🇳🇴
jad-abuse
2026-09-06 06:33:30
(10 hours ago)
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: env_probe ...
show more
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: env_probe, scanner_ua, source_backup, actuator, config_backup, ignition_debug. Observed by 1 sensor(s); 52 hits.
show less
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 03:52:57
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.20.176.131 (131.176.20.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.20.176.131 (131.176.20.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 23:52:53.533277 2026] [security2:error] [pid 2549:tid 2549] [client 34.20.176.131:52208] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.evelynkay.com"] [uri "/.env.old"] [unique_id "apzjlfDdGcg5IzLP9tvSrAAAAHU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
masterguru
2026-09-06 03:34:31
(13 hours ago)
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 34.20.176.131 (US/United States/131.1 ...
show more
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 34.20.176.131 (US/United States/131.176.20.34.bc.googleusercontent.com): 2 in the last 3600 secs (0-196)
show less
Hacking
🇺🇸
TPI-Abuse
2026-09-06 02:58:45
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.20.176.131 (131.176.20.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.20.176.131 (131.176.20.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 22:58:38.454019 2026] [security2:error] [pid 5730:tid 5730] [client 34.20.176.131:48290] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.ixd.net"] [uri "/.env"] [unique_id "apzW3oK7S2Gk2SCf3N9V7AAAAI0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 02:00:38
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.20.176.131 (131.176.20.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.20.176.131 (131.176.20.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 22:00:34.945511 2026] [security2:error] [pid 20032:tid 20032] [client 34.20.176.131:49678] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "michaelwakim.com"] [uri "/.env.dev"] [unique_id "apzJQmyRqnc40QXv4WwzJwAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
e.fierstra
2026-09-06 00:50:35
(16 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
Anonymous
2026-09-06 00:50:02
(16 hours ago)
suspicious request in access.log
Web App Attack
🇳🇱
WeCloudit-Anti-Abuse
2026-09-06 00:32:06
(16 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-06 00:30:05
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.20.176.131 (131.176.20.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.20.176.131 (131.176.20.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 20:29:56.544274 2026] [security2:error] [pid 10535:tid 10535] [client 34.20.176.131:47740] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mx10.adamsclothiers.com"] [uri "/.env.prod"] [unique_id "apy0BM0kiIhxJnR6hWR2NAAAACE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 23:54:24
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.20.176.131 (131.176.20.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.20.176.131 (131.176.20.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 19:54:19.544850 2026] [security2:error] [pid 17143:tid 17143] [client 34.20.176.131:34308] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.leevardaman.com"] [uri "/wp-config.php.bak"] [unique_id "apyrq-wJ4SbbBql4yf9jhQAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-05 23:52:38
(17 hours ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack
🇬🇧
Aetherweb Ark
2026-09-05 22:57:50
(18 hours ago)
(mod_security) mod_security (id:949110) triggered by 34.20.176.131 (US/United States/131.176.20.34.b ...
show more
(mod_security) mod_security (id:949110) triggered by 34.20.176.131 (US/United States/131.176.20.34.bc.googleusercontent.com): N in the last X secs
show less
Web App Attack
🇩🇪
FD-IX
2026-09-05 22:56:41
(18 hours ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
🇫🇷
dynamix
2026-09-05 22:56:24
(18 hours ago)
Multiple WAF Violations
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 22:40:31
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.20.176.131 (131.176.20.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.20.176.131 (131.176.20.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 18:40:26.294824 2026] [security2:error] [pid 14369:tid 14369] [client 34.20.176.131:54756] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "gildemello.com"] [uri "/wp-config.php~"] [unique_id "apyaWnuUTJbgQXDYwbKPGwAAAFc"]
show less
Brute-Force
Bad Web Bot
Web App Attack