🇳🇱
Site.eu
2026-09-08 00:06:52
(30 minutes ago)
Excessive 404/403 errors
Brute-Force
🇫🇷
UnixPrime
2026-09-07 20:43:57
(3 hours ago)
34.75.233.61 - - [07/Sep/2026:22:43:56 +0200] "GET /.env.backup HTTP/1.1" 404 118 "-" "Mozilla/5.0 A ...
show more
34.75.233.61 - - [07/Sep/2026:22:43:56 +0200] "GET /.env.backup HTTP/1.1" 404 118 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; GrokBot/1.0; +https://x.ai/grokbot)"
34.75.233.61 - - [07/Sep/2026:22:43:56 +0200] "GET /.env.development HTTP/1.1" 404 118 "-" "Mozilla/5.0 (compatible; GrokBot/1.0; +https://x.ai/grokbot)"
...
show less
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 20:33:08
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.75.233.61 (61.233.75.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.75.233.61 (61.233.75.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 16:33:04.767933 2026] [security2:error] [pid 14234:tid 14234] [client 34.75.233.61:9538] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.ozarkmountainwinetrail.org"] [uri "/@fs/src/.env"] [unique_id "ap8fgDhKfwd1x9aF8yqcmgAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 19:50:31
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.75.233.61 (61.233.75.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.75.233.61 (61.233.75.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 15:50:25.457599 2026] [security2:error] [pid 2683:tid 2683] [client 34.75.233.61:37872] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.mysticalparadise.com"] [uri "/@fs/.env.local"] [unique_id "ap8VgYMv8mbScTh4WQdaLAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
Aetherweb Ark
2026-09-07 19:01:18
(5 hours ago)
(mod_security) mod_security (id:949110) triggered by 34.75.233.61 (US/United States/61.233.75.34.bc. ...
show more
(mod_security) mod_security (id:949110) triggered by 34.75.233.61 (US/United States/61.233.75.34.bc.googleusercontent.com): N in the last X secs
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 18:20:26
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.75.233.61 (61.233.75.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.75.233.61 (61.233.75.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 14:20:19.026239 2026] [security2:error] [pid 32169:tid 32169] [client 34.75.233.61:19332] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.qosmexico.com"] [uri "/@fs/.env.production"] [unique_id "ap8AYynaaZnig37eJIB4rAAAACQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 17:03:46
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.75.233.61 (61.233.75.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.75.233.61 (61.233.75.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 13:03:39.137730 2026] [security2:error] [pid 6956:tid 6956] [client 34.75.233.61:8738] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.surveyiowa.com"] [uri "/@fs/.env.development"] [unique_id "ap7ua7UVJTZ1i4HYvsSGFAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 16:37:54
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.75.233.61 (61.233.75.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.75.233.61 (61.233.75.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 12:37:48.278557 2026] [security2:error] [pid 27323:tid 27323] [client 34.75.233.61:62212] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.groomattheinn.com"] [uri "/@fs/.env"] [unique_id "ap7oXIJLbcyNmRmJFtBDYQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇮🇹
CoreTech srl
2026-09-07 16:28:12
(8 hours ago)
CloudLinux/Plesk alert - host=cloudlinux dominio=mitan.it ip=34.75.233.61 richieste=225 rischio=ALTO ...
show more
CloudLinux/Plesk alert - host=cloudlinux dominio=mitan.it ip=34.75.233.61 richieste=225 rischio=ALTO score=19 motivi=molte_richieste,molte_uri_uniche,molti_404,ua_script_bot,path_sospetti,poco_statico,dinamico cat_id=21,19 periodo=10min
show less
Web App Attack
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-07 16:07:33
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.75.233.61 (61.233.75.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.75.233.61 (61.233.75.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 12:07:27.295659 2026] [security2:error] [pid 3392:tid 3392] [client 34.75.233.61:7448] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.gacstoday.com"] [uri "/@fs/.env.local"] [unique_id "ap7hPz7zP6LiVR2wrG1FBgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇮🇹
VHosting
2026-09-07 16:05:03
(8 hours ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
🇩🇪
Hazzard
2026-09-07 15:52:22
(8 hours ago)
(mod_security) mod_security triggered on hostname [redacted]): (CF_ENABLE)
SQL Injection
🇸🇪
vaia.cloud
2026-09-07 15:45:02
(8 hours ago)
crowdsecurity/http-path-traversal-probing
Brute-Force
Web App Attack