🇳🇱
Site.eu
2026-09-08 16:50:23
(12 minutes ago)
Excessive multi-domain requests
Brute-Force
🇺🇸
TPI-Abuse
2026-09-08 16:35:31
(27 minutes ago)
(mod_security) mod_security (id:210492) triggered by 34.178.203.98 (98.203.178.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.178.203.98 (98.203.178.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 12:35:25.952475 2026] [security2:error] [pid 29314:tid 29314] [client 34.178.203.98:30872] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.mywheatgrass.com"] [uri "/@fs/root/.env"] [unique_id "aqA5TY-eiJs6TzYZHwjf2QAAAII"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
raph
2026-09-08 16:23:23
(39 minutes ago)
[DOT FILES] crawler *.env*, .git*, .config*, etc.
Bad Web Bot
Web App Attack
🇬🇧
Celtic
2026-09-08 16:06:34
(56 minutes ago)
Blocked by Fail2Ban with Jail (plesk-modsecurity)
Brute-Force
SSH
🇺🇸
TPI-Abuse
2026-09-08 16:06:17
(56 minutes ago)
(mod_security) mod_security (id:210492) triggered by 34.178.203.98 (98.203.178.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.178.203.98 (98.203.178.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 12:06:10.459139 2026] [security2:error] [pid 3836385:tid 3836385] [client 34.178.203.98:60166] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.geo-modal.com"] [uri "/@fs/.env"] [unique_id "aqAyciHzJlNNn9sFNQVrzgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 15:47:15
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.178.203.98 (98.203.178.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.178.203.98 (98.203.178.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 11:47:07.912448 2026] [security2:error] [pid 18472:tid 18472] [client 34.178.203.98:23728] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.vid.com"] [uri "/@fs/.env"] [unique_id "aqAt-0n9RKru6xrgEzIh-QAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
WeCloudit-Anti-Abuse
2026-09-08 15:42:51
(1 hour ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
Anonymous
2026-09-08 15:02:32
(2 hours ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
🇳🇱
e.fierstra
2026-09-08 14:50:37
(2 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
🇳🇱
Site.eu
2026-09-08 14:38:11
(2 hours ago)
Excessive 404/403 errors
Brute-Force
🇺🇸
TPI-Abuse
2026-09-08 14:36:14
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.178.203.98 (98.203.178.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.178.203.98 (98.203.178.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 10:36:08.892799 2026] [security2:error] [pid 12319:tid 12319] [client 34.178.203.98:44466] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "castelan.anxo.org"] [uri "/@fs/.env"] [unique_id "aqAdWNO-pYeNvMbbvc5LgQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇮🇹
VHosting
2026-09-08 14:15:04
(2 hours ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
Anonymous
2026-09-08 13:47:47
(3 hours ago)
Multiple web server 400 error codes from same source ip
Web App Attack