🇺🇸
TPI-Abuse
2026-09-08 09:53:32
(55 minutes ago)
(mod_security) mod_security (id:210492) triggered by 34.151.207.196 (196.207.151.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.151.207.196 (196.207.151.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 05:53:27.883626 2026] [security2:error] [pid 26676:tid 26676] [client 34.151.207.196:45122] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.tiln.org"] [uri "/.env.prod"] [unique_id "ap_bF3LDplZPDF_VlLnhvgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 07:39:58
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.151.207.196 (196.207.151.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.151.207.196 (196.207.151.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 03:39:50.517211 2026] [security2:error] [pid 31053:tid 31053] [client 34.151.207.196:45894] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.costumeshalloweenparty.com"] [uri "/.env.local"] [unique_id "ap-7xlx5aX5NMbF6XhucKwAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 06:42:54
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.151.207.196 (196.207.151.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.151.207.196 (196.207.151.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 02:42:45.674491 2026] [security2:error] [pid 29105:tid 29105] [client 34.151.207.196:57332] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.aldrich.us"] [uri "/.env.production"] [unique_id "ap-uZexG0M7eoqpJEU1UZQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 04:24:18
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.151.207.196 (196.207.151.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.151.207.196 (196.207.151.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 00:24:11.406915 2026] [security2:error] [pid 10925:tid 10925] [client 34.151.207.196:52850] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.evelynkay.com"] [uri "/wp-config.php.bak"] [unique_id "ap-N6-ExcbuyW9o5_cQIoQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇱🇻
garmtech.com
2026-09-08 03:06:15
(7 hours ago)
Attempted access to sensitive endpoint (/.env) detected. Automated scan or unauthorized probing.
Web App Attack
🇩🇪
MBombeck
2026-09-07 13:37:40
(21 hours ago)
Fail2Ban: traefik-botsearch on edge-01.ioioio.dev
Port Scan
Web App Attack
🇪🇸
Yoeph
2026-09-07 12:23:43
(22 hours ago)
Attacking server service nginx-movimientos-forbidden (Permanently Banned by Fail2ban on TurnoControl ...
show more
Attacking server service nginx-movimientos-forbidden (Permanently Banned by Fail2ban on TurnoControlPro VPS)
show less
Hacking
Brute-Force
Bad Web Bot
Web App Attack
🇱🇹
sobakintech
2026-09-07 05:58:43
(1 day ago)
Detected by CrowdSec on Traefik reverse proxy: crowdsecurity/http-probing
Port Scan
Web App Attack
Anonymous
2026-09-06 06:29:13
(2 days ago)
IP banned by Fail2Ban due to multiple malicious requests on Nginx
Brute-Force
SSH
Web App Attack
🇧🇪
sid3windr
2026-09-06 06:25:34
(2 days ago)
GET /.env (Tarpitted for 2m10s, wasted 7.73kB)
Web App Attack
🇧🇷
borbolla
2026-09-06 06:21:03
(2 days ago)
Automated web credential/secret scanner blocked by Fail2Ban. Probed: "GET /.env HTTP/1.1" "GET /.env ...
show more
Automated web credential/secret scanner blocked by Fail2Ban. Probed: "GET /.env HTTP/1.1" "GET /.env.backup HTTP/1.1" "GET /.env.bak HTTP/1.1"
show less
Web App Attack
Bad Web Bot
🇺🇸
thieuleu
2026-09-06 06:18:50
(2 days ago)
Unauthorized connection attempt blocked by firewall policy. Web application hardening active.
Brute-Force
Exploited Host
🇻🇳
trung.fun
2026-09-06 06:06:52
(2 days ago)
DDoS, Hack, Brute Force, Web Attack
...
DDoS Attack
Web Spam
Hacking
Brute-Force
Web App Attack
🇬🇧
openstrike.co.uk
2026-09-06 05:13:16
(2 days ago)
13 attacks on PHP URLs, env grabbing URLs:
GET /wp-config.php.bak HTTP/1.1
GET /.env.prod HTTP/1.1
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-06 02:34:30
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.151.207.196 (196.207.151.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.151.207.196 (196.207.151.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 22:34:23.049421 2026] [security2:error] [pid 257599:tid 257621] [client 34.151.207.196:38686] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "fishrapper.com"] [uri "/wp-config.php.bak"] [unique_id "apzRLx6CKJg02Y_H8XxQzQAAAQg"]
show less
Brute-Force
Bad Web Bot
Web App Attack