🇺🇸
TPI-Abuse
2026-09-04 15:20:15
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.151.202.217 (217.202.151.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.151.202.217 (217.202.151.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 11:20:09.375801 2026] [security2:error] [pid 5710:tid 5710] [client 34.151.202.217:42794] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.natickvillagerentals.com"] [uri "/.env.backup"] [unique_id "aprhqWYg_E8QDRzY3x1wnAAAAB8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
lolyay
2026-09-04 13:33:56
(3 days ago)
34.151.202.217 - - [04/Sep/2026:13:33:55 +0000] "GET /_ignition/health-check HTTP/1.1" 404 0 "-" "cr ...
show more
34.151.202.217 - - [04/Sep/2026:13:33:55 +0000] "GET /_ignition/health-check HTTP/1.1" 404 0 "-" "crusader-worker/1.0"
34.151.202.217 - - [04/Sep/2026:13:33:55 +0000] "GET /.env.bak HTTP/1.1" 404 0 "-" "crusader-worker/1.0"
...
show less
Web App Attack
Bad Web Bot
🇧🇷
P1n4
2026-09-04 13:32:10
(3 days ago)
Heimdal IDS auto-block: sensitive_file (score=1.00)
Web App Attack
🇸🇪
vaia.cloud
2026-09-04 12:55:03
(4 days ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
🇩🇪
Hazzard
2026-09-04 12:53:50
(4 days ago)
(mod_security) mod_security triggered on hostname [redacted]): (CF_ENABLE)
SQL Injection
🇩🇪
XICTRON
2026-09-04 12:00:05
(4 days ago)
ModSecurity rule violation detected by Fail2Ban
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 11:43:59
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 34.151.202.217 (217.202.151.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.151.202.217 (217.202.151.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 07:43:52.174915 2026] [security2:error] [pid 32412:tid 32412] [client 34.151.202.217:48004] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.abramson-offner.com"] [uri "/.env.dev"] [unique_id "apqu-NNkgB1FjGtlMLoPAwAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 10:42:13
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 34.151.202.217 (217.202.151.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.151.202.217 (217.202.151.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 06:42:07.213382 2026] [security2:error] [pid 16996:tid 16996] [client 34.151.202.217:50600] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "letceteradesign.kathrynmcbride.com"] [uri "/wp-config.php~"] [unique_id "apqgf3A6Jf4BA2ROZs1uAQAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
consul.to
2026-09-04 10:15:55
(4 days ago)
Web attack/malicious scanning detected
Web App Attack
🇫🇷
masterguru
2026-09-04 10:13:29
(4 days ago)
Restricted File Access Attempt. Matched phrase ".env" at REQUEST_FILENAME. (930130-196)
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 10:08:41
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 34.151.202.217 (217.202.151.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.151.202.217 (217.202.151.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 06:08:35.626610 2026] [security2:error] [pid 24668:tid 24668] [client 34.151.202.217:58196] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jcpenterprise.com"] [uri "/.env.backup"] [unique_id "apqYo6g_7NYsNlZ0QGZmWwAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
Skyrider
2026-09-04 08:26:36
(4 days ago)
crowdsecurity/http-sensitive-files
Web App Attack
🇳🇱
WeCloudit-Anti-Abuse
2026-09-04 08:26:25
(4 days ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-04 08:21:29
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 34.151.202.217 (217.202.151.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.151.202.217 (217.202.151.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 04:21:24.330168 2026] [security2:error] [pid 22721:tid 22721] [client 34.151.202.217:57580] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.m2pg.net"] [uri "/.env"] [unique_id "app_hAx4-olMdPRqaV4SrAAAAFo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
masterguru
2026-09-04 07:47:05
(4 days ago)
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 34.151.202.217 (BR/Brazil/217.202.151 ...
show more
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 34.151.202.217 (BR/Brazil/217.202.151.34.bc.googleusercontent.com): 1 in the last 3600 secs (0-195)
show less
Hacking