Anonymous
2026-08-29 03:30:11
(18 hours ago)
IP banned by Fail2Ban in jail nginx-abusive-ips
Web App Attack
Brute-Force
Bad Web Bot
🇺🇸
TPI-Abuse
2026-08-29 03:28:42
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.145.216.69 (69.216.145.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.145.216.69 (69.216.145.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 23:28:34.754535 2026] [security2:error] [pid 12950:tid 12950] [client 34.145.216.69:60568] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "hien.sonnyvo.com"] [uri "/.env.backup"] [unique_id "apJR4kSWpe3boXDZ3wheXQAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇮🇩
Burayot
2026-08-29 03:06:00
(19 hours ago)
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 34.145.216.69 (US/United States/69. ...
show more
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 34.145.216.69 (US/United States/69.216.145.34.bc.googleusercontent.com): 1 in the last 3600 secs
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-08-29 03:03:18
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.145.216.69 (69.216.145.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.145.216.69 (69.216.145.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 23:03:14.684847 2026] [security2:error] [pid 6987:tid 6987] [client 34.145.216.69:45848] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "paxbrewing.com"] [uri "/.env.save"] [unique_id "apJL8hrMQqMSbnvRVGNTCAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-29 02:14:55
(19 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.145.216.69 (69.216.145.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.145.216.69 (69.216.145.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 22:14:46.788785 2026] [security2:error] [pid 19639:tid 19639] [client 34.145.216.69:43000] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.momokuwait.gulftelecom.com|F|2"] [data ".log"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.momokuwait.gulftelecom.com"] [uri "/storage/logs/laravel.log"] [unique_id "apJAlpjIvr6S_10pDLVFiwAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
i-turnradio.nl
2026-08-29 00:53:57
(21 hours ago)
2026-08-29 02:53:57 (CET) ~ Blocked by abusescan risk assessment
Web App Attack
🇺🇸
TPI-Abuse
2026-08-29 00:50:37
(21 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.145.216.69 (69.216.145.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.145.216.69 (69.216.145.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 20:50:31.971986 2026] [security2:error] [pid 12725:tid 12725] [client 34.145.216.69:41144] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "magodarman.com"] [uri "/.env.production"] [unique_id "apIs14Zm4YSaygJT4P7mPgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇦🇺
dyln
2026-08-29 00:17:14
(21 hours ago)
Dyls honeypot brute-force: proto8 (19 total hits)
Brute-Force
🇺🇸
mnsf
2026-08-29 00:08:50
(22 hours ago)
Abuse Detected (12)
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-08-28 23:26:15
(22 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.145.216.69 (69.216.145.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.145.216.69 (69.216.145.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 19:26:07.885131 2026] [security2:error] [pid 20665:tid 20665] [client 34.145.216.69:57964] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.mta-sts.suffolksystems.com"] [uri "/.env"] [unique_id "apIZD4h7-8Zed9GSnW9lwwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-28 23:10:21
(23 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.145.216.69 (69.216.145.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.145.216.69 (69.216.145.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 19:10:16.628010 2026] [security2:error] [pid 10064:tid 10064] [client 34.145.216.69:52870] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "idatex.us"] [uri "/.env.backup"] [unique_id "apIVWObfUkaWoI3acqbkrAAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇨🇭
4server
2026-08-28 22:47:56
(23 hours ago)
[SatAug2900:47:49.4944782026][security2:error][pid3335451:tid3335722][client34.145.216.69:0]ModSecur ...
show more
[SatAug2900:47:49.4944782026][security2:error][pid3335451:tid3335722][client34.145.216.69:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\"wp-config\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"610\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"webdisk.eutecne.ch\"][uri\"/wp-config.php.swp\"][unique_id\"apIQFaxj8AM6O70VM5GyZQAAAM4\"]
show less
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-08-28 21:29:41
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.145.216.69 (69.216.145.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.145.216.69 (69.216.145.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 17:29:34.100890 2026] [security2:error] [pid 5398:tid 5398] [client 34.145.216.69:45396] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.ndakno.jazziientertainment.com"] [uri "/.env.prod"] [unique_id "apH9vn7qqSiRXhqkIneWBAAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇮🇹
Inartis
2026-08-28 21:12:31
(1 day ago)
34.145.216.69 - - [28/Aug/2026:23:12:29 +0200] "GET /.env.production HTTP/1.1" 403 5547 "-" "crusade ...
show more
34.145.216.69 - - [28/Aug/2026:23:12:29 +0200] "GET /.env.production HTTP/1.1" 403 5547 "-" "crusader-worker/1.0"
34.145.216.69 - - [28/Aug/2026:23:12:29 +0200] "GET /.env.example HTTP/1.1" 403 5531 "-" "crusader-worker/1.0"
34.145.216.69 - - [28/Aug/2026:23:12:29 +0200] "GET /.env.dev HTTP/1.1" 403 5547 "-" "crusader-worker/1.0"
...
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-28 18:50:05
(1 day ago)
suspicious request in access.log
Web App Attack