🇺🇸
TPI-Abuse
2026-09-07 20:29:07
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.30.211.158 (158.211.30.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.30.211.158 (158.211.30.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 16:29:02.506854 2026] [security2:error] [pid 2648:tid 2648] [client 34.30.211.158:36676] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "carolmaalouf.com"] [uri "/@fs/.env"] [unique_id "ap8ejr0QHLuTyojOIAzm_QAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 19:41:17
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.30.211.158 (158.211.30.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.30.211.158 (158.211.30.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 15:41:12.707250 2026] [security2:error] [pid 24987:tid 24987] [client 34.30.211.158:63868] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.samanthasomers.com"] [uri "/@fs/../../.env"] [unique_id "ap8TWOuoDfuJsDJBfwheSgAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-07 18:42:58
(9 hours ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-07 18:37:50
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.30.211.158 (158.211.30.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.30.211.158 (158.211.30.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 14:37:42.927909 2026] [security2:error] [pid 31283:tid 31283] [client 34.30.211.158:11716] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jacksonholetim.individualhealth.com"] [uri "/@fs/.env.development"] [unique_id "ap8EdjvHB8jMuPejuwFl3wAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
Savvii
2026-09-07 18:32:36
(9 hours ago)
20 attempts against mh-misbehave-ban on redirect
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 18:17:23
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.30.211.158 (158.211.30.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.30.211.158 (158.211.30.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 14:17:15.819977 2026] [security2:error] [pid 16926:tid 16935] [client 34.30.211.158:10092] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.oldestgunclub.com"] [uri "/@fs/.env"] [unique_id "ap7_q0fKrKGIT3M1qZw3PwAAAQQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
Site.eu
2026-09-07 17:34:46
(10 hours ago)
Excessive 404/403 errors
Brute-Force
🇳🇱
e.fierstra
2026-09-07 17:29:13
(10 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 17:24:09
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.30.211.158 (158.211.30.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.30.211.158 (158.211.30.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 13:24:03.440609 2026] [security2:error] [pid 12917:tid 12917] [client 34.30.211.158:64888] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.coalminer.com"] [uri "/@fs/.env"] [unique_id "ap7zM7GDVsg8FJ6M4_GwwAAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
big-cloud.nl
2026-09-07 17:22:22
(10 hours ago)
Try to access /@fs/.env?raw??
Web App Attack
🇪🇸
pipeline.es
2026-09-07 17:19:05
(10 hours ago)
Web scanning / probing for vulnerable paths | URL: /graphql | Evidence: www.viajeslinan.com 34.30.21 ...
show more
Web scanning / probing for vulnerable paths | URL: /graphql | Evidence: www.viajeslinan.com 34.30.211.158 - - [07/Sep/2026:19:18:21 +0200] \"GET /graphql HTTP/1.1\" 404 4189 \"-\" \"Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko; compatible; Bytespider; +https://zhanzhang.toutiao.com/) Chrome/151.0.7041.165 Safari/537.36 Edg/151.0.7041.165\" GEOIP_COUNTRY_CODE=US | ASN: GOOGLE-CLOUD-PLATFORM | Country: US
show less
Port Scan
Web App Attack
Anonymous
2026-09-07 16:58:40
(11 hours ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 16:54:30
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.30.211.158 (158.211.30.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.30.211.158 (158.211.30.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 12:54:24.613021 2026] [security2:error] [pid 22404:tid 22404] [client 34.30.211.158:14660] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "quincysheetmetal.com.nashes.net"] [uri "/@fs/src/.env"] [unique_id "ap7sQAamilaJS2OsDt1BWAAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 16:06:04
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.30.211.158 (158.211.30.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.30.211.158 (158.211.30.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 12:05:58.444451 2026] [security2:error] [pid 16534:tid 16534] [client 34.30.211.158:47484] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.futureproductionsonline.com"] [uri "/@fs/..%252f..%252f..%252f..%252f..%252fapp/.env"] [unique_id "ap7g5o47RcaH3ESlH6Bx_wAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇮🇹
VHosting
2026-09-07 15:45:03
(12 hours ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack