🇧🇾
lns.bz
2026-09-07 09:59:55
(12 minutes ago)
Too many 404 requests [BY]
Web App Attack
🇺🇸
FreeMyIP
2026-09-06 06:06:09
(1 day ago)
Automated fail2ban report: web application attack / scanning for exploitable paths.
Bad Web Bot
Web App Attack
Anonymous
2026-09-06 03:33:18
(1 day ago)
Web scanner: GET /.env
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-06 02:54:52
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.104.217.153 (153.217.104.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.104.217.153 (153.217.104.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 22:54:47.345269 2026] [security2:error] [pid 3505777:tid 3505901] [client 34.104.217.153:40946] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ozworkshop.aussiepens.com"] [uri "/.env.local"] [unique_id "apzV9_3Jx5DkjDVB6KJ_-AAAAcc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 02:19:40
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.104.217.153 (153.217.104.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.104.217.153 (153.217.104.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 22:19:35.699598 2026] [security2:error] [pid 26133:tid 26133] [client 34.104.217.153:60168] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "straypointers.com"] [uri "/wp-config.php.bak"] [unique_id "apzNt92vNbQp0HN_TL9QZwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-06 02:10:03
(1 day ago)
suspicious request in access.log
Web App Attack
🇬🇧
consul.to
2026-09-06 00:33:12
(1 day ago)
Web attack/malicious scanning detected
Web App Attack
🇳🇴
jad-abuse
2026-09-06 00:26:36
(1 day ago)
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: env_probe ...
show more
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: env_probe, scanner_ua, source_backup, actuator, ignition_debug, config_backup. Observed by 1 sensor(s); 19 hits.
show less
Hacking
Web App Attack
🇳🇱
MyGlobalFlowers
2026-09-06 00:16:59
(1 day ago)
Multiple WAF Violations
Web App Attack
🇫🇷
masterguru
2026-09-06 00:07:15
(1 day ago)
Attempt to access a backup or working file. Pattern match "\\\\. (920500-196)
Hacking
🇮🇹
VHosting
2026-09-05 23:25:03
(1 day ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 23:24:28
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.104.217.153 (153.217.104.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.104.217.153 (153.217.104.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 19:24:24.515566 2026] [security2:error] [pid 3021:tid 3021] [client 34.104.217.153:56254] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "xirin.net.owenmail.com"] [uri "/.env"] [unique_id "apykqBOrWqE7cN2CCTmNGQAAAHE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 22:55:08
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.104.217.153 (153.217.104.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.104.217.153 (153.217.104.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 18:54:58.061388 2026] [security2:error] [pid 18712:tid 18712] [client 34.104.217.153:46596] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.simplyelegantboutique.com"] [uri "/wp-config.php.swp"] [unique_id "apydwgowXGuLymxYgkJXsQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
LRob
2026-09-05 22:48:22
(1 day ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /.env.dev (+12 more) | 2026-09-05 22:48 UTC
show less
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 21:40:54
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.104.217.153 (153.217.104.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.104.217.153 (153.217.104.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 17:40:46.190027 2026] [security2:error] [pid 3107:tid 3107] [client 34.104.217.153:59250] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.cadimpressions.com"] [uri "/.env"] [unique_id "apyMXrRrDb0uRGLdfMGcbAAAACg"]
show less
Brute-Force
Bad Web Bot
Web App Attack