๐บ๐ธ
TPI-Abuse
2026-08-27 11:46:09
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.101.70.83 (83.70.101.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.101.70.83 (83.70.101.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 07:46:01.758620 2026] [security2:error] [pid 18688:tid 18688] [client 34.101.70.83:42668] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jenricker.com"] [uri "/wp-config.php.swp"] [unique_id "apAjeRicuthxXpKea51baQAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-27 11:33:45
(1 hour ago)
Malicious Probing
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-08-27 10:49:51
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.101.70.83 (83.70.101.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.101.70.83 (83.70.101.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 06:49:44.632598 2026] [security2:error] [pid 18507:tid 18507] [client 34.101.70.83:57510] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "nightknightalarms.com"] [uri "/.env.bak"] [unique_id "apAWSHH3kN9eQYKKszKtUwAAACE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 09:49:24
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.101.70.83 (83.70.101.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.101.70.83 (83.70.101.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 05:49:18.639780 2026] [security2:error] [pid 3426:tid 3426] [client 34.101.70.83:46814] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "murphylumber.ca"] [uri "/wp-config.php~"] [unique_id "apAIHoZioVDSYXw6EY57zQAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
4server
2026-08-27 09:46:01
(3 hours ago)
[ThuAug2711:45:55.7242442026][security2:error][pid991437:tid991443][client34.101.70.83:0]ModSecurity ...
show more
[ThuAug2711:45:55.7242442026][security2:error][pid991437:tid991443][client34.101.70.83:0]ModSecurity:Accessdeniedwithcode403\(phase2\).Stringmatchwithin\".asa/.asax/.ascx/.backup/.bak/.bat/.cdx/.cer/.cfg/.cmd/.com/.config/.conf/.cs/.csproj/.csr/.dat/.db/.dbf/.dll/.dos/.htr/.htw/.ida/.idc/.idq/.inc/.ini/.key/.licx/.lnk/.log/.mdb/.old/.pass/.pdb/.pol/.printer/.pwd/.rdb/.resources/.resx/.sql/.swp/.sys/.vb/.vbs/.vbproj/.vsdisco/.webinfo/.xsx/\"atTX:extension.[file\"/etc/apache2/conf.d/modsec_rules/00_asl_zz_strict.conf\"][line\"91\"][id\"390716\"][rev\"2\"][msg\"Atomicorp.comWAFRules:URLfileextensionisrestrictedbypolicy\"][data\".backup\"][severity\"ERROR\"][hostname\"www.risanamento-funghi-muffa.ch.136-243-54-122.cpanel.site\"][uri\"/.env.backup\"][unique_id\"apAHUwFCRJgfQTOvCZfrQgAAAUA\"]
show less
Port Scan
Brute-Force
Web App Attack
๐ฉ๐ช
inlink.ltd
2026-08-27 09:33:44
(3 hours ago)
dot file probe
Web App Attack
๐ซ๐ท
masterguru
2026-08-27 07:21:57
(5 hours ago)
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 34.101.70.83 (ID/Indonesia/83.70.101. ...
show more
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 34.101.70.83 (ID/Indonesia/83.70.101.34.bc.googleusercontent.com): 1 in the last 3600 secs (0-195)
show less
Hacking
๐บ๐ธ
TPI-Abuse
2026-08-27 07:04:58
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.101.70.83 (83.70.101.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.101.70.83 (83.70.101.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 03:04:50.191594 2026] [security2:error] [pid 3467:tid 3467] [client 34.101.70.83:52504] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ads.cruisingforsex.com"] [uri "/.env"] [unique_id "ao_hkv2ELleFJ6P8qI5PDAAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
debestelapp
2026-08-27 07:00:07
(6 hours ago)
Web App Attack
๐บ๐ธ
Victor Lรณpez
2026-08-27 06:49:31
(6 hours ago)
www.desdeotramirada.com 34.101.70.83 - - [27/Aug/2026:01:49:31 -0500] "GET /wp-config.php.bak HTTP/1 ...
show more
www.desdeotramirada.com 34.101.70.83 - - [27/Aug/2026:01:49:31 -0500] "GET /wp-config.php.bak HTTP/1.1" 404 26289 "-" "crusader-worker/1.0" -
www.desdeotramirada.com 34.101.70.83 - - [27/Aug/2026:01:49:31 -0500] "GET /.env.production HTTP/1.1" 404 26289 "-" "crusader-worker/1.0" -
www.desdeotramirada.com 34.101.70.83 - - [27/Aug/2026:01:49:31 -0500] "GET /.env.old HTTP/1.1" 404 26289 "-" "crusader-worker/1.0" -
...
show less
Hacking
Web App Attack
๐ฉ๐ช
maxpower
2026-08-27 06:03:58
(7 hours ago)
(nginx_hardened) REGOLA 3 - Nginx Hardening Triggered 34.101.70.83 (ID/Indonesia/83.70.101.34.bc.goo ...
show more
(nginx_hardened) REGOLA 3 - Nginx Hardening Triggered 34.101.70.83 (ID/Indonesia/83.70.101.34.bc.googleusercontent.com): 3 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 2026/08/27 08:03:56 [error] 3333549#3333549: *366145 access forbidden by rule, client: 34.101.70.83, server: avconsulenze.arkon.it, request: "GET /wp-config.php.swp HTTP/1.1", host: "www.avconsulenze.arkon.it"
2026/08/27 08:03:56 [error] 3333543#3333543: *366146 access forbidden by rule, client: 34.101.70.83, server: avconsulenze.arkon.it, request: "GET /wp-config.php.bak HTTP/1.1", host: "www.avconsulenze.arkon.it"
2026/08/27 08:03:56 [error] 3333545#3333545: *366151 access forbidden by rule, client: 34.101.70.83, server: avconsulenze.arkon.it, request: "GET /wp-config.php~ HTTP/1.1", host: "www.avconsulenze.arkon.it"
show less
Port Scan
๐ฎ๐น
mediarama.com
2026-08-27 06:00:16
(7 hours ago)
Banned by Fail2Ban
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 04:47:36
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.101.70.83 (83.70.101.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.101.70.83 (83.70.101.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 00:47:29.647340 2026] [security2:error] [pid 14594:tid 14594] [client 34.101.70.83:47042] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "movieheadshots.com.robertmcatee.com"] [uri "/.env.save"] [unique_id "ao_BYTyHlb2SLmSvCGahgAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
consul.to
2026-08-27 04:23:04
(8 hours ago)
Web attack/malicious scanning detected
Web App Attack
๐ฉ๐ช
Hary74656
2026-08-27 03:27:35
(9 hours ago)
[Thu Aug 27 05:27:30.259199 2026] [security2:error] [pid 106955:tid 107064] [client 34.101.70.83:557 ...
show more
[Thu Aug 27 05:27:30.259199 2026] [security2:error] [pid 106955:tid 107064] [client 34.101.70.83:55718] [client 34.101.70.83] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "125"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.local"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "78.46.107.184"] [uri "/.env.local"] [unique_id "ao-undfjWFJTZUJ8UD7UGgAAAjY"]
[Thu Aug 27 05:27:30.259228 2026] [security2:error] [pid 107093:tid 107182] [client 34.101.70.83:55786] [client 34.101.70.83] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/
...
show less
Web App Attack