🇺🇸
TPI-Abuse
2026-09-06 03:54:29
(53 minutes ago)
(mod_security) mod_security (id:210492) triggered by 34.65.172.186 (186.172.65.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.65.172.186 (186.172.65.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 23:54:25.085424 2026] [security2:error] [pid 31699:tid 31699] [client 34.65.172.186:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.portfoliolighting.net"] [uri "/.ENV"] [unique_id "apzj8YBUptaDxA7TPf7qxgAAAGw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 02:58:03
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.65.172.186 (186.172.65.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.65.172.186 (186.172.65.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 22:57:56.129292 2026] [security2:error] [pid 7077:tid 7077] [client 34.65.172.186:59532] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.styxwetworld.com"] [uri "/.env.local"] [unique_id "apzWtMiGnDLgh_3BKRicpQAAAEY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
dynamix
2026-09-06 01:36:05
(3 hours ago)
Multiple WAF Violations
Web App Attack
🇫🇷
Catalin Negru
2026-09-06 01:32:13
(3 hours ago)
Recidive ban by fail2ban on server.blackbit.ro
Brute-Force
🇫🇷
✨
2026-09-06 01:12:10
(3 hours ago)
Domain : londonriversideconferencing.com
Rule : env
2026-09-06 01:10:58 ***hidden-privacy***46 GET / ...
show more
Domain : londonriversideconferencing.com
Rule : env
2026-09-06 01:10:58 ***hidden-privacy***46 GET /.env.bak - 80 - 34.65.172.186 HTTP/1.1 crusader-worker/1.0 - londonriversideconferencing.com 404 0 2 1527 111 320 - -
show less
Hacking
SQL Injection
🇬🇧
consul.to
2026-09-06 00:38:18
(4 hours ago)
Web attack/malicious scanning detected
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 00:37:14
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.65.172.186 (186.172.65.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.65.172.186 (186.172.65.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 20:37:07.765727 2026] [security2:error] [pid 18226:tid 18226] [client 34.65.172.186:56954] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "hmdinc.harintonmechanical.com"] [uri "/.env.local"] [unique_id "apy1s-BZAZjyYQjBk6CBhgAAACo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
Philister11
2026-09-06 00:08:47
(4 hours ago)
CrowdSec: crowdsecurity/http-probing (CH/AS396982)
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-06 00:07:43
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.65.172.186 (186.172.65.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.65.172.186 (186.172.65.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 20:07:38.775435 2026] [security2:error] [pid 21700:tid 21700] [client 34.65.172.186:52588] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "pearson-specter.com"] [uri "/.env.prod"] [unique_id "apyuym7QT_vz0dz14JBVJQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 23:28:44
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.65.172.186 (186.172.65.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.65.172.186 (186.172.65.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 19:28:40.563678 2026] [security2:error] [pid 29513:tid 29513] [client 34.65.172.186:33672] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htaccess" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.consorciolegal.com"] [uri "/.htaccess"] [unique_id "apylqJFQ0Qc5l2kN0RJ6iQAAAHM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
FD-IX
2026-09-05 22:38:56
(6 hours ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 22:37:33
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.65.172.186 (186.172.65.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.65.172.186 (186.172.65.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 18:37:29.907385 2026] [security2:error] [pid 18237:tid 18237] [client 34.65.172.186:35130] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ftp.ostarek.com"] [uri "/.env"] [unique_id "apyZqdATakqdBESYoE-FGgAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-05 21:04:46
(7 hours ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-05 20:32:05
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.65.172.186 (186.172.65.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.65.172.186 (186.172.65.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 16:31:58.391776 2026] [security2:error] [pid 4144:tid 4144] [client 34.65.172.186:60046] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ftp.superzilla.com"] [uri "/.env.bak"] [unique_id "apx8PiLNRIOtlWkB4MgYYQAAACw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-05 20:17:29
(8 hours ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack