🇺🇸
TPI-Abuse
2026-09-04 15:21:21
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.26.188.42 (42.188.26.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.26.188.42 (42.188.26.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 11:21:15.673355 2026] [security2:error] [pid 418:tid 418] [client 34.26.188.42:58332] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.baystreet.news"] [uri "/.env.prod"] [unique_id "aprh6x7rfUn8CtlZlCsyHgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-04 14:57:05
(19 hours ago)
Blocked by ModSec and CSF
Port Scan
🇩🇪
tentwentyfour
2026-09-04 14:47:54
(19 hours ago)
Blocked for probing for sensitive web application components
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 14:32:01
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.26.188.42 (42.188.26.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.26.188.42 (42.188.26.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 10:31:55.330139 2026] [security2:error] [pid 20100:tid 20100] [client 34.26.188.42:47922] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "delta-pizza.com"] [uri "/.env.local"] [unique_id "aprWW0d8WqxHanLTfWxEagAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
4server
2026-09-04 14:07:11
(20 hours ago)
[FriSep0416:07:05.8612162026][security2:error][pid247402:tid247483][client34.26.188.42:0]ModSecurity ...
show more
[FriSep0416:07:05.8612162026][security2:error][pid247402:tid247483][client34.26.188.42:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Patternmatch\"\(\?i\)\(\?:/\(\?:\^\|/\)\\\\\\\\.\(env\|git\|svn\|hg\|DS_Store\)\|/\(\?:wp-config\|\\\\\\\\.htaccess\|\\\\\\\\.htpasswd\)\|\\\\\\\\.\(\?:sql\|bak\|old\|log\)\$\)\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"156\"][id\"960720\"][msg\"Forbiddenfileaccessattempt\"][severity\"CRITICAL\"][hostname\"webdisk.dsfiduciaria.ch\"][uri\"/wp-config.php.bak\"][unique_id\"aprQib8PcG9jK9JA8TIdCwAAAJI\"]
show less
Port Scan
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 14:02:08
(20 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.26.188.42 (42.188.26.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.26.188.42 (42.188.26.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 10:02:00.061811 2026] [security2:error] [pid 2593:tid 2593] [client 34.26.188.42:57758] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "oshkoshvolleyball.thinksite.net"] [uri "/.env.dev"] [unique_id "aprPWNxAwOq8g24InCd7ZgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-04 13:07:08
(21 hours ago)
Automated web scanner. Requested suspicious paths: /env. UTC: 2026-09-04 12:29:26.
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 12:51:39
(21 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.26.188.42 (42.188.26.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.26.188.42 (42.188.26.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 08:51:33.525019 2026] [security2:error] [pid 2112:tid 2112] [client 34.26.188.42:39684] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mantarparke.chevronparkett.com"] [uri "/.env.bak"] [unique_id "apq-1ViDA0QMGjd0EoO1kQAAACA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 11:44:05
(22 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.26.188.42 (42.188.26.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.26.188.42 (42.188.26.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 07:43:59.094655 2026] [security2:error] [pid 466:tid 466] [client 34.26.188.42:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.ndanetworks.com"] [uri "/.env.save"] [unique_id "apqu_ypjP2UsNH9Nd03hGAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
debestelapp
2026-09-04 11:25:11
(22 hours ago)
Web App Attack
🇩🇪
ddobko
2026-09-04 10:47:36
(23 hours ago)
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 10:03:34
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.26.188.42 (42.188.26.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.26.188.42 (42.188.26.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 06:03:26.379197 2026] [security2:error] [pid 26027:tid 26027] [client 34.26.188.42:51544] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.jiveturkeyband.com"] [uri "/.env.bak"] [unique_id "apqXbrc9LUJylp9f_ePqpQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
factor1
2026-09-04 10:02:49
(1 day ago)
CrowdSec at apollo Reports Abuse
Web App Attack
🇩🇰
Leif Neland
2026-09-04 10:00:04
(1 day ago)
Detected by CrowdSec on slim
Brute-Force
🇺🇸
TPI-Abuse
2026-09-04 09:17:52
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.26.188.42 (42.188.26.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.26.188.42 (42.188.26.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 05:17:46.390990 2026] [security2:error] [pid 17003:tid 17003] [client 34.26.188.42:37558] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jfordclanrecipes.com"] [uri "/.env.local"] [unique_id "apqMupXuSX8_bV5AyXj_XAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack