🇺🇸
TPI-Abuse
2026-09-04 14:58:56
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.39.148.241 (241.148.39.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.39.148.241 (241.148.39.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 10:58:51.672234 2026] [security2:error] [pid 26279:tid 26279] [client 34.39.148.241:37318] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "poland-yacht-registration.yacht-register-holland.com"] [uri "/.env"] [unique_id "aprcq0_f7lKTMrEEQULTOgAAACM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
WeCloudit-Anti-Abuse
2026-09-04 14:53:46
(4 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
Anonymous
2026-09-04 14:34:22
(4 hours ago)
(mod_security) mod_security triggered on hostname [redacted] 34.39.148.241 (BR/Brazil/241.148.39.34. ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.39.148.241 (BR/Brazil/241.148.39.34.bc.googleusercontent.com)
show less
SQL Injection
🇺🇸
TPI-Abuse
2026-09-04 14:11:56
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.39.148.241 (241.148.39.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.39.148.241 (241.148.39.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 10:11:49.350475 2026] [security2:error] [pid 17941:tid 17941] [client 34.39.148.241:39514] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.reelfruits.com"] [uri "/.env.local"] [unique_id "aprRpadO12a5y9Y09aEZtwAAAG0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 13:45:46
(5 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.39.148.241 (241.148.39.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.39.148.241 (241.148.39.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 09:45:39.224187 2026] [security2:error] [pid 25442:tid 25442] [client 34.39.148.241:55914] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||acme-aviation.com|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "acme-aviation.com"] [uri "/wp-config.php.bak"] [unique_id "aprLg5kMFNBmPNinR-TEvQAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-04 13:28:36
(5 hours ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
Anonymous
2026-09-04 11:51:52
(7 hours ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 11:43:42
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.39.148.241 (241.148.39.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.39.148.241 (241.148.39.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 07:43:38.944353 2026] [security2:error] [pid 605348:tid 605348] [client 34.39.148.241:47250] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.grandvistalabs.com"] [uri "/.env.old"] [unique_id "apqu6quw3lOBa-sQnQFULQAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇮🇹
VHosting
2026-09-04 11:20:05
(7 hours ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
🇫🇷
dynamix
2026-09-04 11:03:28
(7 hours ago)
Multiple WAF Violations
Web App Attack
🇩🇪
Viveronese
2026-09-04 10:48:47
(8 hours ago)
HTTP vulnerability scanning
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 10:44:55
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.39.148.241 (241.148.39.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.39.148.241 (241.148.39.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 06:44:50.049585 2026] [security2:error] [pid 15116:tid 15116] [client 34.39.148.241:41606] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "knorgmusic.com"] [uri "/.env"] [unique_id "apqhItkFmiH9IW_zSPouvwAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack