🇺🇸
TPI-Abuse
2026-09-04 15:20:00
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.65.208.106 (106.208.65.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.65.208.106 (106.208.65.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 11:19:51.709292 2026] [security2:error] [pid 29289:tid 29289] [client 34.65.208.106:58770] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.brianwhitty.com"] [uri "/.env.old"] [unique_id "aprhlwS6C_BU9AQbJeUZ1gAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
MyGlobalFlowers
2026-09-04 15:00:12
(12 hours ago)
Multiple WAF Violations
Web App Attack
🇦🇺
nzhost.co.nz
2026-09-04 14:15:12
(13 hours ago)
$f2bV_matches
Hacking
Brute-Force
🇩🇪
FD-IX
2026-09-04 12:56:58
(14 hours ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 12:53:42
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.65.208.106 (106.208.65.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.65.208.106 (106.208.65.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 08:53:39.195168 2026] [security2:error] [pid 27495:tid 27495] [client 34.65.208.106:52554] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mgiexperience.digitalracemedia.com"] [uri "/.env"] [unique_id "apq_U4QZw5klu4mXO78HAQAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇨🇭
Ribeye375
2026-09-04 12:49:29
(14 hours ago)
HIPS web-exfiltration - Block tcp/0:65535
Web App Attack
Anonymous
2026-09-04 12:26:04
(15 hours ago)
Bot / scanning and/or hacking attempts: GET /env HTTP/1.1, GET /.env.old HTTP/1.1, GET /wp-config.ph ...
show more
Bot / scanning and/or hacking attempts: GET /env HTTP/1.1, GET /.env.old HTTP/1.1, GET /wp-config.php.swp HTTP/1.1, GET /.env.example HTTP/1.1, GET /_ignition/health-check HTTP/1.1, GET /.env.save HTTP/1.1, GET /.env.prod HTTP/1.1, GET /.env.backup HTTP/1.1, GET /wp-config.php~ HTTP/1.1, GET /.env.dev HTTP/1.1, GET /crusader-404-probe HTTP/1.1, GET /actuator/env HTTP/1.1
show less
Hacking
Web App Attack
🇨🇦
Anytech
2026-09-04 12:16:31
(15 hours ago)
Blocked by Conn-Monitor: env-probing
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-04 12:12:19
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.65.208.106 (106.208.65.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.65.208.106 (106.208.65.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 08:12:14.881564 2026] [security2:error] [pid 24082:tid 24082] [client 34.65.208.106:42898] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "faeriespringsfarm.com"] [uri "/wp-config.php.swp"] [unique_id "apq1noPFqYz8qQpDDt1aDgAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 11:44:55
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.65.208.106 (106.208.65.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.65.208.106 (106.208.65.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 07:44:48.798875 2026] [security2:error] [pid 19027:tid 19027] [client 34.65.208.106:34630] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.grieve.tv"] [uri "/wp-config.php.bak"] [unique_id "apqvMIzjTzuc4eDZrO4AfAAAAD0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
dom4k
2026-09-04 11:18:32
(16 hours ago)
34.65.208.106 - - [04/Sep/2026:11:18:31 +0000] "GET /.env HTTP/1.1" 444 0 "-" "crusader-worker/1.0"
...
show more
34.65.208.106 - - [04/Sep/2026:11:18:31 +0000] "GET /.env HTTP/1.1" 444 0 "-" "crusader-worker/1.0"
...
show less
Web Spam
Bad Web Bot
Web App Attack
Anonymous
2026-09-04 11:04:10
(16 hours ago)
(mod_security) mod_security triggered on hostname [redacted])
SQL Injection
🇺🇸
TPI-Abuse
2026-09-04 10:08:49
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.65.208.106 (106.208.65.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.65.208.106 (106.208.65.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 06:08:44.217294 2026] [security2:error] [pid 23854:tid 23854] [client 34.65.208.106:43660] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jimgrenier.com"] [uri "/.env.local"] [unique_id "apqYrHdfFxd-Ufeu6HbNpQAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-04 09:35:30
(18 hours ago)
(config_exploit_scan) Configuratie Scanner / Nep GPTBot 34.65.208.106 (CH/Switzerland/106.208.65.34. ...
show more
(config_exploit_scan) Configuratie Scanner / Nep GPTBot 34.65.208.106 (CH/Switzerland/106.208.65.34.bc.googleusercontent.com): 3 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 34.65.208.106 - - [04/Sep/2026:11:35:25 +0200] "GET /.env.local HTTP/1.1" 406 4830 "-" "crusader-worker/1.0"
34.65.208.106 - - [04/Sep/2026:11:35:25 +0200] "GET /.env.production HTTP/1.1" 406 4831 "-" "crusader-worker/1.0"
34.65.208.106 - - [04/Sep/2026:11:35:25 +0200] "GET /.env.old HTTP/1.1" 406 4832 "-" "crusader-worker/1.0"
show less
Port Scan
🇫🇷
dynamix
2026-09-04 08:25:04
(19 hours ago)
Multiple WAF Violations
Web App Attack