🇺🇸
TPI-Abuse
2026-09-06 03:51:42
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.185.67.235 (235.67.185.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.185.67.235 (235.67.185.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 23:51:37.619503 2026] [security2:error] [pid 2952:tid 2952] [client 34.185.67.235:53266] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.turtletaekwondo.com"] [uri "/.env.production"] [unique_id "apzjSV-UcQwSkmGGHVPQAAAAAJQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇮🇹
VHosting
2026-09-06 03:05:02
(2 hours ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 03:00:45
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.185.67.235 (235.67.185.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.185.67.235 (235.67.185.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 23:00:38.759890 2026] [security2:error] [pid 3933:tid 3933] [client 34.185.67.235:48268] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "web221.dnchosting.com"] [uri "/.env.save"] [unique_id "apzXVmhId_MRsWJCX58LhQAAACs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 02:44:41
(2 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.185.67.235 (235.67.185.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.185.67.235 (235.67.185.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 22:44:33.611511 2026] [security2:error] [pid 8012:tid 8012] [client 34.185.67.235:40334] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||affairsafloat.com.salsberggroup.com|F|2"] [data ".log"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "affairsafloat.com.salsberggroup.com"] [uri "/storage/logs/laravel.log"] [unique_id "apzTkVg9GK-CCju2itex-gAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
ddobko
2026-09-06 02:29:50
(2 hours ago)
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 02:21:28
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.185.67.235 (235.67.185.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.185.67.235 (235.67.185.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 22:21:22.254618 2026] [security2:error] [pid 16348:tid 16350] [client 34.185.67.235:37074] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "coloradospringsmardigras.aafm.us"] [uri "/.env"] [unique_id "apzOIjIu3NXoDoPvqIkHTAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
mnsf
2026-09-06 02:05:25
(3 hours ago)
Scanning/Probing (20)
Brute-Force
Web App Attack
Anonymous
2026-09-06 01:49:33
(3 hours ago)
Bloqueado automaticamente por CrowdSec escenario crowdsecurity/http-probing
Brute-Force
🇮🇹
clamehost.it
2026-09-06 01:46:16
(3 hours ago)
Automatic report - Brute Force attack using this IP address
Brute-Force
🇩🇪
XICTRON
2026-09-05 23:00:11
(6 hours ago)
ModSecurity rule violation detected by Fail2Ban
Web App Attack
🇳🇱
e.fierstra
2026-09-05 22:58:29
(6 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 22:50:53
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.185.67.235 (235.67.185.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.185.67.235 (235.67.185.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 18:50:47.406462 2026] [security2:error] [pid 5219:tid 5219] [client 34.185.67.235:42254] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "dildog.ingberinteriors.com"] [uri "/.env.local"] [unique_id "apycxx4QbjRiNbLQbCKpUwAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
dynamix
2026-09-05 22:32:23
(6 hours ago)
Multiple WAF Violations
Web App Attack
🇳🇱
WeCloudit-Anti-Abuse
2026-09-05 21:17:29
(8 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-05 21:08:47
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.185.67.235 (235.67.185.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.185.67.235 (235.67.185.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 17:08:42.037259 2026] [security2:error] [pid 17578:tid 17578] [client 34.185.67.235:51238] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "charamand.com"] [uri "/.env.dev"] [unique_id "apyE2uBu8GJz0bRRL3qDaQAAAD8"]
show less
Brute-Force
Bad Web Bot
Web App Attack