🇩🇪
FD-IX
2026-09-06 06:03:13
(7 hours ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 03:51:45
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.47.14.100 (100.14.47.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.47.14.100 (100.14.47.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 23:51:40.878138 2026] [security2:error] [pid 11952:tid 11952] [client 34.47.14.100:50300] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.andrewrmarshall.com"] [uri "/.env.production"] [unique_id "apzjTHIt_LNAqNOeLqEJGwAAACg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 03:28:34
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.47.14.100 (100.14.47.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.47.14.100 (100.14.47.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 23:28:31.547910 2026] [security2:error] [pid 8688:tid 8688] [client 34.47.14.100:36324] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "casaroma-alassio.com"] [uri "/.env.local"] [unique_id "apzd3wu5PG8cEQRgdXt6ZQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 03:06:49
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.47.14.100 (100.14.47.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.47.14.100 (100.14.47.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 23:06:42.947870 2026] [security2:error] [pid 16463:tid 16463] [client 34.47.14.100:59776] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.weddingcakenapkins.com"] [uri "/.env.prod"] [unique_id "apzYwiyNCjgdp8aXpNA_0gAAADs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇱🇻
garmtech.com
2026-09-06 03:04:54
(10 hours ago)
Attempted access to sensitive endpoint (/.env.prod) detected. Automated scan or unauthorized probing ...
show more
Attempted access to sensitive endpoint (/.env.prod) detected. Automated scan or unauthorized probing.
show less
Web App Attack
🇨🇭
zynex
2026-09-06 02:22:55
(11 hours ago)
URL Probing: /.env
Web App Attack
🇫🇷
dynamix
2026-09-06 02:03:42
(11 hours ago)
Multiple WAF Violations
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 01:44:37
(11 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.47.14.100 (100.14.47.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.47.14.100 (100.14.47.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 21:44:30.787791 2026] [security2:error] [pid 13507:tid 13507] [client 34.47.14.100:41522] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||atame.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "atame.com"] [uri "/db.sql"] [unique_id "apzFfgWIE-ejbvM12tkk9gAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
consul.to
2026-09-06 01:36:43
(12 hours ago)
Web attack/malicious scanning detected
Web App Attack
Anonymous
2026-09-06 01:15:04
(12 hours ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 00:33:59
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.47.14.100 (100.14.47.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.47.14.100 (100.14.47.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 20:33:54.035484 2026] [security2:error] [pid 7358:tid 7358] [client 34.47.14.100:46876] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bbernalcom.ayudaclic.com"] [uri "/wp-config.php.swp"] [unique_id "apy08oHJmkGckHEPHd7xFQAAACs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-06 00:30:35
(13 hours ago)
[ssd5.kdns.gr] httpd-config-scan: sites=www.volunteers.weihnachtsbasar-athen.gr; logs=/var/log/httpd ...
show more
[ssd5.kdns.gr] httpd-config-scan: sites=www.volunteers.weihnachtsbasar-athen.gr; logs=/var/log/httpd/domains/weihnachtsbasar-athen.gr.volunteers.log; samples=/.env.production | /wp-config.php~ | /.env.local
show less
Hacking
Web App Attack
🇳🇱
WeCloudit-Anti-Abuse
2026-09-06 00:04:43
(13 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
🇧🇷
Halux
2026-09-05 23:13:33
(14 hours ago)
34.47.14.100 Web Application Firewall multiple violations
Hacking
Web App Attack
🇳🇱
e.fierstra
2026-09-05 23:06:11
(14 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack