Anonymous
2026-09-06 04:36:37
(1 hour ago)
Aggressive web scan
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 03:53:06
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.152.30.80 (80.30.152.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.152.30.80 (80.30.152.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 23:52:59.587737 2026] [security2:error] [pid 3505653:tid 3505684] [client 34.152.30.80:34802] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.stephanie.stauffer.name"] [uri "/.env"] [unique_id "apzjm5t-xs6dfcnCXm6EWgAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
rakkor
2026-09-06 03:34:07
(2 hours ago)
2026-09-06T04:34:06+01:00 NAS [Sun Sep 06 04:34:06.418403 2026] [proxy_fcgi:error] [pid 22310:tid 22 ...
show more
2026-09-06T04:34:06+01:00 NAS [Sun Sep 06 04:34:06.418403 2026] [proxy_fcgi:error] [pid 22310:tid 22337] [client 34.152.30.80:58998] AH01071: Got error 'Primary script unknown'
...
show less
Brute-Force
Hacking
🇺🇸
TPI-Abuse
2026-09-06 03:31:58
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.152.30.80 (80.30.152.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.152.30.80 (80.30.152.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 23:31:51.796405 2026] [security2:error] [pid 16295:tid 16295] [client 34.152.30.80:38906] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "carltonelyse.com"] [uri "/wp-config.php~"] [unique_id "apzep5E4omoNFM_qXF6ZrAAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
Hazzard
2026-09-06 03:05:54
(3 hours ago)
(mod_security) mod_security triggered on hostname [redacted]): (CF_ENABLE)
SQL Injection
🇺🇸
TPI-Abuse
2026-09-06 03:04:50
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.152.30.80 (80.30.152.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.152.30.80 (80.30.152.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 23:04:43.113865 2026] [security2:error] [pid 7368:tid 7368] [client 34.152.30.80:40062] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.skp.hk"] [uri "/.env"] [unique_id "apzYS6gxu1j1Q_UayolLRQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇲🇾
Rizzy
2026-09-06 02:38:33
(3 hours ago)
Multiple WAF Violations
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 02:02:50
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.152.30.80 (80.30.152.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.152.30.80 (80.30.152.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 22:02:46.821665 2026] [security2:error] [pid 4210:tid 4210] [client 34.152.30.80:33000] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mainefirst.arsenaultartistmanagement.com"] [uri "/.env"] [unique_id "apzJxqChYRO_iFHs-vmtqwAAADc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇰
SaltySoftworks
2026-09-06 01:49:03
(4 hours ago)
User agent spoofing
Spoofing
🇺🇸
TPI-Abuse
2026-09-06 01:31:47
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.152.30.80 (80.30.152.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.152.30.80 (80.30.152.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 21:31:43.263788 2026] [security2:error] [pid 23148:tid 23148] [client 34.152.30.80:39616] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "miss-ma.com"] [uri "/.env.dev"] [unique_id "apzCf6n7ZFiFcZuBz16B7wAAAFk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇷🇺
DZBOT
2026-09-06 01:05:59
(5 hours ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 00:57:12
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.152.30.80 (80.30.152.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.152.30.80 (80.30.152.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 20:57:05.088760 2026] [security2:error] [pid 29031:tid 29046] [client 34.152.30.80:42472] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "tierrasolymar.com"] [uri "/.env.local"] [unique_id "apy6YYN7N4-iBKWROW9sowAAAEo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 00:39:26
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.152.30.80 (80.30.152.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.152.30.80 (80.30.152.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 20:39:19.925318 2026] [security2:error] [pid 30126:tid 30126] [client 34.152.30.80:52260] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "hotelkona.com"] [uri "/wp-config.php.swp"] [unique_id "apy2N_OmNNucng4VbL8Y2QAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
✨
2026-09-06 00:08:15
(6 hours ago)
Domain : pathuku.com
Rule : env
2026-09-06 00:06:16 217.194.212.136 GET /.env - 443 - 34.152.30.80 H ...
show more
Domain : pathuku.com
Rule : env
2026-09-06 00:06:16 217.194.212.136 GET /.env - 443 - 34.152.30.80 HTTP/1.1 crusader-worker/1.0 - pathuku.com 301 0 0 433 87 110 - -
show less
Hacking
SQL Injection
🇺🇸
TPI-Abuse
2026-09-06 00:02:07
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.152.30.80 (80.30.152.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.152.30.80 (80.30.152.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 20:02:03.953903 2026] [security2:error] [pid 31363:tid 31363] [client 34.152.30.80:59532] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jmnr.net"] [uri "/.env.bak"] [unique_id "apyte6hC04hFq1aG15V44AAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack