🇺🇸
TPI-Abuse
2026-09-09 11:49:45
(45 minutes ago)
(mod_security) mod_security (id:210492) triggered by 34.146.46.188 (188.46.146.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.146.46.188 (188.46.146.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 07:49:37.312572 2026] [security2:error] [pid 2596:tid 2596] [client 34.146.46.188:64418] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.maritanasystems.com"] [uri "/@fs/.env"] [unique_id "aqFH0faduv6Yn4rNjD-clgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
LRob
2026-09-09 11:01:53
(1 hour ago)
Declared crawler ignoring robots.txt and the refusals it is given | ua: Mozilla/5.0 AppleWebKit/537. ...
show more
Declared crawler ignoring robots.txt and the refusals it is given | ua: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; Amzn-SearchBot/1.0; +https://developer.amazon.com/support/amazon | path: /@fs/.env (+9 more) | 2026-09-09 11:01 UTC
show less
Bad Web Bot
🇩🇪
yvoictra
2026-09-09 10:39:28
(1 hour ago)
Bloqueado automáticamente por CrowdSec. Escenario: crowdsecurity/http-path-traversal-probing
Web App Attack
🇬🇧
consul.to
2026-09-09 10:39:21
(1 hour ago)
Web attack/malicious scanning detected
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 09:52:10
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.146.46.188 (188.46.146.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.146.46.188 (188.46.146.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 05:52:06.391380 2026] [security2:error] [pid 16653:tid 16729] [client 34.146.46.188:28184] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.ecocentri.city"] [uri "/@fs/app/.env"] [unique_id "aqEsRm206c_MfMEAHdLhCQAAANI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 09:35:49
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.146.46.188 (188.46.146.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.146.46.188 (188.46.146.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 05:35:42.911754 2026] [security2:error] [pid 14647:tid 14647] [client 34.146.46.188:31506] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mintgames.com.danged.com"] [uri "/@fs/src/.env"] [unique_id "aqEobjlpdXJldVUELBl-pAAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-09 09:00:07
(3 hours ago)
| Suspicious URL access.
Web App Attack
Hacking
SQL Injection
🇺🇸
TPI-Abuse
2026-09-09 08:41:18
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.146.46.188 (188.46.146.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.146.46.188 (188.46.146.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 04:41:13.490902 2026] [security2:error] [pid 1603:tid 1603] [client 34.146.46.188:5284] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.newcangroup.com"] [uri "/@fs/.env"] [unique_id "aqEbqfwApeFrWbpENL2sTgAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-09 07:56:30
(4 hours ago)
Multiple web server 400 error codes from same source ip
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 07:43:33
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.146.46.188 (188.46.146.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.146.46.188 (188.46.146.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 03:43:28.023755 2026] [security2:error] [pid 20320:tid 20320] [client 34.146.46.188:29582] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.beepainless.com"] [uri "/@fs/.env"] [unique_id "aqEOIF2y-s9mO2q8wFaMDwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
dynamix
2026-09-09 07:29:27
(5 hours ago)
Multiple WAF Violations
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 06:35:42
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.146.46.188 (188.46.146.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.146.46.188 (188.46.146.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 02:35:34.716015 2026] [security2:error] [pid 25792:tid 25792] [client 34.146.46.188:31062] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.cmabiblequizzing.org"] [uri "/@fs/..%252f..%252f..%252f..%252f..%252froot/.env"] [unique_id "aqD-NniOeNfQ3dRf639mqgAAAC4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇿
Antinson
2026-09-09 05:52:43
(6 hours ago)
Scraping with a high error ratio and request rate
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-09 05:27:21
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.146.46.188 (188.46.146.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.146.46.188 (188.46.146.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 01:27:14.135446 2026] [security2:error] [pid 6747:tid 6747] [client 34.146.46.188:10828] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.hawleyrentals.com"] [uri "/@fs/app/.env"] [unique_id "aqDuMl1IWjeBZXGeY8n1vQAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-09 05:03:05
(7 hours ago)
34.146.46.188 - - [09/Sep/2026:00:02:58 -0500] "GET /.env.local HTTP/1.1" 403 12 "-" "Mozilla/5.0 (X ...
show more
34.146.46.188 - - [09/Sep/2026:00:02:58 -0500] "GET /.env.local HTTP/1.1" 403 12 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-SearchBot/1.0; +https://www.anthropic.com/claude-searchbot) Chrome/128.0.7091.66 Safari/537.36" 162.159.110.22
34.146.46.188 - - [09/Sep/2026:00:02:58 -0500] "GET /.env HTTP/1.1" 403 199 "-" "Mozilla/5.0 (Windows NT 11.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko; compatible; GPTBot/1.4; +https://openai.com/gptbot) Chrome/118.0.112.39 Safari/537.36 Edg/118.0.112.39" 162.159.110.22
34.146.46.188 - - [09/Sep/2026:00:03:03 -0500] "GET /.env.production HTTP/1.1" 403 12 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.8125.109 Safari/537.36 Edg/124.0.8125.109; compatible; Perplexity-User/1.0; +https://perplexity.ai/perplexity-user" 172.64.213.72
34.146.46.188 - - [09/Sep/2026:00:03:03 -0500] "GET /.env.staging HTTP/1.1" 403 12 "-" "Mozilla/5.0 (compatible
...
show less
Brute-Force
Bad Web Bot
Web App Attack