🇺🇸
TPI-Abuse
2026-09-04 14:12:59
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.47.49.241 (241.49.47.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.47.49.241 (241.49.47.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 10:12:53.223763 2026] [security2:error] [pid 23489:tid 23489] [client 34.47.49.241:47074] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.pa-ksa.com"] [uri "/.env"] [unique_id "aprR5RfejGTcC-YXHn6_9wAAAG4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
MatCat
2026-09-04 14:05:12
(8 hours ago)
Banned by fail2ban: apache-webprobe
Port Scan
Bad Web Bot
🇺🇸
dot.mg
2026-09-04 13:38:08
(8 hours ago)
Bad behaviour
Web Spam
🇸🇪
vaia.cloud
2026-09-04 13:25:03
(8 hours ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 12:32:11
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.47.49.241 (241.49.47.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.47.49.241 (241.49.47.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 08:32:06.583520 2026] [security2:error] [pid 16041:tid 16041] [client 34.47.49.241:42652] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "gdhlgroup.com"] [uri "/.env.prod"] [unique_id "apq6RgWEie16nnnI92vppwAAAIM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇵🇱
Budyn
2026-09-04 12:04:28
(10 hours ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scan ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scanner. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: i.budyn.ovh | URI: /actuator/configprops | UA: crusader-worker/1.0 | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
🇬🇧
WebNiraj
2026-09-04 11:54:13
(10 hours ago)
(mod_security) mod_security (id:949110) triggered by 34.47.49.241 (CA/Canada/241.49.47.34.bc.googleu ...
show more
(mod_security) mod_security (id:949110) triggered by 34.47.49.241 (CA/Canada/241.49.47.34.bc.googleusercontent.com): 5 in the last 3600 secs [SIGMA]
show less
Brute-Force
🇺🇸
TPI-Abuse
2026-09-04 11:44:46
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.47.49.241 (241.49.47.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.47.49.241 (241.49.47.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 07:44:40.675750 2026] [security2:error] [pid 12728:tid 12728] [client 34.47.49.241:43134] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.advantstudio.com"] [uri "/.env.local"] [unique_id "apqvKGdGt75srHtkylIBcgAAAC0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
Aetherweb Ark
2026-09-04 10:56:42
(11 hours ago)
(mod_security) mod_security (id:949110) triggered by 34.47.49.241 (CA/Canada/241.49.47.34.bc.googleu ...
show more
(mod_security) mod_security (id:949110) triggered by 34.47.49.241 (CA/Canada/241.49.47.34.bc.googleusercontent.com): N in the last X secs
show less
Web App Attack
🇩🇪
FD-IX
2026-09-04 10:55:04
(11 hours ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
🇺🇸
kosada.com
2026-09-04 10:42:45
(11 hours ago)
Repeated exploit attempts, for example: /.env.backup /.env (HTTP/1.1 port 443)
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 10:02:19
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.47.49.241 (241.49.47.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.47.49.241 (241.49.47.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 06:02:06.014309 2026] [security2:error] [pid 13479:tid 13479] [client 34.47.49.241:44468] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.kuddlkat.com"] [uri "/wp-config.php~"] [unique_id "apqXHnKzTmq4Kja920HtWAAAAC0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
Stara
2026-09-04 10:01:44
(12 hours ago)
ModSecurity detected web attack - .env/config probing or SQLi/Code injection (Rule 949110)
Brute-Force
SSH
Web App Attack
🇨🇦
polycoda
2026-09-04 09:53:00
(12 hours ago)
AutoBlock: 🎯 Vulnerability Scanner (Non Decay-Based) - ⚙️ Configuration File Access (Non Decay-Based ...
show more
AutoBlock: 🎯 Vulnerability Scanner (Non Decay-Based) - ⚙️ Configuration File Access (Non Decay-Based)
show less
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 09:24:33
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.47.49.241 (241.49.47.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.47.49.241 (241.49.47.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 05:24:26.054009 2026] [security2:error] [pid 25475:tid 25475] [client 34.47.49.241:34318] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.hipstan.com"] [uri "/.env.bak"] [unique_id "apqOSjcmCWXmuh44-XKwKgAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack