Anonymous
2026-09-08 13:11:32
(4 hours ago)
Blocked by FortiWeb WAF ML threat detection. ML probability: 99%, Country: JP, Attack patterns: Word ...
show more
Blocked by FortiWeb WAF ML threat detection. ML probability: 99%, Country: JP, Attack patterns: WordPress scanning, Backup file probing, Cloud secrets probing
show less
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 12:40:41
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.146.157.21 (21.157.146.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.146.157.21 (21.157.146.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 08:40:37.669027 2026] [security2:error] [pid 20323:tid 20323] [client 34.146.157.21:27890] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.progresstraining.info"] [uri "/@fs/.env"] [unique_id "aqACRacS1HP0SE0hdY7uMwAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-08 11:57:00
(5 hours ago)
Excessive crawling/scraping. Vulnerable file probing.
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 11:39:37
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.146.157.21 (21.157.146.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.146.157.21 (21.157.146.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 07:39:30.609636 2026] [security2:error] [pid 10140:tid 10140] [client 34.146.157.21:54494] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.whlr.net"] [uri "/@fs/.env"] [unique_id "ap_z8uE6n6n6rgTbeq6P-gAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 08:45:14
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.146.157.21 (21.157.146.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.146.157.21 (21.157.146.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 04:45:07.919344 2026] [security2:error] [pid 19037:tid 19037] [client 34.146.157.21:52474] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "hacemostuvideoia.com.verdadesreales.com"] [uri "/@fs/.env"] [unique_id "ap_LExNlF2Z1f3FI6r5FZwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
Apache
2026-09-08 08:29:04
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.146.157.21 (JP/Japan/21.157.146.34.bc.google ...
show more
(mod_security) mod_security (id:210492) triggered by 34.146.157.21 (JP/Japan/21.157.146.34.bc.googleusercontent.com): 5 in the last 300 secs (CF_ENABLE)
show less
Brute-Force
Web App Attack
Anonymous
2026-09-08 08:03:14
(9 hours ago)
Bot / seems abusive / Apache connections: 22
DDoS Attack
Web Spam
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 08:02:32
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.146.157.21 (21.157.146.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.146.157.21 (21.157.146.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 04:02:25.056321 2026] [security2:error] [pid 1714852:tid 1715270] [client 34.146.157.21:17318] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.360degreevalue.com"] [uri "/@fs/root/.env"] [unique_id "ap_BEROHGUIw6XcWdwoayQAAAVM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇸🇪
vaia.cloud
2026-09-08 07:55:03
(9 hours ago)
crowdsecurity/http-probing
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 07:47:15
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.146.157.21 (21.157.146.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.146.157.21 (21.157.146.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 03:47:08.341414 2026] [security2:error] [pid 1691:tid 1691] [client 34.146.157.21:1062] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.lighthousechristmascards.com"] [uri "/@fs/.env"] [unique_id "ap-9fE7Vl4hICf_hru0t3wAAAD8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 07:13:34
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.146.157.21 (21.157.146.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.146.157.21 (21.157.146.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 03:13:25.929949 2026] [security2:error] [pid 5748:tid 5748] [client 34.146.157.21:26336] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.oceanrich.biz"] [uri "/@fs/src/.env"] [unique_id "ap-1lUztCyKQd0ijUO4JBgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 06:26:59
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.146.157.21 (21.157.146.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.146.157.21 (21.157.146.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 02:26:51.548242 2026] [security2:error] [pid 2198:tid 2198] [client 34.146.157.21:31106] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.vampireproductions.com"] [uri "/@fs/.env"] [unique_id "ap-qq4AchKyhAbbFE1UjlwAAADQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
masterguru
2026-09-08 05:55:52
(11 hours ago)
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 34.146.157.21 (JP/Japan/21.157.146.34 ...
show more
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 34.146.157.21 (JP/Japan/21.157.146.34.bc.googleusercontent.com): 2 in the last 3600 secs (0-196)
show less
Hacking
🇺🇸
TPI-Abuse
2026-09-08 05:46:22
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.146.157.21 (21.157.146.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.146.157.21 (21.157.146.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 01:46:14.130479 2026] [security2:error] [pid 24979:tid 24979] [client 34.146.157.21:28714] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.folkdancers.org"] [uri "/@fs/root/.env"] [unique_id "ap-hJpID5Yag8dD568qIOQAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 05:24:50
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.146.157.21 (21.157.146.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.146.157.21 (21.157.146.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 01:24:46.138282 2026] [security2:error] [pid 1914:tid 1914] [client 34.146.157.21:56846] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.visitcampbellford.com"] [uri "/@fs/root/.env"] [unique_id "ap-cHjWEu4uBf8H1xn1_fwAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack