🇺🇸
TPI-Abuse
2026-09-04 15:16:52
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.40.245.143 (143.245.40.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.40.245.143 (143.245.40.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 11:16:48.241808 2026] [security2:error] [pid 17294:tid 17294] [client 34.40.245.143:53272] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.thelittleprince.net"] [uri "/.env.prod"] [unique_id "aprg4K8MA85nzNYT0OSvTgAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-04 14:38:12
(1 day ago)
Bot / seems abusive / Apache connections: 21
DDoS Attack
Web Spam
Bad Web Bot
Web App Attack
🇫🇷
Jimbo67
2026-09-04 13:25:48
(1 day ago)
Cloudflare WAF: 26 hits in 30s | action=block | abuse=confirmed_abuse | categories=19,21 | rule_id=3 ...
show more
Cloudflare WAF: 26 hits in 30s | action=block | abuse=confirmed_abuse | categories=19,21 | rule_id=3329c9d804134f3e89780d69bfd872dc | URIs=/,/%2eenv,/.ENV,/.env,/.env. | confidence=0.90
show less
Web App Attack
Bad Web Bot
🇩🇪
LRob
2026-09-04 12:35:30
(1 day ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /.env.example (+12 more) | 2026-09-04 12:35 UTC
show less
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 12:13:52
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.40.245.143 (143.245.40.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.40.245.143 (143.245.40.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 08:13:48.805150 2026] [security2:error] [pid 10805:tid 10805] [client 34.40.245.143:51646] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mnalabama.com"] [uri "/wp-config.php.bak"] [unique_id "apq1_Eq6xCahx5UbMa2TgAAAACA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
e.fierstra
2026-09-04 12:10:13
(1 day ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 11:16:37
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.40.245.143 (143.245.40.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.40.245.143 (143.245.40.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 07:16:31.224629 2026] [security2:error] [pid 5764:tid 5764] [client 34.40.245.143:37632] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.fundingangelinvestors.com"] [uri "/wp-config.php~"] [unique_id "apqojzqrvjCrcrFu1KGUTgAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇸🇪
vaia.cloud
2026-09-04 11:05:06
(1 day ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
🇩🇪
netclix.gr
2026-09-04 10:57:09
(1 day ago)
(mod_security) mod_security triggered on hostname [redacted] 34.40.245.143 (AU/Australia/143.245.40. ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.40.245.143 (AU/Australia/143.245.40.34.bc.googleusercontent.com): (CF_ENABLE)
show less
SQL Injection
🇺🇸
TPI-Abuse
2026-09-04 10:38:50
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.40.245.143 (143.245.40.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.40.245.143 (143.245.40.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 06:38:45.914575 2026] [security2:error] [pid 21178:tid 21178] [client 34.40.245.143:39120] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "anywherecamera.com"] [uri "/.env.example"] [unique_id "apqftfQ_D-Iv8c-3tt6NOwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
consul.to
2026-09-04 10:21:43
(1 day ago)
Web attack/malicious scanning detected
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 10:02:19
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.40.245.143 (143.245.40.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.40.245.143 (143.245.40.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 06:02:07.548999 2026] [security2:error] [pid 24231:tid 24231] [client 34.40.245.143:57042] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.fatcavestudios.com"] [uri "/.env.old"] [unique_id "apqXH3reXjhUOq1I17649wAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 08:35:31
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.40.245.143 (143.245.40.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.40.245.143 (143.245.40.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 04:35:24.013116 2026] [security2:error] [pid 713:tid 713] [client 34.40.245.143:33662] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "relationshipecology.com"] [uri "/.env.save"] [unique_id "apqCzEY0-29c4iIKAL0fZwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
Hazzard
2026-09-04 08:24:01
(1 day ago)
(mod_security) mod_security triggered on hostname [redacted]): (CF_ENABLE)
SQL Injection
Anonymous
2026-09-04 08:11:09
(1 day ago)
Bloqueado automaticamente por CrowdSec escenario crowdsecurity/http-sensitive-files
Brute-Force