🇩🇪
FD-IX
2026-09-04 14:14:23
(17 hours ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 14:06:58
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.65.79.209 (209.79.65.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.65.79.209 (209.79.65.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 10:06:51.992259 2026] [security2:error] [pid 26506:tid 26506] [client 34.65.79.209:37474] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.orientaltd.com"] [uri "/.env.bak"] [unique_id "aprQe2ThAM7v9FgGq_LnIgAAAIE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
Jimbo67
2026-09-04 13:29:48
(18 hours ago)
Cloudflare WAF: 1 hits in 30s | action=block | abuse=confirmed_abuse | categories=21 | rule_id=3329c ...
show more
Cloudflare WAF: 1 hits in 30s | action=block | abuse=confirmed_abuse | categories=21 | rule_id=3329c9d804134f3e89780d69bfd872dc | URIs=/.env.save | confidence=0.95
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 11:17:29
(20 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.65.79.209 (209.79.65.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.65.79.209 (209.79.65.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 07:17:25.340651 2026] [security2:error] [pid 16381:tid 16381] [client 34.65.79.209:54222] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.abq4you.com"] [uri "/wp-config.php~"] [unique_id "apqoxRj-g7ZPQ8tWrhqxewAAADo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
paissangroup
2026-09-04 10:48:02
(20 hours ago)
Multiple WAF Violations
Web App Attack
🇺🇸
brightenfield
2026-09-04 10:42:51
(20 hours ago)
Web App Attack
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 10:31:52
(21 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.65.79.209 (209.79.65.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.65.79.209 (209.79.65.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 06:31:43.793618 2026] [security2:error] [pid 26767:tid 26767] [client 34.65.79.209:60370] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "iamnotguilty.anthonyjoseph.us"] [uri "/wp-config.php.bak"] [unique_id "apqeD2rpUk72sn9KBNvcLAAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
CBJ
2026-09-04 10:17:44
(21 hours ago)
fail2ban: apache-filepath-recon
...
Web App Attack
🇩🇪
Petros Stefanakis
2026-09-04 09:36:46
(21 hours ago)
(mod_security) mod_security triggered on hostname [redacted] 34.65.79.209 (CH/Switzerland/209.79.65. ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.65.79.209 (CH/Switzerland/209.79.65.34.bc.googleusercontent.com)
show less
SQL Injection
🇮🇹
CoreTech srl
2026-09-04 08:58:51
(22 hours ago)
cloudlinux2 fail2ban: 2026-09-04 10:54:18,201 fail2ban.filter [1594]: INFO [plesk-modsecu ...
show more
cloudlinux2 fail2ban: 2026-09-04 10:54:18,201 fail2ban.filter [1594]: INFO [plesk-modsecurity] Found 169.40.142.190 - 2026-09-04 10:54:18cloudlinux2 fail2ban: 2026-09-04 10:54:17,887 fail2ban.filter [1594]: INFO [plesk-modsecurity] Found 169.40.142.190 - 2026-09-04 10:54:17cloudlinux2 fail2ban: 2026-09-04 10:54:35,104 fail2ban.actions [1594]: NOTICE [plesk-modsecurity] Unban 34.65.133.249cloudlinux2 fail2ban: 2026-09-04 10:54:54,151 fail2ban.filter [1594]: INFO [plesk-modsecurity] Found 34.75.79.195 - 2026-09-04 10:54:54cloudlinux2 fail2ban: 2026-09-04 10:55:11,820 fail2ban.filter [1594]: INFO [plesk-modsecurity] Found 34.65.79.209 - 2026-09-04 10:55:11cloudlinux2 fail2ban: 2026-09-04 10:55:11,780 fail2ban.filter [1594]: INFO [plesk-modsecurity] Found 34.65.79.209 - 2026-09-04 10:55:11cloudlinux2 fail2ban: 2026-09-04 10:55:11,796 fail2ban.filter [1594]: INFO [plesk-modsecurity] Found 34.65.79.209 - 2026-09-04 10:55:11cloudlinux2 fail2ba
show less
Brute-Force
🇦🇺
paulshipley.com.au
2026-09-04 08:45:28
(22 hours ago)
[Fri Sep 04 18:45:27.760240 2026] [security2:error] [pid 639620] [client 34.65.79.209:46068] [client ...
show more
[Fri Sep 04 18:45:27.760240 2026] [security2:error] [pid 639620] [client 34.65.79.209:46068] [client 34.65.79.209] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/modsecurity/crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "rjryanpartners.com.au"] [uri "/.env.production"] [unique_id "apqFJzTWQMlbQRsz5lIRbAAAAAM"]
...
show less
Web App Attack
🇳🇱
sernate
2026-09-04 08:39:34
(22 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.65.79.209 (CH/Switzerland/209.79.65.34.bc.go ...
show more
(mod_security) mod_security (id:210492) triggered by 34.65.79.209 (CH/Switzerland/209.79.65.34.bc.googleusercontent.com): 10 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_MODSEC
show less
Brute-Force
🇧🇾
lns.bz
2026-09-04 08:38:14
(22 hours ago)
Too many 404 requests [BY]
Web App Attack
🇸🇪
vaia.cloud
2026-09-04 08:35:01
(22 hours ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
🇳🇱
WeCloudit-Anti-Abuse
2026-09-04 07:42:45
(23 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking