🇳🇱
Savvii
2026-09-04 14:10:48
(23 hours ago)
15 attempts against mh-modsecurity-ban on sonic
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 14:06:32
(23 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.95.163.174 (174.163.95.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.95.163.174 (174.163.95.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 10:06:24.898229 2026] [security2:error] [pid 3074853:tid 3074988] [client 34.95.163.174:59320] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.layoverlocations.com"] [uri "/.env.dev"] [unique_id "aprQYBBOMVLn240jkbtcmgAAARY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 13:30:23
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.95.163.174 (174.163.95.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.95.163.174 (174.163.95.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 09:30:19.416943 2026] [security2:error] [pid 8123:tid 8123] [client 34.95.163.174:38780] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "srippy.com"] [uri "/.env.backup"] [unique_id "aprH60h5_wtH7k6Q66T6owAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-04 13:17:16
(1 day ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
🇬🇧
thetomtaylor.co.uk
2026-09-04 13:08:00
(1 day ago)
Fail2Ban - [WEB]Custom exploit pattern detected on customexploits ... [ice01,ice02,wa01,wa02]
Hacking
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
SCHAPPY
2026-09-04 12:51:37
(1 day ago)
Brute-force attack to non-existent web resources, HTTP code 404.
Brute-Force
Web App Attack
🇩🇪
raph
2026-09-04 12:36:32
(1 day ago)
[DOT FILES] crawler *.env*, .git*, .config*, etc.
Bad Web Bot
Web App Attack
🇩🇪
Hazzard
2026-09-04 12:19:14
(1 day ago)
(mod_security) mod_security triggered on hostname [redacted]): (CF_ENABLE)
SQL Injection
🇫🇷
Stara
2026-09-04 11:47:27
(1 day ago)
ModSecurity detected web attack - .env/config probing or SQLi/Code injection (Rule 949110)
Brute-Force
SSH
Web App Attack
🇳🇱
e.fierstra
2026-09-04 11:46:40
(1 day ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 11:45:52
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.95.163.174 (174.163.95.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.95.163.174 (174.163.95.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 07:45:45.729788 2026] [security2:error] [pid 4342:tid 4342] [client 34.95.163.174:52254] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.lajoze.com"] [uri "/.env.prod"] [unique_id "apqvaQE-JkwEq9jqmGGw5gAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇦🇺
2000cn.com.au
2026-09-04 11:25:50
(1 day ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-04 11:16:14
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.95.163.174 (174.163.95.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.95.163.174 (174.163.95.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 07:16:10.728342 2026] [security2:error] [pid 3639:tid 3639] [client 34.95.163.174:58782] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "correeo.gisur.com"] [uri "/.env.old"] [unique_id "apqoev4AXVXDIAml2kSD1QAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇮🇹
VHosting
2026-09-04 11:05:03
(1 day ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 10:57:57
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.95.163.174 (174.163.95.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.95.163.174 (174.163.95.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 06:57:52.370462 2026] [security2:error] [pid 4275:tid 4275] [client 34.95.163.174:46034] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "biff0.com"] [uri "/.env.old"] [unique_id "apqkMBO0ZOBvCQ1-L5T2zQAAAEo"]
show less
Brute-Force
Bad Web Bot
Web App Attack