Anonymous
2026-09-04 01:14:49
(35 minutes ago)
Blocked by FortiWeb WAF ML threat detection. ML probability: 99%, Country: BE, Attack patterns: Word ...
show more
Blocked by FortiWeb WAF ML threat detection. ML probability: 99%, Country: BE, Attack patterns: WordPress scanning, Backup file probing, Cloud secrets probing
show less
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-04 00:49:25
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.140.213.192 (192.213.140.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.140.213.192 (192.213.140.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 20:49:20.733369 2026] [security2:error] [pid 17557:tid 17557] [client 34.140.213.192:51654] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.romestudios.com"] [uri "/@fs/root/.env"] [unique_id "apoVkPEN5Aa9ZEzJhn5CjgAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-04 00:20:35
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.140.213.192 (192.213.140.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.140.213.192 (192.213.140.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 20:20:30.792509 2026] [security2:error] [pid 11916:tid 11916] [client 34.140.213.192:25076] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.sierra-broadcasting.com"] [uri "/@fs/app/.env"] [unique_id "apoOzkBd947_KeWM3V8MawAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-04 00:02:31
(1 hour ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
Anonymous
2026-09-03 23:45:01
(2 hours ago)
suspicious request in access.log
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-03 23:44:30
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.140.213.192 (192.213.140.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.140.213.192 (192.213.140.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 19:44:26.303727 2026] [security2:error] [pid 28433:tid 28433] [client 34.140.213.192:24204] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.epicureankids.com"] [uri "/@fs/.env"] [unique_id "apoGWjbgxon5aZqaxBHUJAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-03 23:29:11
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.140.213.192 (192.213.140.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.140.213.192 (192.213.140.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 19:29:05.001593 2026] [security2:error] [pid 32270:tid 32270] [client 34.140.213.192:28464] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.directoryofdrugs.com"] [uri "/@fs/.env"] [unique_id "apoCwcdz5vFs8_3Q1AArBwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-03 23:05:12
(2 hours ago)
Bot / seems abusive / Apache connections: 71
DDoS Attack
Web Spam
Bad Web Bot
Web App Attack
π³π±
Site.eu
2026-09-03 22:59:35
(2 hours ago)
Excessive multi-domain requests
Brute-Force
π³π±
Savvii
2026-09-03 22:07:31
(3 hours ago)
20 attempts against mh-misbehave-ban on redirect
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-03 21:19:02
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.140.213.192 (192.213.140.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.140.213.192 (192.213.140.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 17:18:53.936625 2026] [security2:error] [pid 3598:tid 3598] [client 34.140.213.192:31998] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.advantage-plus.net"] [uri "/@fs/root/.env"] [unique_id "apnkPdIIZFnp4KU5aJka2gAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-03 20:56:33
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.140.213.192 (192.213.140.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.140.213.192 (192.213.140.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 16:56:26.229300 2026] [security2:error] [pid 32523:tid 32523] [client 34.140.213.192:59958] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.naturalacu.com"] [uri "/@fs/app/.env"] [unique_id "apne-lbQVW6_Fse3avl3WgAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
palzer.IT
2026-09-03 20:41:49
(5 hours ago)
Fail2ban automatic report for plesk-apache-badbot: 34.140.213.192 - - [03/Sep/2026:22:41:35 +0200] G ...
show more
Fail2ban automatic report for plesk-apache-badbot: 34.140.213.192 - - [03/Sep/2026:22:41:35 +0200] GET /@fs/app/.env?raw?? [DOMAIN_REMOVED] 404 6663 [DOMAIN_REMOVED] Mozilla/5.0 (Windows NT 10.0; rv:150.14) Gecko/20100101 Firefox/150.14; compatible; Amzn-SearchBot/1.0; +[DOMAIN_REMOVED]
show less
Bad Web Bot
πΊπΈ
TPI-Abuse
2026-09-03 20:28:20
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.140.213.192 (192.213.140.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.140.213.192 (192.213.140.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 16:28:13.607503 2026] [security2:error] [pid 27381:tid 27381] [client 34.140.213.192:31370] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.boulevardflowergardens.com"] [uri "/@fs/root/.env"] [unique_id "apnYXc1Kf6qPkOV-N5647wAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
WeCloudit-Anti-Abuse
2026-09-03 20:18:17
(5 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking