🇺🇸
IndigoRidge
2026-09-06 06:31:55
(6 hours ago)
[06/Sep/2026:02:31:54.581359 --0400] ap0I2t6Hb6UFXmJOc2KlaQAAApQ 34.91.106.166 47026 205.233.18.18 7 ...
show more
[06/Sep/2026:02:31:54.581359 --0400] ap0I2t6Hb6UFXmJOc2KlaQAAApQ 34.91.106.166 47026 205.233.18.18 7081
[06/Sep/2026:02:31:54.582233 --0400] ap0I2mjXsgLkEg79yVVsGgAAABA 34.91.106.166 47062 205.233.18.18 7081
[06/Sep/2026:02:31:54.585659 --0400] ap0I2pVeellSCUfiRdWK6AAAA1g 34.91.106.166 47054 205.233.18.18 7081
[06/Sep/2026:02:31:54.585959 --0400] ap0I2t6Hb6UFXmJOc2KlagAAAo4 34.91.106.166 47042 205.233.18.18 7081
[06/Sep/2026:02:31:54.588994 --0400] ap0I2pVeellSCUfiRdWK6QAAA0Y 34.91.106.166 47050 205.233.18.18 7081
...
show less
Hacking
🇺🇸
TPI-Abuse
2026-09-06 03:54:51
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.91.106.166 (166.106.91.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.91.106.166 (166.106.91.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 23:54:45.157599 2026] [security2:error] [pid 23259:tid 23259] [client 34.91.106.166:39292] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.chapa.net"] [uri "/.env.bak"] [unique_id "apzkBTbrkQWgQlveHAYmsAAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 02:34:46
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.91.106.166 (166.106.91.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.91.106.166 (166.106.91.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 22:34:40.868333 2026] [security2:error] [pid 28588:tid 28588] [client 34.91.106.166:60308] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "flic.net"] [uri "/wp-config.php~"] [unique_id "apzRQBX-Zk4lSHEwOuqNawAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
e.fierstra
2026-09-06 02:28:45
(10 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
🇬🇧
consul.to
2026-09-06 01:34:08
(11 hours ago)
Web attack/malicious scanning detected
Web App Attack
Anonymous
2026-09-06 01:25:03
(11 hours ago)
suspicious request in access.log
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 01:08:54
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.91.106.166 (166.106.91.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.91.106.166 (166.106.91.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 21:08:50.017170 2026] [security2:error] [pid 8857:tid 8857] [client 34.91.106.166:43858] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.petersonzeyerlaw.com"] [uri "/.env.local"] [unique_id "apy9IoEl5cDZsC0HeSeHrgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
Aetherweb Ark
2026-09-06 00:06:26
(12 hours ago)
(mod_security) mod_security (id:949110) triggered by 34.91.106.166 (166.106.91.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:949110) triggered by 34.91.106.166 (166.106.91.34.bc.googleusercontent.com): N in the last X secs
show less
Web App Attack
🇩🇪
FeG Deutschland
2026-09-06 00:00:03
(12 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
Anonymous
2026-09-05 23:59:07
(12 hours ago)
Bot / scanning and/or hacking attempts: GET /.env.backup HTTP/1.1, GET /_ignition/health-check HTTP/ ...
show more
Bot / scanning and/or hacking attempts: GET /.env.backup HTTP/1.1, GET /_ignition/health-check HTTP/1.1, GET /.env.prod HTTP/1.1, GET /.env.production HTTP/1.1, GET /.env.old HTTP/1.1, GET /crusader-404-probe HTTP/1.1, GET /.env HTTP/1.1, GET /.env.example HTTP/1.1, GET /.env.local HTTP/1.1, GET /wp-config.php.bak HTTP/1.1, GET /.env.bak HTTP/1.1, GET /wp-config.php.swp HTTP/1.1, GET /.env.save HTTP/1.1, GET /wp-config.php~ HTTP/1.1, GET /actuator/configprops HTTP/1.1
show less
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 23:57:09
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.91.106.166 (166.106.91.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.91.106.166 (166.106.91.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 19:57:01.990709 2026] [security2:error] [pid 3505775:tid 3505882] [client 34.91.106.166:57958] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.ellicottville.net"] [uri "/.env.bak"] [unique_id "apysTb8ERl7gWgWoAPLY4gAAAZg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 23:24:19
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.91.106.166 (166.106.91.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.91.106.166 (166.106.91.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 19:24:14.650575 2026] [security2:error] [pid 3112:tid 3112] [client 34.91.106.166:43694] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "xmas.martinka.org"] [uri "/.env.example"] [unique_id "apyknvbX6C25--39a_e-RQAAAFU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 22:57:48
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.91.106.166 (166.106.91.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.91.106.166 (166.106.91.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 18:57:42.386678 2026] [security2:error] [pid 11731:tid 11806] [client 34.91.106.166:40922] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.expozium.com"] [uri "/.env.production"] [unique_id "apyeZpsU0UwcvWhlsZpL2QAAAc8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
FD-IX
2026-09-05 22:39:09
(13 hours ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 22:37:36
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.91.106.166 (166.106.91.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.91.106.166 (166.106.91.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 18:37:32.267307 2026] [security2:error] [pid 3361551:tid 3361551] [client 34.91.106.166:49794] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ftiptondds.com"] [uri "/.env.backup"] [unique_id "apyZrM-AlGkLpq8zWyzVFAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack