🇩🇪
todix
2026-09-07 13:13:42
(6 hours ago)
Web App Attack Exploid from 34.50.170.18
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 13:06:53
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.50.170.18 (18.170.50.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.50.170.18 (18.170.50.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 09:06:45.559337 2026] [security2:error] [pid 510422:tid 510444] [client 34.50.170.18:34150] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.atitravel-greece.com"] [uri "/@fs/.env.development"] [unique_id "ap625VXgxeJ-Y-n8u_hCzgAAAIg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-07 12:38:53
(6 hours ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
🇳🇱
Savvii
2026-09-07 12:35:25
(6 hours ago)
20 attempts against mh-misbehave-ban on redirect
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 12:32:33
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.50.170.18 (18.170.50.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.50.170.18 (18.170.50.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 08:32:28.111143 2026] [security2:error] [pid 5604:tid 5635] [client 34.50.170.18:10078] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.psychclinicforchange.com"] [uri "/@fs/.env"] [unique_id "ap6u3Inqs0skZHdXxkLy8wAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇮🇹
VHosting
2026-09-07 12:30:03
(6 hours ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
🇫🇷
masterguru
2026-09-07 12:27:43
(6 hours ago)
Restricted File Access Attempt. Matched phrase ".env" at REQUEST_FILENAME. (930130-196)
Hacking
Web App Attack
Anonymous
2026-09-07 12:13:51
(7 hours ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 12:11:06
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.50.170.18 (18.170.50.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.50.170.18 (18.170.50.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 08:10:58.393420 2026] [security2:error] [pid 2203:tid 2203] [client 34.50.170.18:3640] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.pagewideprinting.com"] [uri "/@fs/.env.local"] [unique_id "ap6p0vzs9sv4yXedIyYFMwAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
Octopuce
2026-09-07 12:08:51
(7 hours ago)
Aggressive web search of vulnerable pages: /_nuxt/../.env /.env.local /v2/.env /assets../.env /image ...
show more
Aggressive web search of vulnerable pages: /_nuxt/../.env /.env.local /v2/.env /assets../.env /images../.env ...
show less
Web App Attack
🇫🇷
COMAITE
2026-09-07 11:57:23
(7 hours ago)
Suspicious URL access.
Web App Attack
🇳🇱
WeCloudit-Anti-Abuse
2026-09-07 11:54:07
(7 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-07 11:47:14
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.50.170.18 (18.170.50.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.50.170.18 (18.170.50.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 07:47:07.278438 2026] [security2:error] [pid 27639:tid 27639] [client 34.50.170.18:62004] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.hope4elsalvador.org"] [uri "/@fs/..%252f..%252f..%252f..%252f..%252fapp/.env"] [unique_id "ap6kO3OQw52_O2NyLCUTVAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack