🇺🇸
TPI-Abuse
2026-09-06 03:50:26
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.153.158.18 (18.158.153.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.153.158.18 (18.158.153.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 23:50:19.591085 2026] [security2:error] [pid 22312:tid 22312] [client 34.153.158.18:44440] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.aridscapes.com"] [uri "/.env.local"] [unique_id "apzi-0EBfF9jzN3JmTDD1gAAAFI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 03:00:50
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.153.158.18 (18.158.153.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.153.158.18 (18.158.153.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 23:00:46.203230 2026] [security2:error] [pid 15595:tid 15595] [client 34.153.158.18:47838] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.easylandcash.com"] [uri "/.env.production"] [unique_id "apzXXiBjcVQ2F_hL1aimkgAAAGg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇮🇹
itsvic.dev
2026-09-06 02:59:55
(10 hours ago)
34.153.158.18 - - [06/Sep/2026:02:59:54 +0000] "webmail.itsvic.dev" "GET /.env.bak HTTP/1.1" 404 146 ...
show more
34.153.158.18 - - [06/Sep/2026:02:59:54 +0000] "webmail.itsvic.dev" "GET /.env.bak HTTP/1.1" 404 146 "-" "crusader-worker/1.0"
34.153.158.18 - - [06/Sep/2026:02:59:54 +0000] "webmail.itsvic.dev" "GET /.env HTTP/1.1" 404 146 "-" "crusader-worker/1.0"
34.153.158.18 - - [06/Sep/2026:02:59:54 +0000] "webmail.itsvic.dev" "GET /.env.local HTTP/1.1" 404 146 "-" "crusader-worker/1.0"
...
show less
Brute-Force
Web App Attack
🇩🇪
Hazzard
2026-09-06 02:25:38
(11 hours ago)
(mod_security) mod_security triggered on hostname [redacted]): (CF_ENABLE)
SQL Injection
🇺🇸
TPI-Abuse
2026-09-06 02:22:42
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.153.158.18 (18.158.153.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.153.158.18 (18.158.153.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 22:22:38.934043 2026] [security2:error] [pid 20441:tid 20441] [client 34.153.158.18:33726] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "comune.adamsclothiers.com"] [uri "/.env"] [unique_id "apzObkL8M9hY-pBXmEKiEgAAAB8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-06 02:12:02
(11 hours ago)
WEB attack
Brute-Force
🇺🇸
TPI-Abuse
2026-09-06 02:01:11
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.153.158.18 (18.158.153.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.153.158.18 (18.158.153.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 22:01:06.959329 2026] [security2:error] [pid 3505780:tid 3505920] [client 34.153.158.18:40196] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "malvadocuaderno.emehache.net"] [uri "/.env.production"] [unique_id "apzJYqeVUu6W99IeSwEcIgAAAhE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
LRob
2026-09-06 01:35:52
(11 hours ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /.env.old (+10 more) | 2026-09-06 01:35 UTC
show less
Hacking
Web App Attack
🇩🇪
ISPLtd
2026-09-06 01:12:26
(12 hours ago)
Sep 5 22:12:25 34.153.158.18 TCP SPT=40384 DPT=80 SYN
Sep 5 22:12:25 34.153.158.18 TCP SPT=40422 D ...
show more
Sep 5 22:12:25 34.153.158.18 TCP SPT=40384 DPT=80 SYN
Sep 5 22:12:25 34.153.158.18 TCP SPT=40422 DPT=80 SYN
Sep 5 22:12:25 34.153.158.18 TCP SPT=40418 DPT=80 SYN
...
show less
DDoS Attack
🇺🇸
TPI-Abuse
2026-09-06 01:11:50
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.153.158.18 (18.158.153.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.153.158.18 (18.158.153.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 21:11:44.100255 2026] [security2:error] [pid 16348:tid 16361] [client 34.153.158.18:56874] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "lordennerdale.aafm.us"] [uri "/.env.save"] [unique_id "apy90DIu3NXoDoPvqInwPQAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 00:40:30
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.153.158.18 (18.158.153.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.153.158.18 (18.158.153.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 20:40:22.683611 2026] [security2:error] [pid 10578:tid 10578] [client 34.153.158.18:39378] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "highstakeslearning.com"] [uri "/.env.old"] [unique_id "apy2du-_2xxHYnv_-6SujwAAAFA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇲🇾
Rizzy
2026-09-06 00:18:45
(13 hours ago)
Multiple WAF Violations
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 00:09:04
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.153.158.18 (18.158.153.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.153.158.18 (18.158.153.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 20:08:56.382233 2026] [security2:error] [pid 3480662:tid 3480662] [client 34.153.158.18:35400] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "notrucking.nodepot.com"] [uri "/wp-config.php.swp"] [unique_id "apyvGBZKCge6RftZZmOS4QAAAGI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
e.fierstra
2026-09-05 23:44:56
(13 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 23:37:03
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.153.158.18 (18.158.153.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.153.158.18 (18.158.153.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 19:36:56.152277 2026] [security2:error] [pid 1512:tid 1512] [client 34.153.158.18:43890] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "qwik-wash.com"] [uri "/.env.backup"] [unique_id "apynmPdCtpToMaSzbZuPhgAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack