๐ฌ๐ง
consul.to
2026-09-01 14:06:38
(9 hours ago)
Web attack/malicious scanning detected
Web App Attack
๐ซ๐ฎ
paissangroup
2026-09-01 12:35:47
(11 hours ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 12:30:21
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.104.222.66 (66.222.104.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.104.222.66 (66.222.104.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 08:30:14.238079 2026] [security2:error] [pid 7010:tid 7010] [client 34.104.222.66:53634] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "chiloiangallery.com.saadeh.ws"] [uri "/wp-config.php.swp"] [unique_id "apbFVnpTOgl2h11VoQuIhwAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
daveoctober
2026-09-01 11:59:15
(12 hours ago)
October Sentinel: honeypot triggered
Bad Web Bot
Web App Attack
๐บ๐ธ
MatCat
2026-09-01 11:05:09
(13 hours ago)
Banned by fail2ban: apache-webprobe
Port Scan
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-01 10:59:47
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.104.222.66 (66.222.104.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.104.222.66 (66.222.104.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 06:59:42.580496 2026] [security2:error] [pid 13169:tid 13169] [client 34.104.222.66:35038] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.qualityelevatorcabs.com"] [uri "/.env.save"] [unique_id "apawHqewLY7VA5dL739EeAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-09-01 10:54:25
(13 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-01 09:47:30
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.104.222.66 (66.222.104.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.104.222.66 (66.222.104.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 05:47:26.098827 2026] [security2:error] [pid 2539:tid 2539] [client 34.104.222.66:36318] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sjstauffer.net"] [uri "/.env"] [unique_id "apafLnb6H_OIxuiyxmYPnQAAACM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-09-01 08:24:07
(15 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-01 08:23:48
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.104.222.66 (66.222.104.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.104.222.66 (66.222.104.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 04:23:41.972941 2026] [security2:error] [pid 31653:tid 31653] [client 34.104.222.66:55508] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "melkanbassil.com"] [uri "/.env.save"] [unique_id "apaLjZuwU83ZApfJI5K0VwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ฐ
ScamAware
2026-09-01 07:21:14
(16 hours ago)
Detected by Cloudflare Security Events via WordPress automation. Detection: sensitive_files (Sensiti ...
show more
Detected by Cloudflare Security Events via WordPress automation. Detection: sensitive_files (Sensitive files, source control, config, and backups). Hits from same IP in last 60 minutes: 20. Unique request paths counted internally: 20. Cloudflare action: block. Cloudflare source: firewallCustom.
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 07:20:13
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.104.222.66 (66.222.104.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.104.222.66 (66.222.104.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 03:20:05.425470 2026] [security2:error] [pid 27088:tid 27088] [client 34.104.222.66:33562] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mohsep-eg.com"] [uri "/.env.dev"] [unique_id "apZ8pc-GUrI0msihA-TTOQAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Gwyneth Llewelyn
2026-09-01 07:10:46
(16 hours ago)
2026/09/01 08:10:40 [error] 380595#380595: *2022361 access forbidden by rule, client: 34.104.222.66, ...
show more
2026/09/01 08:10:40 [error] 380595#380595: *2022361 access forbidden by rule, client: 34.104.222.66, server: [redacted], request: "GET /.env HTTP/1.1", host: "mta-sts.[redacted]"
34.104.222.66 - - [01/Sep/2026:08:10:40 +0100] "GET /.env HTTP/1.1" 403 2599 "-" "crusader-worker/1.0"
2026/09/01 08:10:44 [error] 380595#380595: *2022365 access forbidden by rule, client: 34.104.222.66, server: [redacted], request: "GET //.env HTTP/1.1", host: "mta-sts.[redacted]"
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 05:05:56
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.104.222.66 (66.222.104.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.104.222.66 (66.222.104.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 01:05:47.840700 2026] [security2:error] [pid 30068:tid 30068] [client 34.104.222.66:37010] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.juridicovidal.com"] [uri "/.env.production"] [unique_id "apZdK3UoBFhVkiptCtVuXQAAACc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 04:13:02
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.104.222.66 (66.222.104.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.104.222.66 (66.222.104.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 00:12:57.689982 2026] [security2:error] [pid 15285:tid 15285] [client 34.104.222.66:40128] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "valuerec.com"] [uri "/wp-config.php~"] [unique_id "apZQydZftKKeDvIKsc2NrgAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack