🇺🇸
TPI-Abuse
2026-09-06 02:08:19
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.185.219.214 (214.219.185.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.185.219.214 (214.219.185.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 22:08:15.713260 2026] [security2:error] [pid 32352:tid 32352] [client 34.185.219.214:35248] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sekel.z-mgmt.com"] [uri "/.env.dev"] [unique_id "apzLD0KIlNkWoQnuvF2U9wAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
e.fierstra
2026-09-06 01:47:24
(1 hour ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 01:41:07
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.185.219.214 (214.219.185.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.185.219.214 (214.219.185.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 21:41:03.016119 2026] [security2:error] [pid 5333:tid 5333] [client 34.185.219.214:37586] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "zpepg.xyz.justmakingitbetter.com"] [uri "/.env.local"] [unique_id "apzEr0HuP07KbDN1zpVHBAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-06 01:39:13
(1 hour ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack
🇩🇪
kkw
2026-09-06 01:29:11
(1 hour ago)
[REDACTED] 34.185.219.214 - - [06/Sep/2026:03:29:11 +0200] "GET /.env.example HTTP/1.1" 404 4460 "-" ...
show more
[REDACTED] 34.185.219.214 - - [06/Sep/2026:03:29:11 +0200] "GET /.env.example HTTP/1.1" 404 4460 "-" "crusader-worker/1.0"
... (mode: searching http-sensitive-files)
show less
Bad Web Bot
Web App Attack
🇬🇧
pinguin
2026-09-06 01:20:48
(1 hour ago)
Triggered Cloudflare WAF (firewallManaged) from DE.
Action taken: LOG
Protocol: HTTP/1.1 (GET method ...
show more
Triggered Cloudflare WAF (firewallManaged) from DE.
Action taken: LOG
Protocol: HTTP/1.1 (GET method)
Endpoint: /wp-config.php~
UA: crusader-worker/1.0
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
Anonymous
2026-09-06 00:01:30
(3 hours ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
🇷🇴
iulianh
2026-09-05 23:59:50
(3 hours ago)
80,443
Brute-Force
SSH
🇩🇪
FeG Deutschland
2026-09-05 23:56:04
(3 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 23:51:15
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.185.219.214 (214.219.185.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.185.219.214 (214.219.185.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 19:51:12.106943 2026] [security2:error] [pid 17622:tid 17622] [client 34.185.219.214:42300] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "onlyphotomugs.iyp-home.com"] [uri "/.env.production"] [unique_id "apyq8I6N4rE1E2OrdpF9tAAAACM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 22:38:32
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.185.219.214 (214.219.185.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.185.219.214 (214.219.185.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 18:38:25.628989 2026] [security2:error] [pid 18940:tid 18940] [client 34.185.219.214:55460] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ftp.whore-cams.com"] [uri "/.env.backup"] [unique_id "apyZ4SQPrjXcJMQG8kiK2gAAAFo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
consul.to
2026-09-05 22:20:24
(4 hours ago)
Web attack/malicious scanning detected
Web App Attack
Anonymous
2026-09-05 22:12:14
(4 hours ago)
Web application attack detected.
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 22:10:44
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.185.219.214 (214.219.185.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.185.219.214 (214.219.185.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 18:10:40.086494 2026] [security2:error] [pid 22178:tid 22263] [client 34.185.219.214:49310] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.104ventures.com"] [uri "/.env.prod"] [unique_id "apyTYAhRfwNe3j-HxSx5JAAAARY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇮🇹
VHosting
2026-09-05 20:50:09
(6 hours ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack