🇺🇸
TPI-Abuse
2026-09-06 03:06:26
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.64.146.164 (164.146.64.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.64.146.164 (164.146.64.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 23:06:17.910961 2026] [security2:error] [pid 12621:tid 12621] [client 34.64.146.164:41634] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.toybud.com"] [uri "/.env.production"] [unique_id "apzYqcUIDMk37Alpi-uLNwAAACY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-06 02:39:51
(6 hours ago)
Multiple web server 400 error codes from same source ip
Web App Attack
🇬🇧
consul.to
2026-09-06 00:37:30
(8 hours ago)
Web attack/malicious scanning detected
Web App Attack
🇩🇪
Tsumugi Kotobuki
2026-09-06 00:21:43
(8 hours ago)
Port Scan on Honeypot | Ports: 80/HTTP | Proto: TCP(1) | Flags: all SYN | TTL: 59 | Len: 60B | Win: ...
show more
Port Scan on Honeypot | Ports: 80/HTTP | Proto: TCP(1) | Flags: all SYN | TTL: 59 | Len: 60B | Win: 65320(1) | rDNS: 164.146.64.34.bc.googleusercontent.com | F2B/ufw-honeypot@2026-09-06T00:21:43Z
show less
Port Scan
Hacking
🇮🇳
evicky2002
2026-09-06 00:02:40
(8 hours ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
🇩🇪
seal
2026-09-05 23:54:40
(8 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
SSH
Brute-Force
🇳🇱
e.fierstra
2026-09-05 23:01:06
(9 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
🇫🇷
Baking333
2026-09-05 22:48:27
(10 hours ago)
[redacted] 34.64.146.164 - - [05/Sep/2026:23:48:26 +0100] "GET /.[redacted] HTTP/1.1" 302 6793 0/534 ...
show more
[redacted] 34.64.146.164 - - [05/Sep/2026:23:48:26 +0100] "GET /.[redacted] HTTP/1.1" 302 6793 0/53473 "-" "crusader-worker/1.0" [redacted] 34.64.146.164 - - [05/Sep/2026:23:48:26 +0100] "GET /.[redacted] HTTP/1.1" 302 6793 0/49866 "-" "crusader-worker/1.0" [redacted] 34.64.146.164 - - [05/Sep/2026:23:48:26 +0100] "GET /.[redacted] HTTP/1.1" 302 6793 0/42293 "-" "crusader-worker/1.0" [redacted] 34.64.146.164 - - [05/Sep/2026:23:48:26 +0100] "GET /.[redacted] HTTP/1.1" 302 6793 0/53211 "-" "crusader-worker/1.0"
show less
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 22:45:49
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.64.146.164 (164.146.64.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.64.146.164 (164.146.64.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 18:45:43.353123 2026] [security2:error] [pid 15679:tid 15679] [client 34.64.146.164:36308] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "videoverse.com"] [uri "/.env.production"] [unique_id "apybly9tKQtaTNLwlIqdbQAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
FeG Deutschland
2026-09-05 21:25:56
(11 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 1247
Exploited Host
Web App Attack
🇬🇧
WebNiraj
2026-09-05 20:44:32
(12 hours ago)
(mod_security) mod_security (id:949110) triggered by 34.64.146.164 (KR/South Korea/164.146.64.34.bc. ...
show more
(mod_security) mod_security (id:949110) triggered by 34.64.146.164 (KR/South Korea/164.146.64.34.bc.googleusercontent.com): 5 in the last 3600 secs [SIGMA]
show less
Brute-Force
🇩🇪
tinect
2026-09-05 07:39:38
(1 day ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
Anonymous
2026-09-05 07:12:38
(1 day ago)
Blocked by ModSec and CSF
Port Scan
🇫🇷
Catalin Negru
2026-09-05 06:42:05
(1 day ago)
2026-09-05 09:42:03,261 fail2ban.actions [1796604]: NOTICE [apache-scan] Ban 34.64.146.164
2 ...
show more
2026-09-05 09:42:03,261 fail2ban.actions [1796604]: NOTICE [apache-scan] Ban 34.64.146.164
2026-09-05 09:42:03,309 fail2ban.actions [1796604]: NOTICE [apache-404] Ban 34.64.146.164
2026-09-05 09:42:03,626 fail2ban.actions [1796604]: NOTICE [laravel-auth] Ban 34.64.146.164
2026-09-05 09:42:04,854 fail2ban.actions [1796604]: NOTICE [apache-security] Ban 34.64.146.164
2026-09-05 09:42:04,964 fail2ban.actions [1796604]: NOTICE [apache-dirscan] Ban 34.64.146.164
...
show less
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 15:14:42
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.64.146.164 (164.146.64.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.64.146.164 (164.146.64.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 11:14:37.712236 2026] [security2:error] [pid 25009:tid 25009] [client 34.64.146.164:60442] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.capassoart.com"] [uri "/.env"] [unique_id "aprgXeKE0IuSRr6_rOCQVwAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack