🇩🇪
FD-IX
2026-09-04 12:11:28
(30 minutes ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
🇺🇸
WellSpring
2026-09-04 11:56:54
(45 minutes ago)
env exposure on naturologie.com/.env.local — WellSpr.ing/NetSentinel civic-AI security layer
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 11:39:12
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.6.240.75 (75.240.6.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.6.240.75 (75.240.6.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 07:39:06.298488 2026] [security2:error] [pid 13901:tid 13901] [client 34.6.240.75:39134] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "2ezgroup.com"] [uri "/.env.prod"] [unique_id "apqt2iBHV-oeHhosXr5rYAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
Stara
2026-09-04 11:20:59
(1 hour ago)
ModSecurity detected web attack - .env/config probing or SQLi/Code injection (Rule 949110)
Brute-Force
SSH
Web App Attack
🇫🇷
dynamix
2026-09-04 10:52:40
(1 hour ago)
Multiple WAF Violations
Web App Attack
🇬🇧
consul.to
2026-09-04 10:34:01
(2 hours ago)
Web attack/malicious scanning detected
Web App Attack
🇨🇦
zXero
2026-09-04 10:23:13
(2 hours ago)
Fail2Ban automatic report - jail: no-wordpress
Brute-Force
SSH
DDoS Attack
🇺🇸
TPI-Abuse
2026-09-04 08:50:38
(3 hours ago)
(mod_security) mod_security (id:949110) triggered by 34.6.240.75 (75.240.6.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:949110) triggered by 34.6.240.75 (75.240.6.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 04:50:33.284674 2026] [security2:error] [pid 31826:tid 31826] [client 34.6.240.75:58380] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "789bid.net.crazycontrols.com"] [uri "/.env.backup"] [unique_id "apqGWVdZZARWEbOTluwxqQAAACw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
ddobko
2026-09-04 08:35:13
(4 hours ago)
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 08:27:34
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.6.240.75 (75.240.6.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.6.240.75 (75.240.6.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 04:27:29.592390 2026] [security2:error] [pid 29657:tid 29657] [client 34.6.240.75:40004] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.danafrostick.com"] [uri "/.env.bak"] [unique_id "apqA8W-x9E0u1Z6NjeLYGwAAACU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
WeCloudit-Anti-Abuse
2026-09-04 08:24:00
(4 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
🇬🇧
Aetherweb Ark
2026-09-04 08:06:10
(4 hours ago)
(mod_security) mod_security (id:949110) triggered by 34.6.240.75 (75.240.6.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:949110) triggered by 34.6.240.75 (75.240.6.34.bc.googleusercontent.com): N in the last X secs
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 07:47:00
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.6.240.75 (75.240.6.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.6.240.75 (75.240.6.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 03:46:54.383985 2026] [security2:error] [pid 26139:tid 26139] [client 34.6.240.75:58138] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ftp.outsourceitinc.com"] [uri "/.env.production"] [unique_id "app3btjlH5kLcW9GBbSU_wAAAE4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
initsol
2026-09-04 06:27:40
(6 hours ago)
[Fri Sep 04 08:27:39.133389 2026] [authz_core:error] [pid 1929757:tid 1929757] [client 34.6.240.75:6 ...
show more
[Fri Sep 04 08:27:39.133389 2026] [authz_core:error] [pid 1929757:tid 1929757] [client 34.6.240.75:60720] AH01630: client denied by server configuration: /var/www/.env.old
[Fri Sep 04 08:27:39.133905 2026] [authz_core:error] [pid 1935555:tid 1935555] [client 34.6.240.75:60716] AH01630: client denied by server configuration: /var/www/.env.prod
[Fri Sep 04 08:27:39.139540 2026] [authz_core:error] [pid 1935563:tid 1935563] [client 34.6.240.75:60760] AH01630: client denied by server configuration: /var/www/.env.backup
...
show less
Brute-Force
🇩🇪
Hazzard
2026-09-04 05:53:09
(6 hours ago)
(mod_security) mod_security triggered on hostname [redacted]): (CF_ENABLE)
SQL Injection