🇫🇮
mnazibo
2026-09-05 08:00:05
(9 hours ago)
Date: 05/Sep/2026 10:16:10 | Reported IP: 34.65.176.17 mod_security | id: 930130 | CH/group.my_domai ...
show more
Date: 05/Sep/2026 10:16:10 | Reported IP: 34.65.176.17 mod_security | id: 930130 | CH/group.my_domain/- | Connections: 19 | Blocked: Permanent Block: [LF_MODSEC] | URIs: /; /%2eenv; /.env; /.env.; /.env/; //.env; /.ENV; /.env.backup; /.env.bak; /.env.dev; /.env.example; /.env.local; /.env.old; /.env.prod; /.env.production; /.env.save; /wp-config.php~; /wp-config.php.bak; /wp-config.php.swp | Logs: Restricted File Access Attempt
show less
SQL Injection
Brute-Force
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-04 15:23:16
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.65.176.17 (17.176.65.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.65.176.17 (17.176.65.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 11:23:11.501087 2026] [security2:error] [pid 20626:tid 20626] [client 34.65.176.17:37844] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.hardcountryrock.com"] [uri "/.env.local"] [unique_id "apriX3bx6hVjil0s8yuvqgAAAE8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 14:05:50
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.65.176.17 (17.176.65.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.65.176.17 (17.176.65.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 10:05:44.441532 2026] [security2:error] [pid 20827:tid 20827] [client 34.65.176.17:57580] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.jeannieksmith.com"] [uri "/.env"] [unique_id "aprQOEaO1PabhHWIJAz_mwAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
Vegascosmetics
2026-09-04 13:43:37
(1 day ago)
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after matched multi-pattern attack signatur ...
show more
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after matched multi-pattern attack signature. Evidence: AttackPattern: laravel\.log (Match: laravel.log)
show less
Hacking
Web App Attack
🇩🇪
raph
2026-09-04 13:04:12
(1 day ago)
[Wordpress] crawler /wp-admin/*, /wp-content/*, etc.
Bad Web Bot
Web App Attack
🇫🇷
dwmp
2026-09-04 12:48:35
(1 day ago)
Url probing: /.env.save
Web App Attack
🇳🇱
WeCloudit-Anti-Abuse
2026-09-04 12:29:29
(1 day ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
🇩🇪
FeG Deutschland
2026-09-04 12:18:41
(1 day ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
🇳🇱
e.fierstra
2026-09-04 12:04:58
(1 day ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 11:43:03
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.65.176.17 (17.176.65.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.65.176.17 (17.176.65.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 07:42:59.597201 2026] [security2:error] [pid 28402:tid 28402] [client 34.65.176.17:49296] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.mainescentsecrets.com"] [uri "/.env.dev"] [unique_id "apquwwCVr5_b7cDbihgPTQAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 10:07:17
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.65.176.17 (17.176.65.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.65.176.17 (17.176.65.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 06:07:13.372837 2026] [security2:error] [pid 9128:tid 9128] [client 34.65.176.17:40104] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kennedysplace.com"] [uri "/.env.bak"] [unique_id "apqYUXN3axes1vVduo4f6wAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇨🇦
polycoda
2026-09-04 09:36:59
(1 day ago)
AutoBlock: 🎯 Vulnerability Scanner (Non Decay-Based) - ⚙️ Configuration File Access (Non Decay-Based ...
show more
AutoBlock: 🎯 Vulnerability Scanner (Non Decay-Based) - ⚙️ Configuration File Access (Non Decay-Based)
show less
Hacking
Web App Attack
🇵🇱
lns.bz
2026-09-04 09:22:50
(1 day ago)
Too many 404 requests [BY]
Web App Attack
🇬🇧
Aetherweb Ark
2026-09-04 09:22:46
(1 day ago)
(mod_security) mod_security (id:949110) triggered by 34.65.176.17 (CH/Switzerland/17.176.65.34.bc.go ...
show more
(mod_security) mod_security (id:949110) triggered by 34.65.176.17 (CH/Switzerland/17.176.65.34.bc.googleusercontent.com): N in the last X secs
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 08:40:31
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.65.176.17 (17.176.65.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.65.176.17 (17.176.65.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 04:40:27.396986 2026] [security2:error] [pid 20737:tid 20737] [client 34.65.176.17:47840] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "register-yacht-seychelles.com"] [uri "/.env.local"] [unique_id "apqD-0qaesIuhugbjHJPPAAAAH4"]
show less
Brute-Force
Bad Web Bot
Web App Attack