🇺🇸
TPI-Abuse
2026-09-08 07:33:30
(8 minutes ago)
(mod_security) mod_security (id:210492) triggered by 34.146.51.207 (207.51.146.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.146.51.207 (207.51.146.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 03:33:24.748723 2026] [security2:error] [pid 9927:tid 9927] [client 34.146.51.207:34222] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.alanbeckwith.com"] [uri "/@fs/root/.env"] [unique_id "ap-6RJCkGe6VdTHlfkzWVgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 07:05:09
(36 minutes ago)
(mod_security) mod_security (id:210492) triggered by 34.146.51.207 (207.51.146.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.146.51.207 (207.51.146.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 03:05:03.952216 2026] [security2:error] [pid 24429:tid 24429] [client 34.146.51.207:28692] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.wa211.org"] [uri "/@fs/.env"] [unique_id "ap-zn3EZ0dIR3LQLlqaC4QAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
LRob
2026-09-08 07:02:05
(39 minutes ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /@fs/proc/self/environ (+11 more) | 2026-09-08 07:02 UTC
show less
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 05:11:49
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.146.51.207 (207.51.146.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.146.51.207 (207.51.146.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 01:11:43.501022 2026] [security2:error] [pid 4154:tid 4186] [client 34.146.51.207:22386] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.pueblodermatology.com.aafm.us"] [uri "/@fs/root/.env"] [unique_id "ap-ZD0-YlZNbSYcVbqbMtgAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 04:45:57
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.146.51.207 (207.51.146.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.146.51.207 (207.51.146.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 00:45:51.219529 2026] [security2:error] [pid 588316:tid 588342] [client 34.146.51.207:11172] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.myrasnyder.com"] [uri "/@fs/.env"] [unique_id "ap-S_7K6im_k6s5C8zFFlQAAAUs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
BlueWire Hosting
2026-09-08 03:49:28
(3 hours ago)
High-confidence malicious configuration/VCS probe
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 03:21:08
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.146.51.207 (207.51.146.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.146.51.207 (207.51.146.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 23:21:02.931887 2026] [security2:error] [pid 3859:tid 3859] [client 34.146.51.207:40540] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.cityslickerstomp.info"] [uri "/@fs/.env"] [unique_id "ap9_HriBpNyiUobdepMsGwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-08 03:19:01
(4 hours ago)
XSS Attempt
Hacking
🇫🇷
Jimbo67
2026-09-08 03:10:48
(4 hours ago)
Cloudflare WAF: 23 hits in 30s | action=block | abuse=suspicious_probe | categories=19,21 | rule_id= ...
show more
Cloudflare WAF: 23 hits in 30s | action=block | abuse=suspicious_probe | categories=19,21 | rule_id=3329c9d804134f3e89780d69bfd872dc | URIs=/,/@fs/..%252f..%252f..%252f..%252f..%252fapp/.env??raw??,/@fs/..%252f..%252f..%252f..%252f..%252fproc/self/environ??raw??,/@fs/.env.local??raw??,/@fs/.env??ra…
show less
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 03:05:42
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.146.51.207 (207.51.146.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.146.51.207 (207.51.146.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 23:05:38.968016 2026] [security2:error] [pid 1016:tid 1016] [client 34.146.51.207:5120] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "centuryabsinthe.com"] [uri "/@fs/.env.local"] [unique_id "ap97guLPcgXsOX6RupZUTgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
palzer.IT
2026-09-08 02:50:56
(4 hours ago)
Fail2ban automatic report for plesk-apache-badbot: 34.146.51.207 - - [08/Sep/2026:04:50:40 +0200] GE ...
show more
Fail2ban automatic report for plesk-apache-badbot: 34.146.51.207 - - [08/Sep/2026:04:50:40 +0200] GET /@fs/.env?raw?? [DOMAIN_REMOVED] 404 56506 [DOMAIN_REMOVED] Mozilla/5.0 (Linux; Android 15; SM-S918B) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.7614.148 Mobile Safari/537.36; compatible; GPTBot/1.2; +[DOMAIN_REMOVED]
show less
Bad Web Bot
🇧🇪
cmbplf
2026-09-08 02:47:38
(4 hours ago)
601 requests with url.path *.config/*
Brute-Force
Bad Web Bot
Anonymous
2026-09-08 02:46:12
(4 hours ago)
Bot / seems abusive / Apache connections: 54
DDoS Attack
Web Spam
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 02:31:05
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.146.51.207 (207.51.146.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.146.51.207 (207.51.146.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 22:31:00.901784 2026] [security2:error] [pid 23034:tid 23034] [client 34.146.51.207:36096] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.grmvrr.com"] [uri "/@fs/app/.env"] [unique_id "ap9zZJVDrhLpTgfWchOGwAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 01:32:32
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.146.51.207 (207.51.146.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.146.51.207 (207.51.146.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 21:32:28.309721 2026] [security2:error] [pid 29307:tid 29307] [client 34.146.51.207:50872] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.austinbiblestudents.org"] [uri "/@fs/root/.env"] [unique_id "ap9lrMp7lTRq41kY3Yia1QAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack