🇺🇸
TPI-Abuse
2026-09-07 10:37:02
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.170.216.59 (59.216.170.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.170.216.59 (59.216.170.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 06:36:56.623448 2026] [security2:error] [pid 2219:tid 2219] [client 34.170.216.59:30738] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.69strains.com"] [uri "/@fs/../../.env"] [unique_id "ap6TyM1Ou4lA-pk4KS0n-wAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
Site.eu
2026-09-07 10:21:08
(3 hours ago)
Excessive multi-domain requests
Brute-Force
🇺🇸
TPI-Abuse
2026-09-07 10:17:35
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.170.216.59 (59.216.170.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.170.216.59 (59.216.170.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 06:17:28.534430 2026] [security2:error] [pid 1628411:tid 1628411] [client 34.170.216.59:39778] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.bentechconstruction.com"] [uri "/@fs/.env"] [unique_id "ap6POGIBBEX5AkxOdVsQdQAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇦🇺
rubixstudios
2026-09-07 09:54:02
(4 hours ago)
Excessive HTTP requests consistent with automated attack behaviour detected by Imunify360
DDoS Attack
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 09:28:40
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.170.216.59 (59.216.170.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.170.216.59 (59.216.170.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 05:28:33.547255 2026] [security2:error] [pid 6093:tid 6093] [client 34.170.216.59:56896] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.stardancertantra.com"] [uri "/@fs/..%252f..%252f..%252f..%252f..%252froot/.env"] [unique_id "ap6DwQ8TCISXdqgolNh84gAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇸🇪
vaia.cloud
2026-09-07 09:20:03
(4 hours ago)
crowdsecurity/http-probing
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 09:04:42
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.170.216.59 (59.216.170.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.170.216.59 (59.216.170.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 05:04:35.986391 2026] [security2:error] [pid 27489:tid 27489] [client 34.170.216.59:52870] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.grayhost.net"] [uri "/@fs/.env"] [unique_id "ap5-I63sbgE6ZoXtejtCOwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
Mangelot Hosting
2026-09-07 08:24:08
(5 hours ago)
(modsecurity) srv103 ModSecurity 34.170.216.59 (US/United States/59.216.170.34.bc.googleusercontent. ...
show more
(modsecurity) srv103 ModSecurity 34.170.216.59 (US/United States/59.216.170.34.bc.googleusercontent.com): 30 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs:
show less
Web App Attack
🇩🇪
BlueWire Hosting
2026-09-07 08:18:34
(5 hours ago)
High-confidence malicious configuration/VCS probe
Web App Attack
🇬🇧
Aetherweb Ark
2026-09-07 08:04:24
(6 hours ago)
(mod_security) mod_security (id:949110) triggered by 34.170.216.59 (US/United States/59.216.170.34.b ...
show more
(mod_security) mod_security (id:949110) triggered by 34.170.216.59 (US/United States/59.216.170.34.bc.googleusercontent.com): N in the last X secs
show less
Web App Attack
🇩🇪
Hary74656
2026-09-07 08:00:58
(6 hours ago)
Fail2Ban on schani.hostmi.at: jail=apache-modsecurity, failures=3. No raw log data included.
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 07:56:20
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.170.216.59 (59.216.170.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.170.216.59 (59.216.170.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 03:56:16.113560 2026] [security2:error] [pid 23313:tid 23313] [client 34.170.216.59:51708] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.muskogeecleaning.com"] [uri "/@fs/src/.env"] [unique_id "ap5uIFv1zdMpPB25NDLZCAAAAIQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 07:21:21
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.170.216.59 (59.216.170.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.170.216.59 (59.216.170.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 03:21:17.980043 2026] [security2:error] [pid 1924:tid 1924] [client 34.170.216.59:32340] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bilimkurgumanyagi.com"] [uri "/@fs/app/.env"] [unique_id "ap5l7WL3jwpfGGUjRYTs8QAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 06:58:08
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.170.216.59 (59.216.170.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.170.216.59 (59.216.170.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 02:58:02.138800 2026] [security2:error] [pid 23923:tid 23923] [client 34.170.216.59:27154] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.walkingwithghosts.com"] [uri "/@fs/.env"] [unique_id "ap5gegVI4KCiy1L0Si2KcAAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
Octopuce
2026-09-07 06:35:03
(7 hours ago)
Aggressive web search of vulnerable pages: /v1/.env /.docker/.env /.env.local /uploads../.env /.env ...
show more
Aggressive web search of vulnerable pages: /v1/.env /.docker/.env /.env.local /uploads../.env /.env ...
show less
Web App Attack