🇮🇪
AutosOnShow
2026-09-05 07:42:05
(12 hours ago)
blocked for webapp attack | path requested: / | seen at 2026-09-05 07:41:46.039 |
Web App Attack
Anonymous
2026-09-05 07:29:39
(12 hours ago)
Sep 5 09:29:38 mail2 Nextcloud[118570]: {"reqId":"apvE4nV47X9OVyvJDh_jpQAAAEc","level":1,"time":"20 ...
show more
Sep 5 09:29:38 mail2 Nextcloud[118570]: {"reqId":"apvE4nV47X9OVyvJDh_jpQAAAEc","level":1,"time":"2026-09-05T07:29:38+00:00","remoteAddr":"34.102.89.124","user":"--","app":"core","method":"GET","url":"/actuator/configprops","scriptName":"/index.php","message":"Trusted domain error. \"34.102.89.124\" tried to access using \"cloud.akcurate.de\" as host.","userAgent":"crusader-worker/1.0","version":"32.0.9.2","data":{"app":"core"}}
Sep 5 09:29:38 mail2 Nextcloud[118564]: {"reqId":"apvE4nV47X9OVyvJDh_jqQAAAEE","level":1,"time":"2026-09-05T07:29:38+00:00","remoteAddr":"34.102.89.124","user":"--","app":"core","method":"GET","url":"/wp-config.php~","scriptName":"/index.php","message":"Trusted domain error. \"34.102.89.124\" tried to access using \"cloud.akcurate.de\" as host.","userAgent":"crusader-worker/1.0","version":"32.0.9.2","data":{"app":"core"}}
Sep 5 09:29:38 mail2 Nextcloud[142598]: {"reqId":"apvE4nV47X9OVyvJDh_jqgAAAEM","level":1,"time":"2026-09-05T07:29:38+00:00","remoteAddr":"3
...
show less
Brute-Force
Web App Attack
🇧🇾
lns.bz
2026-09-05 06:51:34
(13 hours ago)
Too many 404 requests [BY]
Web App Attack
🇻🇳
trung.fun
2026-09-04 15:16:47
(1 day ago)
DDoS, Hack, Brute Force, Web Attack
...
DDoS Attack
Web Spam
Hacking
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 14:06:58
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.102.89.124 (124.89.102.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.102.89.124 (124.89.102.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 10:06:51.686002 2026] [security2:error] [pid 7696:tid 7696] [client 34.102.89.124:47740] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "walterceron.com"] [uri "/.env.production"] [unique_id "aprQe4d2dBpDKZZZdNx18AAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
iNetWorker
2026-09-04 14:05:38
(1 day ago)
trolling for resource vulnerabilities
Web App Attack
🇺🇦
URAN Publishing Service
2026-09-04 13:37:14
(1 day ago)
[04/Sep/2026:16:37:14 +0300] -- 34.102.89.124 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET / ...
show more
[04/Sep/2026:16:37:14 +0300] -- 34.102.89.124 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET /.env HTTP/1.1
show less
Bad Web Bot
Web App Attack
🇳🇱
e.fierstra
2026-09-04 13:24:20
(1 day ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 13:17:39
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.102.89.124 (124.89.102.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.102.89.124 (124.89.102.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 09:17:34.669146 2026] [security2:error] [pid 20213:tid 20213] [client 34.102.89.124:57984] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "stewarttaylor.com"] [uri "/.env.prod"] [unique_id "aprE7gJRVwkLMJFaahsncgAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-04 13:01:42
(1 day ago)
Sensitive file access attempt
Hacking
🇩🇪
4server
2026-09-04 11:57:59
(1 day ago)
[FriSep0413:57:55.4090302026][security2:error][pid105368:tid105502][client34.102.89.124:0]ModSecurit ...
show more
[FriSep0413:57:55.4090302026][security2:error][pid105368:tid105502][client34.102.89.124:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Patternmatch\"\(\?i\)\(\?:/\(\?:\^\|/\)\\\\\\\\.\(env\|git\|svn\|hg\|DS_Store\)\|/\(\?:wp-config\|\\\\\\\\.htaccess\|\\\\\\\\.htpasswd\)\|\\\\\\\\.\(\?:sql\|bak\|old\|log\)\$\)\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"156\"][id\"960720\"][msg\"Forbiddenfileaccessattempt\"][severity\"CRITICAL\"][hostname\"studioars.ch.136-243-54-122.cpanel.site\"][uri\"/wp-config.php~\"][unique_id\"apqyQypZ-tKkkezp0UXz8AAAARc\"]
show less
Port Scan
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 10:34:23
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.102.89.124 (124.89.102.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.102.89.124 (124.89.102.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 06:34:17.450841 2026] [security2:error] [pid 16629:tid 16629] [client 34.102.89.124:38572] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "americanexportimport.internetnameregistration.com"] [uri "/.env.production"] [unique_id "apqeqYskmXWKLMMQt_wEtAAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 09:51:59
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.102.89.124 (124.89.102.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.102.89.124 (124.89.102.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 05:51:54.669702 2026] [security2:error] [pid 21437:tid 21437] [client 34.102.89.124:42084] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "graduationinvitationsonline.com"] [uri "/wp-config.php.swp"] [unique_id "apqUumH21N7AVX2HiSLbRAAAACY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 09:16:40
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.102.89.124 (124.89.102.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.102.89.124 (124.89.102.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 05:16:32.740095 2026] [security2:error] [pid 18870:tid 18870] [client 34.102.89.124:40024] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "xirin.org.owenmail.com"] [uri "/wp-config.php.swp"] [unique_id "apqMcLqSFwZyaBeCu1SLdgAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 08:24:21
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.102.89.124 (124.89.102.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.102.89.124 (124.89.102.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 04:24:15.427515 2026] [security2:error] [pid 29411:tid 29411] [client 34.102.89.124:56866] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.g-drome.com"] [uri "/.env.local"] [unique_id "apqAL2hdvoPuQXXkkP_lZQAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack