🇺🇸
TPI-Abuse
2026-09-04 15:17:23
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.81.68.190 (190.68.81.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.81.68.190 (190.68.81.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 11:17:19.453267 2026] [security2:error] [pid 22273:tid 22273] [client 34.81.68.190:51684] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.integritysecurity.net"] [uri "/.env.local"] [unique_id "aprg_3bAk30GfvzirkBGPwAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 14:10:05
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.81.68.190 (190.68.81.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.81.68.190 (190.68.81.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 10:09:59.001910 2026] [security2:error] [pid 25359:tid 25359] [client 34.81.68.190:49832] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.loneoakhoney.com"] [uri "/.env.dev"] [unique_id "aprRN9xtthhF0_R7zFuDhQAAAEI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
Grossmann-Gruppe
2026-09-04 14:08:21
(1 week ago)
Plesk Fail2Ban: plesk-modsecurity
Hacking
Brute-Force
🇳🇱
WeCloudit-Anti-Abuse
2026-09-04 14:03:29
(1 week ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-04 13:27:42
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.81.68.190 (190.68.81.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.81.68.190 (190.68.81.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 09:27:38.537839 2026] [security2:error] [pid 6295:tid 6295] [client 34.81.68.190:54888] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "smarthome.varnadorefamily.com"] [uri "/.env.backup"] [unique_id "aprHSg1d8B0JR-tjgsK6QQAAAC0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
kosada.com
2026-09-04 13:25:02
(1 week ago)
Repeated exploit attempts, for example: /actuator/configprops /actuator/ (HTTP/1.1 port 443)
Web App Attack
🇫🇷
dynamix
2026-09-04 13:20:14
(1 week ago)
Multiple WAF Violations
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 12:13:13
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.81.68.190 (190.68.81.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.81.68.190 (190.68.81.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 08:13:08.356714 2026] [security2:error] [pid 27465:tid 27465] [client 34.81.68.190:39292] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mrappliancefl.com"] [uri "/.env.prod"] [unique_id "apq11KKlhdi1UsyG88rFxQAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 11:05:07
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.81.68.190 (190.68.81.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.81.68.190 (190.68.81.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 07:05:02.967952 2026] [security2:error] [pid 28393:tid 28393] [client 34.81.68.190:44764] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "hotelkona.com"] [uri "/wp-config.php~"] [unique_id "apql3h3dUCuFWbdihwOkwAAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
YF
2026-09-04 11:00:25
(1 week ago)
WordPress config file probe
Web App Attack
🇳🇱
debestelapp
2026-09-04 10:55:11
(1 week ago)
Web App Attack
🇩🇪
patrisei
2026-09-04 10:35:31
(1 week ago)
You are now banned for 10 years by Schiffdorf-West Patrol. Trigger: crowdsecurity/http-sensitive-fil ...
show more
You are now banned for 10 years by Schiffdorf-West Patrol. Trigger: crowdsecurity/http-sensitive-files
show less
Port Scan
Web App Attack
🇩🇪
TheDjRider
2026-09-04 10:05:26
(1 week ago)
CrowdSec detected Web application reconnaissance. Scenario: local/framework-recon. Automatic ban tri ...
show more
CrowdSec detected Web application reconnaissance. Scenario: local/framework-recon. Automatic ban triggered. Detection time (UTC): 2026-09-04T10:05:24.615362722Z. Context: http_status=200
show less
Web App Attack
🇷🇴
iulianh
2026-09-04 09:56:32
(1 week ago)
80,443
Brute-Force
SSH
🇳🇱
javierin
2026-09-04 08:46:03
(1 week ago)
34.81.68.190 - regalo-personalizado.javierin.com - - [04/Sep/2026:08:46:02 +0000] "GET /env HTTP/1.1 ...
show more
34.81.68.190 - regalo-personalizado.javierin.com - - [04/Sep/2026:08:46:02 +0000] "GET /env HTTP/1.1" 404 7362 "-" "crusader-worker/1.0"
34.81.68.190 - regalo-personalizado.javierin.com - - [04/Sep/2026:08:46:02 +0000] "GET /.env HTTP/1.1" 404 7362 "-" "crusader-worker/1.0"
...
show less
Web App Attack
Hacking