🇺🇸
TPI-Abuse
2026-09-06 04:13:13
(16 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.20.253.134 (134.253.20.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.20.253.134 (134.253.20.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 00:13:08.530696 2026] [security2:error] [pid 28402:tid 28402] [client 34.20.253.134:44238] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||cain2012.org|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "cain2012.org"] [uri "/backup.sql"] [unique_id "apzoVD-iJ_8ilLrrDPXSdAAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 03:54:10
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.20.253.134 (134.253.20.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.20.253.134 (134.253.20.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 23:54:04.842968 2026] [security2:error] [pid 32120:tid 32120] [client 34.20.253.134:60888] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.henning.org"] [uri "/.env"] [unique_id "apzj3NIhdSq3XAXzxUlRZQAAAI0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 01:28:05
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.20.253.134 (134.253.20.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.20.253.134 (134.253.20.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 21:28:01.223891 2026] [security2:error] [pid 16138:tid 16138] [client 34.20.253.134:54192] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "10bestcountryclubs.directoryofbikes.com"] [uri "/wp-config.php.bak"] [unique_id "apzBoZoQNZBoWw0PQh3gGAAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-06 01:15:20
(19 hours ago)
Multiple web server 400 error codes from same source ip
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 00:37:33
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.20.253.134 (134.253.20.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.20.253.134 (134.253.20.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 20:37:29.901468 2026] [security2:error] [pid 10868:tid 10868] [client 34.20.253.134:57882] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "hienle.com"] [uri "/.env.bak"] [unique_id "apy1yZtGqeDzWHefAAKddAAAAEc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 23:58:05
(20 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.20.253.134 (134.253.20.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.20.253.134 (134.253.20.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 19:57:57.687674 2026] [security2:error] [pid 30947:tid 30947] [client 34.20.253.134:48948] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.businessthanksgivingcard.com"] [uri "/.env"] [unique_id "apyshX2D2f67vATTveZbrwAAAJE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
mnsf
2026-09-05 23:05:47
(21 hours ago)
Scanning/Probing (20)
Brute-Force
Web App Attack
🇳🇱
WeCloudit-Anti-Abuse
2026-09-05 23:04:06
(21 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
🇫🇷
dynamix
2026-09-05 22:57:35
(21 hours ago)
Multiple WAF Violations
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 22:52:16
(21 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.20.253.134 (134.253.20.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.20.253.134 (134.253.20.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 18:52:11.888975 2026] [security2:error] [pid 16927:tid 16927] [client 34.20.253.134:50560] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "drowninglovers.com"] [uri "/.env.old"] [unique_id "apydG7v3DrtRg3NMq_h9twAAAJI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
NewGastroline
2026-09-05 22:39:31
(21 hours ago)
Malicious request blocked by CrowdSec on gastro-prod1.boreus.de
Bad Web Bot
Web App Attack
Anonymous
2026-09-05 22:37:55
(21 hours ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack
🇳🇱
e.fierstra
2026-09-05 22:27:12
(21 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
🇬🇧
Aetherweb Ark
2026-09-05 22:17:31
(22 hours ago)
(mod_security) mod_security (id:949110) triggered by 34.20.253.134 (US/United States/134.253.20.34.b ...
show more
(mod_security) mod_security (id:949110) triggered by 34.20.253.134 (US/United States/134.253.20.34.bc.googleusercontent.com): N in the last X secs
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 22:11:46
(22 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.20.253.134 (134.253.20.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.20.253.134 (134.253.20.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 18:11:38.765959 2026] [security2:error] [pid 19824:tid 19824] [client 34.20.253.134:42126] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.purelywhimsical.com"] [uri "/.env.production"] [unique_id "apyTmhBECJ14ViMo8-dk1AAAAHw"]
show less
Brute-Force
Bad Web Bot
Web App Attack