🇺🇸
TPI-Abuse
2026-09-06 03:48:57
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.75.72.62 (62.72.75.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.75.72.62 (62.72.75.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 23:48:49.974083 2026] [security2:error] [pid 29083:tid 29083] [client 34.75.72.62:55364] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.cleaningsuppliescr.com"] [uri "/.env.bak"] [unique_id "apziobDXRqXhJajkcG4BnwAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
MatCat
2026-09-06 02:05:14
(4 hours ago)
Banned by fail2ban: apache-webprobe
Port Scan
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-06 01:48:38
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.75.72.62 (62.72.75.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.75.72.62 (62.72.75.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 21:48:33.349486 2026] [security2:error] [pid 21405:tid 21405] [client 34.75.72.62:50548] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "safetyfastclub.com"] [uri "/wp-config.php~"] [unique_id "apzGcQJ0FHtlA1JHK3HDGAAAAEI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
e.fierstra
2026-09-06 01:26:05
(4 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
Anonymous
2026-09-06 00:07:34
(6 hours ago)
Web App Attack
Brute-Force
Exploited Host
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 00:00:11
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.75.72.62 (62.72.75.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.75.72.62 (62.72.75.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 19:59:58.986780 2026] [security2:error] [pid 22328:tid 22328] [client 34.75.72.62:60234] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "keysenterprise.net"] [uri "/.env.local"] [unique_id "apys_jYkkML6S-exiiDjpQAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 23:06:05
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.75.72.62 (62.72.75.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.75.72.62 (62.72.75.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 19:06:00.574607 2026] [security2:error] [pid 11646:tid 11719] [client 34.75.72.62:36958] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "redesign.mdbscommercialcleaning.com"] [uri "/.env.example"] [unique_id "apygWMhY564o5wKLIwibJQAAARY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇨🇭
4server
2026-09-05 23:00:59
(7 hours ago)
[SunSep0601:00:52.4172852026][security2:error][pid2162577:tid2162944][client34.75.72.62:0]ModSecurit ...
show more
[SunSep0601:00:52.4172852026][security2:error][pid2162577:tid2162944][client34.75.72.62:0]ModSecurity:Accessdeniedwithcode403\(phase2\).Stringmatchwithin\".asa/.asax/.ascx/.backup/.bak/.bat/.cdx/.cer/.cfg/.cmd/.com/.config/.conf/.cs/.csproj/.csr/.dat/.db/.dbf/.dll/.dos/.htr/.htw/.ida/.idc/.idq/.inc/.ini/.key/.licx/.lnk/.log/.mdb/.old/.pass/.pdb/.pol/.printer/.pwd/.rdb/.resources/.resx/.sql/.swp/.sys/.vb/.vbs/.vbproj/.vsdisco/.webinfo/.xsx/\"atTX:extension.[file\"/etc/apache2/conf.d/modsec_rules/00_asl_zz_strict.conf\"][line\"91\"][id\"390716\"][rev\"2\"][msg\"Atomicorp.comWAFRules:URLfileextensionisrestrictedbypolicy\"][data\".log\"][severity\"ERROR\"][hostname\"mail.safertechnics.ch\"][uri\"/storage/logs/laravel.log\"][unique_id\"apyfJKIGWJJs6VGjR9vbnAAAAUU\"]
show less
Hacking
Web App Attack
🇫🇷
dynamix
2026-09-05 22:56:20
(7 hours ago)
Multiple WAF Violations
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 22:30:47
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.75.72.62 (62.72.75.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.75.72.62 (62.72.75.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 18:30:43.944253 2026] [security2:error] [pid 22732:tid 22732] [client 34.75.72.62:34620] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "tomorrowsdust.net.greighhouse.com"] [uri "/.env.local"] [unique_id "apyYE0IGZDP7uIAvJfXNlQAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
Marc
2026-09-05 22:11:41
(8 hours ago)
34.75.72.62 - - [06/Sep/2026:00:11:41 +0200] "GET /.env.dev HTTP/1.1" 404 4618 "-" "crusader-worker/ ...
show more
34.75.72.62 - - [06/Sep/2026:00:11:41 +0200] "GET /.env.dev HTTP/1.1" 404 4618 "-" "crusader-worker/1.0" 34.75.72.62 - - [06/Sep/2026:00:11:41 +0200] "GET /.env.local HTTP/1.1" 404 4616 "-" "crusader-worker/1.0" 34.75.72.62 - - [06/Sep/2026:00:11:41 +0200] "GET /.env.example HTTP/1.1" 404 4617 "-" "crusader-worker/1.0"
show less
Brute-Force
Anonymous
2026-09-05 22:01:06
(8 hours ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack
🇫🇷
Octopuce
2026-09-05 21:56:45
(8 hours ago)
Aggressive web search of vulnerable pages: /dump.sql /backup.tar /www.zip /web.zip /dump.tar.gz ...
Web App Attack
🇬🇧
consul.to
2026-09-05 21:42:33
(8 hours ago)
Web attack/malicious scanning detected
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 21:15:38
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.75.72.62 (62.72.75.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.75.72.62 (62.72.75.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 17:15:34.583392 2026] [security2:error] [pid 8838:tid 8838] [client 34.75.72.62:34072] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "guernsey-boat-registration.com"] [uri "/.env.bak"] [unique_id "apyGdm0Q62GX4uFqkOuFbgAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack