🇺🇸
TPI-Abuse
2026-09-04 15:18:49
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.175.91.18 (18.91.175.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.175.91.18 (18.91.175.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 11:18:43.102512 2026] [security2:error] [pid 8048:tid 8048] [client 34.175.91.18:53730] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.shawnlayne.com"] [uri "/.env"] [unique_id "aprhU4YtOQAUngiRcZtLWQAAAJU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
Celtic
2026-09-04 15:02:26
(4 hours ago)
Blocked by Fail2Ban with Jail (plesk-modsecurity)
Brute-Force
SSH
🇩🇪
YF
2026-09-04 14:30:22
(5 hours ago)
WordPress config file probe
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 14:06:33
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.175.91.18 (18.91.175.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.175.91.18 (18.91.175.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 10:06:27.740736 2026] [security2:error] [pid 25472:tid 25472] [client 34.175.91.18:35428] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.paragontechusa.com"] [uri "/.env.dev"] [unique_id "aprQYy99KBamjk29m4ZVzgAAACI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
MatCat
2026-09-04 13:05:11
(6 hours ago)
Banned by fail2ban: apache-webprobe
Port Scan
Bad Web Bot
🇩🇪
ddobko
2026-09-04 12:03:44
(7 hours ago)
Bad Web Bot
Web App Attack
🇬🇧
cg-design.co.uk
2026-09-04 09:36:29
(10 hours ago)
(mod_security) mod_security triggered on hostname [redacted] 34.175.91.18 (ES/Spain/18.91.175.34.bc. ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.175.91.18 (ES/Spain/18.91.175.34.bc.googleusercontent.com)
show less
SQL Injection
🇺🇸
TPI-Abuse
2026-09-04 09:17:23
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.175.91.18 (18.91.175.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.175.91.18 (18.91.175.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 05:17:16.565449 2026] [security2:error] [pid 21582:tid 21582] [client 34.175.91.18:48074] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "juniperhills.net"] [uri "/.env.backup"] [unique_id "apqMnKy66Qd7S3FIjIZfqAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
big-cloud.nl
2026-09-04 09:11:03
(10 hours ago)
Try to access /.env
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 08:42:11
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.175.91.18 (18.91.175.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.175.91.18 (18.91.175.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 04:42:03.555086 2026] [security2:error] [pid 3945:tid 3945] [client 34.175.91.18:34662] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "robin5on.com"] [uri "/.env.example"] [unique_id "apqEW_V5lrnMDets7JG-IwAAAEc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
FeG Deutschland
2026-09-04 08:34:56
(11 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 08:23:55
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.175.91.18 (18.91.175.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.175.91.18 (18.91.175.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 04:23:48.487332 2026] [security2:error] [pid 31986:tid 31986] [client 34.175.91.18:47842] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.graduationnapkins.com"] [uri "/.env.prod"] [unique_id "apqAFG_uCbOK82mxNqy7UgAAAEI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
WeCloudit-Anti-Abuse
2026-09-04 08:04:02
(11 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
🇨🇦
Anytech
2026-09-04 08:03:52
(11 hours ago)
Blocked by Conn-Monitor: env-probing
Web App Attack
Hacking
🇫🇷
dynamix
2026-09-04 08:01:44
(11 hours ago)
Multiple WAF Violations
Web App Attack