [unique_id "aprPowSYYiPzUJIk0fs_VAAAAF8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-04 13:54:36
(17 hours ago)
Blocked by ModSec and CSF
Port Scan
🇸🇪
vaia.cloud
2026-09-04 13:40:05
(17 hours ago)
crowdsecurity/http-probing
Brute-Force
Web App Attack
🇳🇱
debestelapp
2026-09-04 12:20:10
(18 hours ago)
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 12:11:48
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.126.166.248 (248.166.126.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.126.166.248 (248.166.126.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 08:11:45.847065 2026] [security2:error] [pid 2824996:tid 2825044] [client 34.126.166.248:59246] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.myrasnyder.com"] [uri "/@fs/root/.env"] [unique_id "apq1gR0fUXAXMoF-M9v48QAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇪🇸
alferez
2026-09-04 08:47:15
(22 hours ago)
Searching .(env|sql|zip|tar|rar) files
Hacking
Exploited Host
Web App Attack
🇫🇷
masterguru
2026-09-04 08:06:35
(23 hours ago)
(modsec_5015) ModSec 5015: Suspicious User-Agent from 34.126.166.248 (SG/Singapore/248.166.126.34.bc ...
show more
(modsec_5015) ModSec 5015: Suspicious User-Agent from 34.126.166.248 (SG/Singapore/248.166.126.34.bc.googleusercontent.com): 1 in the last 3600 secs (0-196)
show less
Hacking
🇸🇪
vaia.cloud
2026-09-04 08:05:04
(23 hours ago)
crowdsecurity/http-path-traversal-probing
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 07:20:56
(23 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.126.166.248 (248.166.126.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.126.166.248 (248.166.126.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 03:20:50.745652 2026] [security2:error] [pid 432:tid 432] [client 34.126.166.248:28592] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "thelotsmokehouse.com"] [uri "/@fs/root/.env"] [unique_id "appxUrEgdytI6X086ECWawAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 06:45:59
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.126.166.248 (248.166.126.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.126.166.248 (248.166.126.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 02:45:55.387000 2026] [security2:error] [pid 17252:tid 17252] [client 34.126.166.248:28740] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.delunafamily.thelowensteinfamily.com"] [uri "/@fs/.env"] [unique_id "apppI9aNzXb377r_l0-C2QAAACU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
OptimusGO
2026-09-04 06:00:37
(1 day ago)
Malicious activity detected: web_attack
Server: commstackbc (185.127.18.66)
Attack: web_attack
Time ...
show more
Malicious activity detected: web_attack
Server: commstackbc (185.127.18.66)
Attack: web_attack
Timestamp: 2026-09-04 07:00:37 UTC
Log evidence:
34.126.166.248 - - [04/Sep/2026:07:00:30 +0100] "GET / HTTP/1.1" 200 409 "-" "Mozilla/5.0 (Linux; Android 13; SM-G935R6; Build/TP1A.180718.91) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.6261.127 Mobile Safari/537.36"
09/04/2026-07:00:36.712418 [wDrop] [**] [1:7000500:1] FINSERV CRITICAL: Aggressive Port Scan [**] [Classification: Attempted Information Leak] [Priority: 2] {TCP} 34.126.166.248:40664 -> 185.127.18.66:443
09/04/2026-07:00:36.712418 [**] [1:9000060:2] AUTONOMOUS Long-term Reconnaissance [**] [Classification: (null)] [Priority: 2] {TCP} 34.126.166.248:40664 -> 185.127.18.66:443
show less
Port Scan
Brute-Force
🇬🇧
consul.to
2026-09-04 05:52:50
(1 day ago)
Web attack/malicious scanning detected
Web App Attack