๐บ๐ธ
TPI-Abuse
2026-09-01 13:51:41
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.146.137.150 (150.137.146.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.146.137.150 (150.137.146.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 09:51:32.891250 2026] [security2:error] [pid 28814:tid 28814] [client 34.146.137.150:46056] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.watonga.com"] [uri "/.env.backup"] [unique_id "apbYZHQTTI7_f_Kgr0XBHwAAACg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
cybersteve99
2026-09-01 12:29:41
(1 day ago)
Too many 4xx Requests -
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 12:04:35
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.146.137.150 (150.137.146.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.146.137.150 (150.137.146.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 08:04:30.997597 2026] [security2:error] [pid 8289:tid 8289] [client 34.146.137.150:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "demondomain.com"] [uri "/.env"] [unique_id "apa_TsnX85pxlTrnrmUltAAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
dbmwebdesign
2026-09-01 11:10:04
(1 day ago)
WAF repeated trigger detected by Fail2Ban in plesk-modsecurity jail
Web App Attack
๐ฆ๐บ
AWW-Admin
2026-09-01 11:06:34
(1 day ago)
(mod_security) mod_security triggered on hostname [redacted] 34.146.137.150 (JP/Japan/150.137.146.34 ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.146.137.150 (JP/Japan/150.137.146.34.bc.googleusercontent.com)
show less
SQL Injection
๐บ๐ธ
TPI-Abuse
2026-09-01 10:59:02
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.146.137.150 (150.137.146.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.146.137.150 (150.137.146.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 06:58:54.458737 2026] [security2:error] [pid 2485:tid 2485] [client 34.146.137.150:48482] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.edelbaumarchitect.com"] [uri "/.env.prod"] [unique_id "apav7sBzX8seQFpF55BdIgAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Vegascosmetics
2026-09-01 09:37:41
(1 day ago)
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after PHP/CMS/webshell exploit probe (possi ...
show more
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after PHP/CMS/webshell exploit probe (possible exploited host). Evidence: AttackPattern: /wp-config\.php (Match: /wp-config.php)
show less
Hacking
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 08:51:49
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.146.137.150 (150.137.146.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.146.137.150 (150.137.146.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 04:51:44.828530 2026] [security2:error] [pid 5381:tid 5381] [client 34.146.137.150:37296] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "shiner.org"] [uri "/.env"] [unique_id "apaSIGGT9Tx0WwrR6P2LEgAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 07:53:46
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.146.137.150 (150.137.146.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.146.137.150 (150.137.146.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 03:53:39.702213 2026] [security2:error] [pid 10802:tid 10802] [client 34.146.137.150:46504] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.jerryfeil.com"] [uri "/.env.example"] [unique_id "apaEg-Q5qozIFhGEfdWQsgAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
consul.to
2026-09-01 07:41:09
(1 day ago)
Web attack/malicious scanning detected
Web App Attack
๐ฉ๐ช
FD-IX
2026-09-01 07:19:49
(1 day ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
Anonymous
2026-09-01 07:09:03
(1 day ago)
Bot / scanning and/or hacking attempts: GET /.env HTTP/1.1, GET /_ignition/health-check HTTP/1.1, GE ...
show more
Bot / scanning and/or hacking attempts: GET /.env HTTP/1.1, GET /_ignition/health-check HTTP/1.1, GET /.env.prod HTTP/1.1, GET /.env.local HTTP/1.1, GET /storage/logs/laravel.log HTTP/1.1
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 04:28:44
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.146.137.150 (150.137.146.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.146.137.150 (150.137.146.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 00:28:38.768724 2026] [security2:error] [pid 6500:tid 6500] [client 34.146.137.150:53146] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "boat-registration-spain.com"] [uri "/.env.production"] [unique_id "apZUdh2vU_Y5sfLsXPdaZwAAACM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฟ๐ฆ
conure.sh
2026-09-01 04:11:44
(1 day ago)
csagent: score 20.0: wp-config backup grab x2; 1 domain(s) in 0s
Web App Attack
๐ฎ๐ฉ
penjaga BRIN
2026-09-01 03:37:38
(1 day ago)
Suspicious malicious activity
Hacking