Anonymous
2026-09-04 14:09:54
(7 minutes ago)
(mod_security) mod_security triggered on hostname [redacted])
SQL Injection
🇺🇸
TPI-Abuse
2026-09-04 14:05:52
(11 minutes ago)
(mod_security) mod_security (id:210492) triggered by 34.26.63.173 (173.63.26.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.26.63.173 (173.63.26.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 10:05:48.216687 2026] [security2:error] [pid 8451:tid 8451] [client 34.26.63.173:50862] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.musicfreakcentral.com"] [uri "/.env.dev"] [unique_id "aprQPC33DIlMZJC9ZPbuugAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
mnsf
2026-09-04 12:05:18
(2 hours ago)
Scanning/Probing (20)
Brute-Force
Web App Attack
🇳🇱
MyGlobalFlowers
2026-09-04 12:01:06
(2 hours ago)
Multiple WAF Violations
Web App Attack
🇳🇱
e.fierstra
2026-09-04 11:04:23
(3 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
🇬🇧
Aetherweb Ark
2026-09-04 10:56:02
(3 hours ago)
(mod_security) mod_security (id:949110) triggered by 34.26.63.173 (US/United States/173.63.26.34.bc. ...
show more
(mod_security) mod_security (id:949110) triggered by 34.26.63.173 (US/United States/173.63.26.34.bc.googleusercontent.com): N in the last X secs
show less
Web App Attack
🇦🇺
2000cn.com.au
2026-09-04 10:33:37
(3 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
🇫🇷
dynamix
2026-09-04 10:25:07
(3 hours ago)
Multiple WAF Violations
Web App Attack
🇺🇦
URAN Publishing Service
2026-09-04 10:20:48
(3 hours ago)
[04/Sep/2026:13:20:47 +0300] -- 34.26.63.173 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET /w ...
show more
[04/Sep/2026:13:20:47 +0300] -- 34.26.63.173 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET /wp-config.php.bak HTTP/1.1
show less
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 10:13:54
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.26.63.173 (173.63.26.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.26.63.173 (173.63.26.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 06:13:50.585853 2026] [security2:error] [pid 26922:tid 26922] [client 34.26.63.173:43892] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "johnrobinsonconsulting.com"] [uri "/.env.production"] [unique_id "apqZ3oBK3RzAoyNiA0ETuQAAAEk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 09:50:00
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.26.63.173 (173.63.26.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.26.63.173 (173.63.26.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 05:49:51.993588 2026] [security2:error] [pid 13190:tid 13190] [client 34.26.63.173:37358] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "hatebay.com"] [uri "/wp-config.php~"] [unique_id "apqUP6tUwkqFgIBjOPjknAAAAGo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
LRob
2026-09-04 09:49:46
(4 hours ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /.env.example (+10 more) | 2026-09-04 09:49 UTC
show less
Hacking
Web App Attack
🇫🇷
masterguru
2026-09-04 09:35:11
(4 hours ago)
Restricted File Access Attempt. Matched phrase ".env" at REQUEST_FILENAME. (930130-195)
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 09:11:00
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.26.63.173 (173.63.26.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.26.63.173 (173.63.26.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 05:10:57.211651 2026] [security2:error] [pid 26330:tid 26330] [client 34.26.63.173:56442] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "landeagle.com"] [uri "/.env"] [unique_id "apqLIUb4wm4xpi64svmcAgAAACk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 08:55:31
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.26.63.173 (173.63.26.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.26.63.173 (173.63.26.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 04:55:27.041447 2026] [security2:error] [pid 2442121:tid 2442150] [client 34.26.63.173:33526] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "tkfay.com"] [uri "/.env.local"] [unique_id "apqHfzF_vKxy6dhjsYiaKAAAAMk"]
show less
Brute-Force
Bad Web Bot
Web App Attack