🇬🇧
Aetherweb Ark
2026-09-07 10:01:00
(1 hour ago)
(mod_security) mod_security (id:949110) triggered by 34.68.245.44 (US/United States/44.245.68.34.bc. ...
show more
(mod_security) mod_security (id:949110) triggered by 34.68.245.44 (US/United States/44.245.68.34.bc.googleusercontent.com): N in the last X secs
show less
Web App Attack
🇧🇪
cmbplf
2026-09-07 09:42:58
(1 hour ago)
219 requests with url.path *.azure/*
Brute-Force
Bad Web Bot
🇬🇧
OptimusGO
2026-09-07 09:29:00
(1 hour ago)
Malicious activity detected: web_attack
Server: commstackbc (185.127.18.66)
Attack: web_attack
Time ...
show more
Malicious activity detected: web_attack
Server: commstackbc (185.127.18.66)
Attack: web_attack
Timestamp: 2026-09-07 10:29:00 UTC
Log evidence:
34.68.245.44 - - [07/Sep/2026:10:28:50 +0100] "GET / HTTP/1.1" 403 180 "-" "Mozilla/5.0 (Linux; Android 12; Pixel 6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/114.0.0.0 Mobile Safari/537.36"
09/07/2026-10:28:59.845219 [wDrop] [**] [1:7000500:1] FINSERV CRITICAL: Aggressive Port Scan [**] [Classification: Attempted Information Leak] [Priority: 2] {TCP} 34.68.245.44:15290 -> 185.127.18.66:443
09/07/2026-10:28:59.845219 [**] [1:9000060:2] AUTONOMOUS Long-term Reconnaissance [**] [Classification: (null)] [Priority: 2] {TCP} 34.68.245.44:15290 -> 185.127.18.66:443
show less
Port Scan
Brute-Force
🇺🇸
TPI-Abuse
2026-09-07 09:12:50
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.68.245.44 (44.245.68.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.68.245.44 (44.245.68.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 05:12:46.760261 2026] [security2:error] [pid 8798:tid 8798] [client 34.68.245.44:62082] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mantality.onlyincanada-eh.com"] [uri "/@fs/../../.env"] [unique_id "ap6ADlcvVdzsyQhBsJTlKQAAAC0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
polarolouis
2026-09-07 09:03:36
(2 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-path-traversal-probing
Web App Attack
Hacking
🇸🇪
vaia.cloud
2026-09-07 08:46:42
(2 hours ago)
crowdsecurity/http-probing
Brute-Force
Web App Attack
Anonymous
2026-09-07 08:40:27
(2 hours ago)
Aggressive web scan
Web App Attack
🇺🇸
masterguru
2026-09-07 08:39:29
(2 hours ago)
BAD BOT - Detected and Blocked.. Matched phrase "PerplexityBot" at REQUEST_HEADERS:User-Agent. (1100 ...
show more
BAD BOT - Detected and Blocked.. Matched phrase "PerplexityBot" at REQUEST_HEADERS:User-Agent. (1100000-169)
show less
Bad Web Bot
🇩🇪
FeG Deutschland
2026-09-07 08:31:45
(2 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 1247
Exploited Host
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 08:24:08
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.68.245.44 (44.245.68.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.68.245.44 (44.245.68.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 04:24:02.834504 2026] [security2:error] [pid 25442:tid 25442] [client 34.68.245.44:17356] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.jimcameron.com"] [uri "/@fs/../../.env"] [unique_id "ap50ohuVyoahrwa1ZU0Q8QAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
LRob
2026-09-07 08:16:27
(3 hours ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /@fs/.env (+12 more) | 2026-09-07 08:16 UTC
show less
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 08:06:09
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.68.245.44 (44.245.68.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.68.245.44 (44.245.68.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 04:06:03.045012 2026] [security2:error] [pid 26236:tid 26236] [client 34.68.245.44:48842] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "derekvantreese.com"] [uri "/@fs/.env"] [unique_id "ap5wawoETh9fnXPxlUYA2gAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 07:33:07
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.68.245.44 (44.245.68.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.68.245.44 (44.245.68.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 03:33:00.984472 2026] [security2:error] [pid 2926:tid 2926] [client 34.68.245.44:55296] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.indoorsfinishing.com"] [uri "/@fs/app/.env"] [unique_id "ap5orLg_N3-Gc28nHVeyLQAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
dpsbs
2026-09-07 05:59:57
(5 hours ago)
multiple ips intrustions detected
Hacking
Anonymous
2026-09-07 05:45:31
(5 hours ago)
Web application attack detected.
Web App Attack