🇺🇸
TPI-Abuse
2026-09-04 15:07:45
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.45.91.175 (175.91.45.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.45.91.175 (175.91.45.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 11:07:38.723315 2026] [security2:error] [pid 8244:tid 8244] [client 34.45.91.175:52998] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "415test.com"] [uri "/.env.local"] [unique_id "apreusjX98DCJ4C-QqsNTQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
WizardsToolkit
2026-09-04 13:52:25
(1 day ago)
tried to access forbidden files; attempted to access /storage/logs/laravel.log
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 13:51:09
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.45.91.175 (175.91.45.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.45.91.175 (175.91.45.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 09:51:05.155434 2026] [security2:error] [pid 5248:tid 5248] [client 34.45.91.175:60740] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "agkgt.org.ctsaagt.org"] [uri "/.env.dev"] [unique_id "aprMyYD-B5ANzSq4G05OJgAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
Stara
2026-09-04 13:47:58
(1 day ago)
ModSecurity detected web attack - .env/config probing or SQLi/Code injection (Rule 949110)
Brute-Force
SSH
Web App Attack
🇳🇱
e.fierstra
2026-09-04 13:23:20
(1 day ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
🇩🇪
FD-IX
2026-09-04 13:02:12
(1 day ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 12:14:01
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.45.91.175 (175.91.45.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.45.91.175 (175.91.45.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 08:13:57.666730 2026] [security2:error] [pid 22790:tid 22790] [client 34.45.91.175:55010] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "movil.mpservice.com.sv"] [uri "/.env.save"] [unique_id "apq2BR6i257UB_ZNLqgMogAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-04 10:58:52
(1 day ago)
Blocked by ModSec and CSF
Port Scan
🇺🇸
TPI-Abuse
2026-09-04 10:15:42
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.45.91.175 (175.91.45.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.45.91.175 (175.91.45.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 06:15:37.775349 2026] [security2:error] [pid 7060:tid 7060] [client 34.45.91.175:39334] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "barnrods.com"] [uri "/.env.prod"] [unique_id "apqaSZ9ce1q69M2nSjUk4QAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 09:20:03
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.45.91.175 (175.91.45.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.45.91.175 (175.91.45.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 05:19:56.874886 2026] [security2:error] [pid 32242:tid 32242] [client 34.45.91.175:51664] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.andy-blakk.org"] [uri "/.env.local"] [unique_id "apqNPLbNDGlT-2GI5MgFLgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 08:27:43
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.45.91.175 (175.91.45.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.45.91.175 (175.91.45.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 04:27:36.819458 2026] [security2:error] [pid 24320:tid 24325] [client 34.45.91.175:59080] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.jonathanarlook.com"] [uri "/.env.local"] [unique_id "apqA-GGnu9jfQJd6CsUsqwAAAMA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
dynamix
2026-09-04 08:19:08
(1 day ago)
Multiple WAF Violations
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 08:08:13
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.45.91.175 (175.91.45.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.45.91.175 (175.91.45.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 04:08:04.874105 2026] [security2:error] [pid 23296:tid 23296] [client 34.45.91.175:35894] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "dovka.com"] [uri "/wp-config.php.swp"] [unique_id "app8ZMyt_YziTawe63kOHwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-04 07:30:02
(2 days ago)
suspicious request in access.log
Web App Attack
🇺🇦
URAN Publishing Service
2026-09-04 07:07:59
(2 days ago)
[04/Sep/2026:10:07:59 +0300] -- 34.45.91.175 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.env. ...
show more
[04/Sep/2026:10:07:59 +0300] -- 34.45.91.175 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.env.dev HTTP/1.1
show less
Bad Web Bot
Web App Attack