🇺🇸
TPI-Abuse
2026-09-04 15:18:39
(22 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.85.106.229 (229.106.85.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.85.106.229 (229.106.85.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 11:18:31.656848 2026] [security2:error] [pid 14267:tid 14267] [client 34.85.106.229:52388] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.mkdesignndetailing.com"] [uri "/wp-config.php.swp"] [unique_id "aprhR_ABPjJ0knqiH9kSfgAAAH8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
todix
2026-09-04 14:08:53
(23 hours ago)
Web App Attack Exploid from 34.85.106.229
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 14:05:58
(23 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.85.106.229 (229.106.85.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.85.106.229 (229.106.85.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 10:05:50.870985 2026] [security2:error] [pid 806967:tid 806967] [client 34.85.106.229:33354] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.mindchill.net"] [uri "/.env.production"] [unique_id "aprQPgh_2qHxWdUVWZB_gQAAACY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
WeCloudit-Anti-Abuse
2026-09-04 12:17:26
(1 day ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
🇩🇪
IloGus
2026-09-04 12:02:02
(1 day ago)
WAF repeated trigger detected by Fail2Ban in plesk-modsecurity jail
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 11:50:28
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.85.106.229 (229.106.85.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.85.106.229 (229.106.85.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 07:50:24.736018 2026] [security2:error] [pid 14674:tid 14674] [client 34.85.106.229:47794] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "liverpoolfootballprogrammes.com"] [uri "/.env.bak"] [unique_id "apqwgB6dKTOn_6QVlyvZ8QAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
masterguru
2026-09-04 08:36:18
(1 day ago)
URL file extension is restricted by policy. String match within ".ani/ .asa/ .asax/ .ascx/ .backup/ ...
show more
URL file extension is restricted by policy. String match within ".ani/ .asa/ .asax/ .ascx/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .compositefont/ .config/ .conf/ .crt/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dist/ .dll/ .dos/ .dpkg-dist/ .drv/ .gadget/ .hta/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .inf/ .ini/ .jse/ .key/ .licx/ .lnk/ .log/ .mdb/ .msc/ .ocx/ .old/ .pass/ .pdb/ .pfx/ .pif/ .pem/ .pol/ .prf/ .printer/ .pwd/ .rdb/ .rdp/ .reg/ .resources/ .resx/ .scr/ .sct/ .shs/ .sql/ .swp/ .sys/ .tlb/ .tmp/ .url/ .vb/ .vbe/ .vbs/ .vbproj/ .vsdisco/ .vxd/ .webinfo/ .ws/ .wsc/ .wsf/ .wsh/ .xsd/ .xsx/" at TX:extension. (920440-196)
show less
Hacking
🇫🇷
dynamix
2026-09-04 08:33:01
(1 day ago)
Multiple WAF Violations
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 08:29:28
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.85.106.229 (229.106.85.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.85.106.229 (229.106.85.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 04:29:22.694285 2026] [security2:error] [pid 1563:tid 1563] [client 34.85.106.229:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.rodrigoaldecoa.com"] [uri "/.env.backup"] [unique_id "apqBYgoxpHQWaPLTMrTeYQAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
WeCloudit-Anti-Abuse
2026-09-04 08:28:27
(1 day ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
🇹🇭
Andro
2026-09-04 08:08:00
(1 day ago)
Google Automated malicious reconnaissance attempting to locate exposed environment files, secrets, c ...
show more
Google Automated malicious reconnaissance attempting to locate exposed environment files, secrets, configuration data, and other sensitive application resources. The source is systematically probing for files that may contain credentials, API keys, database connections, or other valuable configuration information. Nice try. Nothing sensitive was left lying around.
show less
Bad Web Bot
Web Spam
🇺🇸
TPI-Abuse
2026-09-04 06:59:26
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.85.106.229 (229.106.85.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.85.106.229 (229.106.85.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 02:59:22.529531 2026] [security2:error] [pid 16543:tid 16543] [client 34.85.106.229:41180] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.norbertesser.com"] [uri "/.env.local"] [unique_id "appsSlajJ8stgp9yURe38AAAACM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇸🇪
vaia.cloud
2026-09-04 06:45:04
(1 day ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 06:37:52
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.85.106.229 (229.106.85.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.85.106.229 (229.106.85.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 02:37:46.352597 2026] [security2:error] [pid 7655:tid 7655] [client 34.85.106.229:50294] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ulrike-petri.de"] [uri "/.env.example"] [unique_id "appnOl_5MQdNZysNxtOs2QAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
Hazzard
2026-09-04 05:58:35
(1 day ago)
(mod_security) mod_security triggered on hostname [redacted]): (CF_ENABLE)
SQL Injection