🇩🇪
FD-IX
2026-09-08 07:23:09
(1 hour ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
🇳🇱
WeCloudit-Anti-Abuse
2026-09-08 06:30:02
(2 hours ago)
SPAM - Bruteforce Attack - DDOS 2
Email Spam
Brute-Force
🇳🇱
WeCloudit-Anti-Abuse
2026-09-08 06:04:03
(3 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
🇱🇻
garmtech.com
2026-09-08 03:59:44
(5 hours ago)
Attempted access to sensitive endpoint (/.env.old) detected. Automated scan or unauthorized probing.
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 02:32:20
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.80.105.252 (252.105.80.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.80.105.252 (252.105.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 22:32:12.793296 2026] [security2:error] [pid 1188:tid 1188] [client 34.80.105.252:53416] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.keystonestandard.com"] [uri "/.env.bak"] [unique_id "ap9zrJIpqvutICq0AMUaQQAAAB8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
homeshowdomain.nl
2026-09-06 22:01:49
(1 day ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-09-05.
show less
Web App Attack
SSH
Hacking
🇺🇸
TPI-Abuse
2026-09-06 03:39:10
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.80.105.252 (252.105.80.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.80.105.252 (252.105.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 23:39:02.465900 2026] [security2:error] [pid 28946:tid 28949] [client 34.80.105.252:33890] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "leadingedgesupply.com"] [uri "/.env.save"] [unique_id "apzgVsiKLOccEIT5yWoQ7wAAAQA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
masterguru
2026-09-06 03:36:39
(2 days ago)
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 34.80.105.252 (TW/Taiwan/252.105.80.3 ...
show more
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 34.80.105.252 (TW/Taiwan/252.105.80.34.bc.googleusercontent.com): 2 in the last 3600 secs (0-196)
show less
Hacking
🇺🇸
TPI-Abuse
2026-09-06 01:58:48
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.80.105.252 (252.105.80.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.80.105.252 (252.105.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 21:58:42.178766 2026] [security2:error] [pid 19724:tid 19724] [client 34.80.105.252:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mep.cloudex.click"] [uri "/.env.dev"] [unique_id "apzI0la9snO-E_s6_GJeKAAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
e.fierstra
2026-09-06 01:02:16
(2 days ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 00:54:21
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.80.105.252 (252.105.80.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.80.105.252 (252.105.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 20:54:15.384196 2026] [security2:error] [pid 31747:tid 31747] [client 34.80.105.252:34240] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "evtoy.danged.com"] [uri "/wp-config.php.bak"] [unique_id "apy5t0ElOoZB_2bcy2INkQAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
FeG Deutschland
2026-09-05 23:57:26
(2 days ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 22:59:29
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.80.105.252 (252.105.80.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.80.105.252 (252.105.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 18:59:24.127391 2026] [security2:error] [pid 29571:tid 29571] [client 34.80.105.252:33350] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.beckersystems.net"] [uri "/.env"] [unique_id "apyezBYu28mCQHDfUhJ2sAAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-05 22:58:14
(2 days ago)
(config_exploit_scan) Configuratie Scanner / Nep GPTBot 34.80.105.252 (TW/Taiwan/252.105.80.34.bc.go ...
show more
(config_exploit_scan) Configuratie Scanner / Nep GPTBot 34.80.105.252 (TW/Taiwan/252.105.80.34.bc.googleusercontent.com): 3 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 34.80.105.252 - - [06/Sep/2026:00:58:09 +0200] "GET /.env.production HTTP/1.1" 406 4829 "-" "crusader-worker/1.0"
34.80.105.252 - - [06/Sep/2026:00:58:09 +0200] "GET /.env.prod HTTP/1.1" 406 4829 "-" "crusader-worker/1.0"
34.80.105.252 - - [06/Sep/2026:00:58:09 +0200] "GET /.env.backup HTTP/1.1" 406 4829 "-" "crusader-worker/1.0"
show less
Port Scan
🇺🇸
TPI-Abuse
2026-09-05 22:43:38
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.80.105.252 (252.105.80.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.80.105.252 (252.105.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 18:43:34.094512 2026] [security2:error] [pid 20988:tid 20988] [client 34.80.105.252:59708] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "hdestimating.com"] [uri "/.env.dev"] [unique_id "apybFtxAlD6MGAGPx4IBzQAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack