🇺🇸
cwytech
2026-09-05 07:06:30
(5 minutes ago)
Fleet-wide ban from the Ghostfleet 👻. Triggered by scenario: cwy/tactical-rmm-lockdown-high.
Hacking
🇦🇺
2000cn.com.au
2026-09-05 06:51:35
(20 minutes ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-04 15:16:26
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.65.109.148 (148.109.65.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.65.109.148 (148.109.65.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 11:16:17.887873 2026] [security2:error] [pid 18368:tid 18368] [client 34.65.109.148:38378] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.adurpartners.com"] [uri "/wp-config.php.swp"] [unique_id "aprgwZOOqfg-mfKQpku0YQAAAHI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 14:07:08
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.65.109.148 (148.109.65.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.65.109.148 (148.109.65.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 10:07:03.687483 2026] [security2:error] [pid 5984:tid 5984] [client 34.65.109.148:54510] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.nationaljar.com"] [uri "/.env.prod"] [unique_id "aprQh-6WqQukNQJtACLXHgAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
Petros Stefanakis
2026-09-04 13:53:39
(17 hours ago)
(mod_security) mod_security triggered on hostname [redacted] 34.65.109.148 (CH/Switzerland/148.109.6 ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.65.109.148 (CH/Switzerland/148.109.65.34.bc.googleusercontent.com)
show less
SQL Injection
🇫🇷
COMAITE
2026-09-04 12:57:05
(18 hours ago)
Suspicious URL access.
Web App Attack
🇺🇦
Olexiy Backend
2026-09-04 12:55:16
(18 hours ago)
34.65.109.148
...
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 12:52:48
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.65.109.148 (148.109.65.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.65.109.148 (148.109.65.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 08:52:43.474422 2026] [security2:error] [pid 31292:tid 31354] [client 34.65.109.148:51764] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "metaphysicalinstitute.com.aafm.us"] [uri "/.env"] [unique_id "apq_G790LOuTT4ybG6cRTwAAAcU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 12:20:50
(18 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.65.109.148 (148.109.65.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.65.109.148 (148.109.65.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 08:20:42.890481 2026] [security2:error] [pid 26375:tid 26375] [client 34.65.109.148:57662] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mimrg.net|F|2"] [data ".env.old"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mimrg.net"] [uri "/.env.old"] [unique_id "apq3mjmEw2tGV7MPC6kgCQAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 11:17:15
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.65.109.148 (148.109.65.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.65.109.148 (148.109.65.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 07:17:11.650973 2026] [security2:error] [pid 10543:tid 10543] [client 34.65.109.148:34940] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.jaspercity.com"] [uri "/.env.old"] [unique_id "apqotzAgmdU9l6IQDrqjpgAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
WeCloudit-Anti-Abuse
2026-09-04 10:42:55
(20 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-04 10:34:04
(20 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.65.109.148 (148.109.65.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.65.109.148 (148.109.65.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 06:33:57.486273 2026] [security2:error] [pid 10220:tid 10220] [client 34.65.109.148:51796] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "alknetsocom.alknetso.name"] [uri "/.env.old"] [unique_id "apqeldKJ0B0rAP9LWcKregAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
XICTRON
2026-09-04 10:30:04
(20 hours ago)
ModSecurity rule violation detected by Fail2Ban
Web App Attack
🇩🇪
filstal.org
2026-09-04 10:07:02
(21 hours ago)
Web reconnaissance detected: automated probing for sensitive files, backup archives, admin panels an ...
show more
Web reconnaissance detected: automated probing for sensitive files, backup archives, admin panels and known vulnerability paths.
show less
Hacking
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 10:01:01
(21 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.65.109.148 (148.109.65.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.65.109.148 (148.109.65.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 06:00:53.038043 2026] [security2:error] [pid 29872:tid 29872] [client 34.65.109.148:35650] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.musicrolls.com"] [uri "/.env.local"] [unique_id "apqW1XQVKNW9ndD6sscW4gAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack