🇺🇸
TPI-Abuse
2026-09-04 14:43:57
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.82.90.146 (146.90.82.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.82.90.146 (146.90.82.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 10:43:50.126302 2026] [security2:error] [pid 17501:tid 17501] [client 34.82.90.146:41244] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "schwanpaint.com"] [uri "/.env.bak"] [unique_id "aprZJvPQLpYquEKaLlvT_wAAACU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
MyGlobalFlowers
2026-09-04 14:15:53
(16 hours ago)
Multiple WAF Violations
Web App Attack
🇩🇪
Petros Stefanakis
2026-09-04 12:12:30
(18 hours ago)
(mod_security) mod_security triggered on hostname [redacted] 34.82.90.146 (US/United States/146.90.8 ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.82.90.146 (US/United States/146.90.82.34.bc.googleusercontent.com)
show less
SQL Injection
🇺🇸
TPI-Abuse
2026-09-04 11:44:19
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.82.90.146 (146.90.82.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.82.90.146 (146.90.82.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 07:44:11.823196 2026] [security2:error] [pid 7075:tid 7075] [client 34.82.90.146:39696] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.rockitfish.com"] [uri "/.env"] [unique_id "apqvCwDjONXjMFuhrEfUJwAAACE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇭🇺
miszterx.hu
2026-09-04 11:03:40
(20 hours ago)
XORP (haproxy): 19x HTTP 404/403/500 or handshake failure in 24h. Automated report from log_check_ip ...
show more
XORP (haproxy): 19x HTTP 404/403/500 or handshake failure in 24h. Automated report from log_check_iptables_generator.sh (xorp.hu)
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 10:37:10
(20 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.82.90.146 (146.90.82.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.82.90.146 (146.90.82.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 06:37:02.784979 2026] [security2:error] [pid 2851062:tid 2851406] [client 34.82.90.146:38752] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "aliqshacommoditiescorporation.com.aliqsha.com"] [uri "/wp-config.php.swp"] [unique_id "apqfTsB6z_qmuejzZ9-KFQAAAUk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-04 10:22:13
(20 hours ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
🇩🇪
FD-IX
2026-09-04 10:07:11
(20 hours ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
🇺🇸
mnsf
2026-09-04 10:06:11
(20 hours ago)
Scanning/Probing (15)
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 10:03:31
(21 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.82.90.146 (146.90.82.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.82.90.146 (146.90.82.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 06:03:26.286070 2026] [security2:error] [pid 8716:tid 8716] [client 34.82.90.146:53384] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.cmcgroup.us.com"] [uri "/.env.dev"] [unique_id "apqXbgAiPTPfvyvOI9fH6gAAAGM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 09:21:48
(21 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.82.90.146 (146.90.82.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.82.90.146 (146.90.82.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 05:21:44.980745 2026] [security2:error] [pid 4692:tid 4768] [client 34.82.90.146:59198] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "louisgfazzi.jd-web-designs.com"] [uri "/.env.save"] [unique_id "apqNqKTWtaz_ebYj_UuzhgAAAU4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇸🇪
vaia.cloud
2026-09-04 08:30:05
(22 hours ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
🇫🇷
Quarks Solutions
2026-09-04 08:29:58
(22 hours ago)
crowdsecurity/http-probing
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-04 07:34:32
(23 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.82.90.146 (146.90.82.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.82.90.146 (146.90.82.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 03:34:26.917261 2026] [security2:error] [pid 678:tid 678] [client 34.82.90.146:53248] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "toptek.com"] [uri "/.env.old"] [unique_id "app0gk5hm0_g2uAXNP_swgAAAB8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-04 06:32:18
(1 day ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking