🇺🇸
TPI-Abuse
2026-08-29 02:22:16
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.73.18.218 (218.18.73.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.73.18.218 (218.18.73.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 22:22:08.235769 2026] [security2:error] [pid 32069:tid 32069] [client 34.73.18.218:42770] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "htaautosales.com"] [uri "/.env.old"] [unique_id "apJCUAKTNLf2Xkjssc8bPQAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
JLKnoch Software GmbH
2026-08-29 01:57:45
(14 hours ago)
CrowdSec crowdsecurity/http-probing
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-08-29 01:49:55
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.73.18.218 (218.18.73.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.73.18.218 (218.18.73.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 21:49:50.189467 2026] [security2:error] [pid 13398:tid 13398] [client 34.73.18.218:58784] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.gotomywebmail.com.globalweb123.com"] [uri "/.env.dev"] [unique_id "apI6vvuIbsh7Bnd5tLATCgAAACQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
WeCloudit-Anti-Abuse
2026-08-29 01:12:02
(14 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-08-29 01:08:46
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.73.18.218 (218.18.73.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.73.18.218 (218.18.73.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 21:08:38.643178 2026] [security2:error] [pid 8911:tid 8911] [client 34.73.18.218:41756] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "taekwondoit.com"] [uri "/.env.backup"] [unique_id "apIxFpceCpMDs27G1-dMRAAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇪🇸
alferez
2026-08-29 00:53:23
(15 hours ago)
Searching .(env|sql|zip|tar|rar) files
Hacking
Exploited Host
Web App Attack
🇩🇰
Leif Neland
2026-08-29 00:00:29
(16 hours ago)
Detected by CrowdSec on slim
Brute-Force
🇩🇪
FeG Deutschland
2026-08-28 23:44:27
(16 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
🇺🇸
TPI-Abuse
2026-08-28 23:18:15
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.73.18.218 (218.18.73.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.73.18.218 (218.18.73.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 19:18:09.280539 2026] [security2:error] [pid 10129:tid 10129] [client 34.73.18.218:58590] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.evomedicals.com"] [uri "/.env.local"] [unique_id "apIXMQAfjwrCgnvQ1ixwdgAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-28 22:23:24
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.73.18.218 (218.18.73.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.73.18.218 (218.18.73.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 18:23:19.522532 2026] [security2:error] [pid 26157:tid 26157] [client 34.73.18.218:48542] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "phillurie.com"] [uri "/.env.save"] [unique_id "apIKV_vLYRl5Dc_4L27aXQAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-28 21:01:38
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.73.18.218 (218.18.73.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.73.18.218 (218.18.73.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 17:01:31.704872 2026] [security2:error] [pid 31905:tid 31905] [client 34.73.18.218:49576] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "fvsllc.com"] [uri "/.env.dev"] [unique_id "apH3KyDAi1mz1xALcmudtQAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇧🇷
Halux
2026-08-28 20:20:56
(19 hours ago)
34.73.18.218 Probing protected path or service
Web App Attack
🇺🇸
TPI-Abuse
2026-08-28 19:51:55
(20 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.73.18.218 (218.18.73.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.73.18.218 (218.18.73.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 15:51:51.025361 2026] [security2:error] [pid 18730:tid 18730] [client 34.73.18.218:50394] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "relayer.net"] [uri "/.env.old"] [unique_id "apHm1zHwy1jXMJaejnxwJwAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇸🇪
vaia.cloud
2026-08-28 19:50:03
(20 hours ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
Anonymous
2026-08-28 18:36:08
(21 hours ago)
CrowdSec: crowdsecurity/crowdsec-appsec-outofband
Hacking
Web App Attack