🇺🇸
TPI-Abuse
2026-09-08 05:08:18
(4 minutes ago)
(mod_security) mod_security (id:210492) triggered by 34.158.67.86 (86.67.158.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.158.67.86 (86.67.158.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 01:08:09.064075 2026] [security2:error] [pid 18457:tid 18457] [client 34.158.67.86:60378] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.aquatech-ind.com"] [uri "/@fs/.env"] [unique_id "ap-YOesvOStp7TvcJ0f4dwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
ConsulHosting
2026-09-08 04:58:40
(14 minutes ago)
Automatically blocked due to distributed attack
Hacking
🇺🇸
TPI-Abuse
2026-09-08 04:30:51
(42 minutes ago)
(mod_security) mod_security (id:210492) triggered by 34.158.67.86 (86.67.158.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.158.67.86 (86.67.158.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 00:30:43.903407 2026] [security2:error] [pid 1544:tid 1544] [client 34.158.67.86:24890] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.dandksupply.com"] [uri "/@fs/.env.local"] [unique_id "ap-Pcy8WdlzWiI6kQg2ssQAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
masterguru
2026-09-08 04:02:08
(1 hour ago)
Restricted File Access Attempt. Matched phrase "/@fs/" at REQUEST_FILENAME. (930130-201)
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 03:19:06
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.158.67.86 (86.67.158.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.158.67.86 (86.67.158.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 23:19:01.876991 2026] [security2:error] [pid 4946:tid 4946] [client 34.158.67.86:3442] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.proplanarchitects.com"] [uri "/@fs/root/.env"] [unique_id "ap9-pbQWps3lbaxJEV2WNwAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
SiyCah
2026-09-08 03:00:02
(2 hours ago)
IP banned by fail2ban; banned in jail apache-modsecurity. Report generated by fail2abuseipdb.
Hacking
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 02:42:20
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.158.67.86 (86.67.158.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.158.67.86 (86.67.158.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 22:42:13.305526 2026] [security2:error] [pid 6258:tid 6258] [client 34.158.67.86:65502] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.judithcaldwell.com"] [uri "/@fs/root/.env"] [unique_id "ap92BTS_EOuJXcySoxAARgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 02:21:03
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.158.67.86 (86.67.158.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.158.67.86 (86.67.158.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 22:20:56.386641 2026] [security2:error] [pid 13149:tid 13149] [client 34.158.67.86:65030] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "dbq.us"] [uri "/@fs/.env"] [unique_id "ap9xCEwBv08nUdW4fBJ0hwAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
neckaralb-admin.de
2026-09-08 01:48:56
(3 hours ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 01:34:05
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.158.67.86 (86.67.158.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.158.67.86 (86.67.158.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 21:33:59.531612 2026] [security2:error] [pid 1966:tid 1966] [client 34.158.67.86:32978] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.batesstrategygroup.com"] [uri "/@fs/app/.env"] [unique_id "ap9mB7-RY9MUTvy14552RgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
consul.to
2026-09-08 01:21:41
(3 hours ago)
Web attack/malicious scanning detected
Web App Attack
🇩🇪
updown.io
2026-09-08 01:18:48
(3 hours ago)
{"level":"info","ts":1788830289.6504433,"logger":"http.log.access.log0","msg":"handled request","req ...
show more
{"level":"info","ts":1788830289.6504433,"logger":"http.log.access.log0","msg":"handled request","request":{"remote_ip":"34.158.67.86","remote_port":"52150","client_ip":"34.158.67.86","proto":"HTTP/1.1","method":"GET","host":"94a0.status.updown.io","uri":"/","headers":{"Accept":["*/*"],"Accept-Encoding":["gzip"],"User-Agent":["Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/148.0.0.0 Safari/537.36"]}},"bytes_read":0,"user_id":"","duration":0.000076878,"size":0,"status":308,"resp_headers":{"Location":["https://94a0.status.updown.io/"],"Content-Type":[],"Server":["Caddy"],"Connection":["close"]}}
{"level":"info","ts":1788830295.4499981,"logger":"http.log.access.log0","msg":"handled request","request":{"remote_ip":"34.158.67.86","remote_port":"17300","client_ip":"34.158.67.86","proto":"HTTP/1.1","method":"GET","host":"94a0.status.updown.io","uri":"/@fs/../../.env?raw??","headers":{"Accept-Encoding":["gzip"],"User-Agent":["Mozilla/5.0 (X11; Ubuntu; Li
...
show less
DDoS Attack
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 00:58:04
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.158.67.86 (86.67.158.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.158.67.86 (86.67.158.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 20:58:00.265914 2026] [security2:error] [pid 17719:tid 17719] [client 34.158.67.86:53426] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "howtogetcoolstuffforfree.banis-associates.com"] [uri "/@fs/root/.env"] [unique_id "ap9dmNsJWvDPNjbyMTyvWQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇧🇪
cmbplf
2026-09-08 00:55:48
(4 hours ago)
398 requests with url.path *.azure/*
Brute-Force
Bad Web Bot
Anonymous
2026-09-08 00:34:14
(4 hours ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking