🇺🇸
TPI-Abuse
2026-09-08 03:36:40
(36 minutes ago)
(mod_security) mod_security (id:210492) triggered by 34.145.226.93 (93.226.145.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.145.226.93 (93.226.145.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 23:36:35.839091 2026] [security2:error] [pid 20399:tid 20399] [client 34.145.226.93:29202] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.i-579captiger.pghsea.com"] [uri "/@fs/.env"] [unique_id "ap-Cw0bmnTzyWUOrVWuW8gAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
FeG Deutschland
2026-09-08 03:16:00
(56 minutes ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 127
Exploited Host
Web App Attack
🇩🇪
Vegascosmetics
2026-09-08 02:59:30
(1 hour ago)
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after first-seen suspicion / AbuseIPDB repu ...
show more
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after first-seen suspicion / AbuseIPDB reputation policy (no URL signature). Evidence: Suspicion-Ban (Score 80>=65, Abuse 90, NonEU, first-seen)
show less
Hacking
Exploited Host
Web App Attack
🇫🇷
Phenix Info
2026-09-08 02:57:08
(1 hour ago)
SmallGuard.fr/Prestashop Massive 403
Web App Attack
🇳🇱
Mangelot Hosting
2026-09-08 02:56:50
(1 hour ago)
(modsecurity) srv101 ModSecurity 34.145.226.93 (US/United States/93.226.145.34.bc.googleusercontent. ...
show more
(modsecurity) srv101 ModSecurity 34.145.226.93 (US/United States/93.226.145.34.bc.googleusercontent.com): 30 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs:
show less
Web App Attack
🇨🇭
zynex
2026-09-08 02:54:12
(1 hour ago)
URL Probing: /@fs/..%252f..%252f..%252f..%252f..%252fapp/.env
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 02:02:00
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.145.226.93 (93.226.145.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.145.226.93 (93.226.145.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 22:01:54.672942 2026] [security2:error] [pid 29986:tid 29986] [client 34.145.226.93:1432] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.linneus.com"] [uri "/@fs/..%252f..%252f..%252f..%252f..%252froot/.env"] [unique_id "ap9sklVKoMgBKyxkTHj30QAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇧🇪
cmbplf
2026-09-08 01:31:03
(2 hours ago)
740 requests with url.path *.aws/*
165 requests with url.path */auth.json
110 requests with url.p ...
show more
740 requests with url.path *.aws/*
165 requests with url.path */auth.json
110 requests with url.path *sendgrid.env
show less
Brute-Force
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-08 01:30:25
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.145.226.93 (93.226.145.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.145.226.93 (93.226.145.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 21:30:20.241925 2026] [security2:error] [pid 23122:tid 23122] [client 34.145.226.93:2088] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.brownweddinginvitations.net"] [uri "/@fs/root/.env"] [unique_id "ap9lLKjbYvsrsT0havap2QAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
e.fierstra
2026-09-08 01:20:01
(2 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 01:14:36
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.145.226.93 (93.226.145.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.145.226.93 (93.226.145.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 21:14:29.598409 2026] [security2:error] [pid 9388:tid 9388] [client 34.145.226.93:3552] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.morleysales.com"] [uri "/@fs/.env"] [unique_id "ap9hdXr36KijHE5OJ9rRLwAAACI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇪🇸
pipeline.es
2026-09-08 01:12:57
(2 hours ago)
Web scanning / probing for vulnerable paths | URL: /.env | Evidence: 34.145.226.93 - - [08/Sep/2026: ...
show more
Web scanning / probing for vulnerable paths | URL: /.env | Evidence: 34.145.226.93 - - [08/Sep/2026:03:12:35 +0200] \"GET /.env HTTP/1.1\" 404 51968 \"https://spainbytrain.info/.env\" \"Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; WhatsApp/[internal_ip])\" GEOIP_COUNTRY_CODE=US | ASN: GOOGLE-CLOUD-PLATFORM | Country: US
show less
Port Scan
Web App Attack
🇳🇱
EGP Abuse Dept
2026-09-08 00:51:07
(3 hours ago)
Scanning for web/db/file exploits on knodtablemanner.tafelconfigurator.nl
SQL Injection
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 00:28:57
(3 hours ago)
(mod_security) mod_security (id:949110) triggered by 34.145.226.93 (93.226.145.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:949110) triggered by 34.145.226.93 (93.226.145.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 20:28:50.230991 2026] [security2:error] [pid 15016:tid 15016] [client 34.145.226.93:43522] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "usataxgroup.com"] [uri "/@fs/.env"] [unique_id "ap9Wwpt9J8Lw_Q-AxnBU0gAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
mnsf
2026-09-08 00:05:25
(4 hours ago)
Scanning/Probing (92)
Request Overload (102)
Brute-Force
Web App Attack