Anonymous
2026-09-01 04:43:16
(5 minutes ago)
Blocked by ModSec and CSF
Port Scan
๐บ๐ธ
TPI-Abuse
2026-09-01 04:42:31
(6 minutes ago)
(mod_security) mod_security (id:210492) triggered by 34.88.20.194 (194.20.88.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.88.20.194 (194.20.88.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 00:42:26.950649 2026] [security2:error] [pid 16012:tid 16012] [client 34.88.20.194:50036] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "home.theyoungstrategist.com"] [uri "/.env.bak"] [unique_id "apZXspi1oOTghwWZPB4zfQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-01 04:42:07
(6 minutes ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
๐ฉ๐ช
raph
2026-09-01 04:00:15
(48 minutes ago)
[Wordpress] crawler /wp-admin/*, /wp-content/*, etc.
Bad Web Bot
Web App Attack
๐ฉ๐ช
4server
2026-09-01 03:53:50
(54 minutes ago)
[TueSep0105:53:47.5222592026][security2:error][pid3616602:tid3616720][client34.88.20.194:0]ModSecuri ...
show more
[TueSep0105:53:47.5222592026][security2:error][pid3616602:tid3616720][client34.88.20.194:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Patternmatch\"\(\?i\)\(\?:/\(\?:\^\|/\)\\\\\\\\.\(env\|git\|svn\|hg\|DS_Store\)\|/\(\?:wp-config\|\\\\\\\\.htaccess\|\\\\\\\\.htpasswd\)\|\\\\\\\\.\(\?:sql\|bak\|old\|log\)\$\)\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"156\"][id\"960720\"][msg\"Forbiddenfileaccessattempt\"][severity\"CRITICAL\"][hostname\"lacer.ch\"][uri\"/.env.old\"][unique_id\"apZMS0exkiQcBGeMTeWVQQAAARY\"]
show less
Port Scan
Brute-Force
Web App Attack
๐ฉ๐ช
Hazzard
2026-09-01 03:49:36
(59 minutes ago)
(mod_security) mod_security triggered on hostname [redacted]): (CF_ENABLE)
SQL Injection
๐บ๐ธ
TPI-Abuse
2026-09-01 03:48:08
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.88.20.194 (194.20.88.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.88.20.194 (194.20.88.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 23:48:01.026991 2026] [security2:error] [pid 17638:tid 17638] [client 34.88.20.194:49968] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "apexandroids.com"] [uri "/wp-config.php~"] [unique_id "apZK8S9Ss_DG4MFx6hP69QAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 03:12:22
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.88.20.194 (194.20.88.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.88.20.194 (194.20.88.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 23:12:18.072394 2026] [security2:error] [pid 28313:tid 28313] [client 34.88.20.194:35668] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "photos.jpwatters.net"] [uri "/.env.local"] [unique_id "apZCkispxjS5RL_ZabOmcwAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-01 03:00:18
(1 hour ago)
suspicious request in access.log
Web App Attack
๐ธ๐ช
vaia.cloud
2026-09-01 02:25:01
(2 hours ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-09-01 01:14:32
(3 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-01 00:49:59
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.88.20.194 (194.20.88.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.88.20.194 (194.20.88.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 20:49:51.736727 2026] [security2:error] [pid 16209:tid 16209] [client 34.88.20.194:46698] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "darrenpeck.com"] [uri "/.env.save"] [unique_id "apYhL6Gow0zp9K33J4TaUQAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 00:17:51
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.88.20.194 (194.20.88.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.88.20.194 (194.20.88.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 20:17:46.826762 2026] [security2:error] [pid 19743:tid 19743] [client 34.88.20.194:40796] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.restaurantfixture.com"] [uri "/.env.prod"] [unique_id "apYZqtU-MwltN_17q-zpTAAAAFo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
Aetherweb Ark
2026-09-01 00:11:43
(4 hours ago)
(mod_security) mod_security (id:949110) triggered by 34.88.20.194 (FI/Finland/194.20.88.34.bc.google ...
show more
(mod_security) mod_security (id:949110) triggered by 34.88.20.194 (FI/Finland/194.20.88.34.bc.googleusercontent.com): N in the last X secs
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-31 23:33:42
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.88.20.194 (194.20.88.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.88.20.194 (194.20.88.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 19:33:38.861765 2026] [security2:error] [pid 14126:tid 14126] [client 34.88.20.194:55322] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "centuryabsinthe.com"] [uri "/.env.production"] [unique_id "apYPUoV3wD2uf6-_2UF71QAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack