🇺🇸
Copious7283
2026-09-09 15:28:23
(34 minutes ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-09 14:21:06
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.62.195.170 (170.195.62.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.62.195.170 (170.195.62.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 10:21:03.179801 2026] [security2:error] [pid 12544:tid 12544] [client 34.62.195.170:24706] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.meliaethelwoodard.com"] [uri "/@fs/src/.env"] [unique_id "aqFrTwgQUS03pdgXQBOm-QAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 13:47:10
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.62.195.170 (170.195.62.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.62.195.170 (170.195.62.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 09:47:02.081061 2026] [security2:error] [pid 16653:tid 16713] [client 34.62.195.170:18442] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.jonneher.com"] [uri "/@fs/.env"] [unique_id "aqFjVm206c_MfMEAHdL2MAAAAMo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 13:10:23
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.62.195.170 (170.195.62.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.62.195.170 (170.195.62.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 09:10:17.297928 2026] [security2:error] [pid 15151:tid 15151] [client 34.62.195.170:35188] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.writeitright.biz"] [uri "/@fs/src/.env"] [unique_id "aqFaudJc3MowQWPsn2lP-wAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇧🇪
voormedia
2026-09-09 12:08:56
(3 hours ago)
Accessed trap at '/.env'
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 11:20:19
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.62.195.170 (170.195.62.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.62.195.170 (170.195.62.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 07:20:14.495682 2026] [security2:error] [pid 25107:tid 25107] [client 34.62.195.170:13674] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.bencramerinc.com"] [uri "/@fs/root/.env"] [unique_id "aqFA7t89e6J3dvkM51crNgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
LRob
2026-09-09 11:13:20
(4 hours ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /@fs/root/.env (+2 more) | 2026-09-09 11:13 UTC
show less
Hacking
Web App Attack
Anonymous
2026-09-09 11:07:12
(4 hours ago)
Bot / seems abusive / Apache connections: 33
DDoS Attack
Web Spam
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 10:32:36
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.62.195.170 (170.195.62.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.62.195.170 (170.195.62.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 06:32:29.971792 2026] [security2:error] [pid 1226821:tid 1226821] [client 34.62.195.170:53790] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.xunhung.tonylai.com"] [uri "/@fs/..%252f..%252f..%252f..%252f..%252froot/.env"] [unique_id "aqE1vbGTtVnnk_UYzTvszgAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 09:18:59
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.62.195.170 (170.195.62.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.62.195.170 (170.195.62.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 05:18:52.226748 2026] [security2:error] [pid 29227:tid 29252] [client 34.62.195.170:53460] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.dermatologycoloradosprings.com"] [uri "/@fs/src/.env"] [unique_id "aqEkfMG_yzLTRzbn92XzpwAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
Hazzard
2026-09-09 09:02:20
(7 hours ago)
(mod_security) mod_security triggered on hostname [redacted]): (CF_ENABLE)
SQL Injection
🇺🇸
TPI-Abuse
2026-09-09 08:48:49
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.62.195.170 (170.195.62.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.62.195.170 (170.195.62.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 04:48:45.917278 2026] [security2:error] [pid 536297:tid 536354] [client 34.62.195.170:31382] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.blastfuture.com"] [uri "/@fs/app/.env"] [unique_id "aqEdbd9PZyRc2a7l9tql9AAAAIs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 08:30:32
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.62.195.170 (170.195.62.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.62.195.170 (170.195.62.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 04:30:27.714538 2026] [security2:error] [pid 5444:tid 5444] [client 34.62.195.170:51030] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.stricklinranch.com"] [uri "/@fs/../../.env"] [unique_id "aqEZIwhCPrXtCzKuX9cwiQAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇨🇭
leo1305
2026-09-09 07:50:13
(8 hours ago)
CrowdSec detection | scenario: http-probing
Port Scan
Web App Attack
🇳🇱
ConsulHosting
2026-09-09 07:48:32
(8 hours ago)
Automatically blocked due to distributed attack
Hacking