🇹🇷
Threat.live
2026-09-05 07:30:03
(4 hours ago)
Threat.live: Web Scan
Web App Attack
🇧🇾
lns.bz
2026-09-05 07:05:59
(4 hours ago)
.env scanning [BY]
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 15:16:30
(20 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.21.74.173 (173.74.21.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.21.74.173 (173.74.21.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 11:16:26.386930 2026] [security2:error] [pid 19994:tid 19994] [client 34.21.74.173:52094] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.haywardcarpentry.com"] [uri "/.env.save"] [unique_id "aprgykbISKPF1JCK3meQpgAAAD0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 14:50:51
(21 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.21.74.173 (173.74.21.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.21.74.173 (173.74.21.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 10:50:44.164174 2026] [security2:error] [pid 20946:tid 20946] [client 34.21.74.173:60706] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "chaletparkaparts.com.handankoc.net"] [uri "/wp-config.php.swp"] [unique_id "apraxEmvKT4VEYrZtZNRVwAAACQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇮🇹
Inartis
2026-09-04 14:11:45
(21 hours ago)
34.21.74.173 - - [04/Sep/2026:16:11:44 +0200] "GET /.env.production HTTP/1.1" 404 5156 "-" "crusader ...
show more
34.21.74.173 - - [04/Sep/2026:16:11:44 +0200] "GET /.env.production HTTP/1.1" 404 5156 "-" "crusader-worker/1.0"
...
show less
Brute-Force
Bad Web Bot
Web App Attack
🇸🇪
vaia.cloud
2026-09-04 13:20:05
(22 hours ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 12:18:04
(23 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.21.74.173 (173.74.21.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.21.74.173 (173.74.21.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 08:17:59.401073 2026] [security2:error] [pid 6869:tid 6869] [client 34.21.74.173:40590] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mitchellamazing.com"] [uri "/.env.save"] [unique_id "apq29yskq2wi-b4qKIY00wAAACE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
thetomtaylor.co.uk
2026-09-04 12:08:01
(23 hours ago)
Fail2Ban - [WEB]Custom exploit pattern detected on customexploits ... [ice01,ice02,wa01,wa02]
Hacking
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 10:01:25
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.21.74.173 (173.74.21.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.21.74.173 (173.74.21.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 06:01:21.118274 2026] [security2:error] [pid 486379:tid 486379] [client 34.21.74.173:35380] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.nuewines.com"] [uri "/.env.production"] [unique_id "apqW8Ss-ZzdoeveV7OBP9gAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 09:25:29
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.21.74.173 (173.74.21.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.21.74.173 (173.74.21.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 05:25:21.481537 2026] [security2:error] [pid 31157:tid 31212] [client 34.21.74.173:49724] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.dkmyers.com"] [uri "/.env.prod"] [unique_id "apqOgQ3ftUW3UjUe0T6o5gAAAFI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 09:08:35
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.21.74.173 (173.74.21.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.21.74.173 (173.74.21.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 05:08:31.644770 2026] [security2:error] [pid 10587:tid 10587] [client 34.21.74.173:35704] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kwgolf.five21.com"] [uri "/.env.prod"] [unique_id "apqKj-IS6_QLPwdpnqEhHgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
ddobko
2026-09-04 08:38:57
(1 day ago)
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 08:38:51
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.21.74.173 (173.74.21.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.21.74.173 (173.74.21.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 04:38:42.779069 2026] [security2:error] [pid 29539:tid 29539] [client 34.21.74.173:43960] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "register-yacht-slovenia.com"] [uri "/.env.prod"] [unique_id "apqDkiR_X4UQ6F5uTHI2FAAAADo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
WeCloudit-Anti-Abuse
2026-09-04 08:29:11
(1 day ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
🇩🇪
FD-IX
2026-09-04 08:19:54
(1 day ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack