🇮🇪
AutosOnShow
2026-09-06 06:25:07
(13 hours ago)
blocked for webapp attack | path requested: / | seen at 2026-09-06 06:24:17.189 |
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 03:52:28
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.74.126.82 (82.126.74.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.74.126.82 (82.126.74.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 23:52:22.024824 2026] [security2:error] [pid 29015:tid 29015] [client 34.74.126.82:43250] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.robtown.com"] [uri "/.env"] [unique_id "apzjdh1sf8BWLLB57aL8vAAAAJE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 03:35:20
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.74.126.82 (82.126.74.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.74.126.82 (82.126.74.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 23:35:17.430160 2026] [security2:error] [pid 25061:tid 25061] [client 34.74.126.82:59522] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "pintoresdecasascdmx.com.spyasociados.com"] [uri "/.env.save"] [unique_id "apzfdZs8SGdDYI7B3gehGwAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
raph
2026-09-06 03:03:38
(16 hours ago)
[DOT FILES] crawler *.env*, .git*, .config*, etc.
Bad Web Bot
Web App Attack
🇬🇧
gws-hostmaster
2026-09-06 02:43:51
(17 hours ago)
ModSecurity OWASP CRS (Anomaly Score: 10): Attempt to access a backup or working file;Restricted Fil ...
show more
ModSecurity OWASP CRS (Anomaly Score: 10): Attempt to access a backup or working file;Restricted File Access Attempt;URL file extension is restricted by policy;
show less
Web App Attack
🇳🇱
BlueWire Hosting
2026-09-06 02:42:24
(17 hours ago)
High-confidence malicious configuration/VCS probe
Web App Attack
🇬🇧
consul.to
2026-09-06 02:34:42
(17 hours ago)
Web attack/malicious scanning detected
Web App Attack
🇫🇷
masterguru
2026-09-06 02:29:34
(17 hours ago)
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 34.74.126.82 (US/United States/82.126 ...
show more
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 34.74.126.82 (US/United States/82.126.74.34.bc.googleusercontent.com): 2 in the last 3600 secs (0-196)
show less
Hacking
🇺🇸
TPI-Abuse
2026-09-06 01:34:37
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.74.126.82 (82.126.74.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.74.126.82 (82.126.74.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 21:34:32.518679 2026] [security2:error] [pid 27919:tid 27919] [client 34.74.126.82:50712] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "morefrogs.com"] [uri "/wp-config.php.bak"] [unique_id "apzDKAjCQJQECN1PTHzFPwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
verlon
2026-09-06 01:19:28
(18 hours ago)
2026/09/06 03:19:25 [error] 1095190#1095190: *392176 access forbidden by rule, client: 34.74.126.82, ...
show more
2026/09/06 03:19:25 [error] 1095190#1095190: *392176 access forbidden by rule, client: 34.74.126.82, server: suitandmore.hu, request: "GET /.env.bak HTTP/2.0", host: "suitandmore.hu"
2026/09/06 03:19:25 [error] 1095191#1095191: *392183 access forbidden by rule, client: 34.74.126.82, server: suitandmore.hu, request: "GET /.env.save HTTP/2.0", host: "suitandmore.hu"
2026/09/06 03:19:25 [error] 1095190#1095190: *392185 access forbidden by rule, client: 34.74.126.82, server: suitandmore.hu, request: "GET /.env.old HTTP/2.0", host: "suitandmore.hu"
...
show less
Hacking
Web App Attack
🇩🇪
DEV-DNS
2026-09-06 01:11:47
(18 hours ago)
(mod_security) mod_security triggered on hostname [redacted])
SQL Injection
🇺🇸
TPI-Abuse
2026-09-06 01:09:23
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.74.126.82 (82.126.74.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.74.126.82 (82.126.74.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 21:09:17.487771 2026] [security2:error] [pid 4094055:tid 4094075] [client 34.74.126.82:39160] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.npaccountants.org"] [uri "/.env"] [unique_id "apy9Pa6cqs6FLYTdRl_KagAAAFI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 00:30:35
(19 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.74.126.82 (82.126.74.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.74.126.82 (82.126.74.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 20:30:29.116337 2026] [security2:error] [pid 20161:tid 20187] [client 34.74.126.82:49348] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||newyorkyoga.org.aafm.us|F|2"] [data ".log"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "newyorkyoga.org.aafm.us"] [uri "/storage/logs/laravel.log"] [unique_id "apy0Jc_VgwQvGGlVJ-nZkAAAAFg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
debestelapp
2026-09-06 00:20:10
(19 hours ago)
Web App Attack
🇺🇸
mnsf
2026-09-06 00:05:57
(19 hours ago)
Scanning/Probing (18)
Brute-Force
Web App Attack