🇺🇸
TPI-Abuse
2026-09-04 15:15:33
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.65.108.217 (217.108.65.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.65.108.217 (217.108.65.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 11:15:27.582474 2026] [security2:error] [pid 24498:tid 24498] [client 34.65.108.217:56888] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.instagenii.com"] [uri "/wp-config.php~"] [unique_id "aprgj4VdWmX7sfRVo8fWjAAAACk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
FD-IX
2026-09-04 14:42:17
(13 hours ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
🇩🇪
FeG Deutschland
2026-09-04 14:40:52
(13 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
🇸🇪
vaia.cloud
2026-09-04 14:40:03
(13 hours ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
🇮🇪
AutosOnShow
2026-09-04 13:54:07
(13 hours ago)
blocked for webapp attack | path requested: / | seen at 2026-09-04 13:53:46.885 |
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 13:50:10
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.65.108.217 (217.108.65.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.65.108.217 (217.108.65.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 09:50:04.643459 2026] [security2:error] [pid 1659:tid 1659] [client 34.65.108.217:36220] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "achari.com"] [uri "/.env.prod"] [unique_id "aprMjIxwO7hQRQP-rjfv-wAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-04 13:49:03
(14 hours ago)
Bot / scanning and/or hacking attempts: GET /.env.dev HTTP/1.1, GET /wp-config.php.swp HTTP/1.1
Hacking
Web App Attack
Anonymous
2026-09-04 12:52:25
(14 hours ago)
SIEM ALERT AUTO REPORT
Email Spam
🇩🇪
Petros Stefanakis
2026-09-04 12:50:46
(15 hours ago)
(mod_security) mod_security triggered on hostname [redacted] 34.65.108.217 (CH/Switzerland/217.108.6 ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.65.108.217 (CH/Switzerland/217.108.65.34.bc.googleusercontent.com)
show less
SQL Injection
🇩🇪
Melle
2026-09-04 12:49:26
(15 hours ago)
Blocked by CrowdSec | Scenario: crowdsecurity/http-sensitive-files | 34.65.108.217 triggered 5 event ...
show more
Blocked by CrowdSec | Scenario: crowdsecurity/http-sensitive-files | 34.65.108.217 triggered 5 events | Detected: 2026-09-04T12:49:25.406675732Z
show less
Web App Attack
Hacking
🇩🇪
Gwyneth Llewelyn
2026-09-04 11:55:26
(15 hours ago)
2026/09/04 12:55:19 [error] 380595#380595: *2782884 access forbidden by rule, client: 34.65.108.217, ...
show more
2026/09/04 12:55:19 [error] 380595#380595: *2782884 access forbidden by rule, client: 34.65.108.217, server: superiorinnercore.game-host.org, request: "GET /.env HTTP/1.1", host: "superiorinnercore.game-host.org"
34.65.108.217 - - [04/Sep/2026:12:55:19 +0100] "GET /.env HTTP/1.1" 403 2599 "-" "crusader-worker/1.0"
2026/09/04 12:55:24 [error] 380594#380594: *2782898 access forbidden by rule, client: 34.65.108.217, server: superiorinnercore.game-host.org, request: "GET //.env HTTP/1.1", host: "superiorinnercore.game-host.org"
show less
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 11:52:55
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.65.108.217 (217.108.65.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.65.108.217 (217.108.65.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 07:52:48.114489 2026] [security2:error] [pid 13767:tid 13767] [client 34.65.108.217:49232] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.adamsclothiers.com"] [uri "/.env.save"] [unique_id "apqxEDZzpGPW4n0HErbpTQAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 11:05:50
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.65.108.217 (217.108.65.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.65.108.217 (217.108.65.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 07:05:42.754560 2026] [security2:error] [pid 28576:tid 28576] [client 34.65.108.217:56444] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "hollyndlaw.com"] [uri "/.env.example"] [unique_id "apqmBo0ydu0XYR1xug3V_gAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
BlueWire Hosting
2026-09-04 10:56:25
(16 hours ago)
High-confidence malicious configuration/VCS probe
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 10:42:53
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.65.108.217 (217.108.65.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.65.108.217 (217.108.65.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 06:42:49.017405 2026] [security2:error] [pid 30441:tid 30441] [client 34.65.108.217:52358] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kneupper.com"] [uri "/wp-config.php.swp"] [unique_id "apqgqRsYFb9tliG_PsM-ywAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack