🇧🇪
cmbplf
2026-09-08 23:38:41
(10 hours ago)
278 requests with url.path */@fs/*
Brute-Force
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-08 20:18:59
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.84.79.191 (191.79.84.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.84.79.191 (191.79.84.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 16:18:52.181962 2026] [security2:error] [pid 10755:tid 10755] [client 34.84.79.191:4920] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.directcch.com"] [uri "/@fs/..%252f..%252f..%252f..%252f..%252froot/.env"] [unique_id "aqBtrEgONCkeGdEsmT8R0AAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 19:23:37
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.84.79.191 (191.79.84.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.84.79.191 (191.79.84.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 15:23:30.719357 2026] [security2:error] [pid 4115379:tid 4115379] [client 34.84.79.191:22968] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.lloydprins.com"] [uri "/@fs/..%252f..%252f..%252f..%252f..%252fapp/.env"] [unique_id "aqBgsuWj0rgcMeLc_3t2agAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 18:18:33
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.84.79.191 (191.79.84.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.84.79.191 (191.79.84.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 14:18:27.469934 2026] [security2:error] [pid 19179:tid 19179] [client 34.84.79.191:1762] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.irishsetterclubofseattle.com"] [uri "/@fs/.env"] [unique_id "aqBRc05uWAu25-y_Tdw05AAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
raph
2026-09-08 17:52:04
(16 hours ago)
[DOT FILES] crawler *.env*, .git*, .config*, etc.
Bad Web Bot
Web App Attack
Anonymous
2026-09-08 17:17:31
(17 hours ago)
IP matched detection query many 3xx errors.
Brute-Force
🇬🇧
consul.to
2026-09-08 17:14:52
(17 hours ago)
Web attack/malicious scanning detected
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 17:11:07
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.84.79.191 (191.79.84.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.84.79.191 (191.79.84.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 13:10:59.790621 2026] [security2:error] [pid 10992:tid 11011] [client 34.84.79.191:1482] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "royalbusinesscollege.com"] [uri "/@fs/../../.env"] [unique_id "aqBBow-CJ3pKPw0fWMYwhAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇮🇹
CoreTech srl
2026-09-08 16:43:51
(17 hours ago)
cloudlinux2 fail2ban: 2026-09-08 18:38:58,851 fail2ban.filter [1794]: INFO [plesk-wordpre ...
show more
cloudlinux2 fail2ban: 2026-09-08 18:38:58,851 fail2ban.filter [1794]: INFO [plesk-wordpress] Found 45.146.55.223 - 2026-09-08 18:38:58cloudlinux2 fail2ban: 2026-09-08 18:39:19,492 fail2ban.filter [1794]: INFO [plesk-modsecurity] Found 34.84.79.191 - 2026-09-08 18:39:19cloudlinux2 fail2ban: 2026-09-08 18:39:19,502 fail2ban.filter [1794]: INFO [plesk-modsecurity] Found 34.84.79.191 - 2026-09-08 18:39:19cloudlinux2 fail2ban: 2026-09-08 18:39:19,537 fail2ban.filter [1794]: INFO [plesk-modsecurity] Found 34.84.79.191 - 2026-09-08 18:39:19cloudlinux2 fail2ban: 2026-09-08 18:39:19,511 fail2ban.filter [1794]: INFO [plesk-modsecurity] Found 34.84.79.191 - 2026-09-08 18:39:19cloudlinux2 fail2ban: 2026-09-08 18:39:19,522 fail2ban.filter [1794]: INFO [plesk-modsecurity] Found 34.84.79.191 - 2026-09-08 18:39:19cloudlinux2 fail2ban: 2026-09-08 18:39:19,548 fail2ban.filter [1794]: INFO [plesk-modsecurity] Found 34.84.79.191 - 2026-09-08 18:39:19clo
show less
Web App Attack
🇳🇱
Site.eu
2026-09-08 15:41:27
(18 hours ago)
Excessive 404/403 errors
Brute-Force
🇸🇪
vaia.cloud
2026-09-08 15:25:02
(18 hours ago)
crowdsecurity/http-probing
Brute-Force
Web App Attack
🇩🇪
Petros Stefanakis
2026-09-08 14:52:56
(19 hours ago)
(mod_security) mod_security triggered on hostname [redacted] 34.84.79.191 (JP/Japan/191.79.84.34.bc. ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.84.79.191 (JP/Japan/191.79.84.34.bc.googleusercontent.com)
show less
SQL Injection
🇺🇸
TPI-Abuse
2026-09-08 14:52:24
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.84.79.191 (191.79.84.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.84.79.191 (191.79.84.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 10:52:18.576195 2026] [security2:error] [pid 11868:tid 11868] [client 34.84.79.191:60118] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autoconfig.ghosted.ws"] [uri "/@fs/src/.env"] [unique_id "aqAhItbku45hJstV3vy87gAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇮🇹
VHosting
2026-09-08 14:35:03
(19 hours ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
Anonymous
2026-09-08 14:31:17
(19 hours ago)
Multiple web server 400 error codes from same source ip
Web App Attack