Anonymous
2026-09-06 03:55:00
(7 hours ago)
suspicious request in access.log
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 02:48:14
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.104.230.169 (169.230.104.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.104.230.169 (169.230.104.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 22:48:06.906317 2026] [security2:error] [pid 15758:tid 15758] [client 34.104.230.169:40228] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "truthsabouthealthcare.com"] [uri "/.env.production"] [unique_id "apzUZo6Nx-qVVKZJ_dzA-AAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 00:57:32
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.104.230.169 (169.230.104.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.104.230.169 (169.230.104.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 20:57:27.497396 2026] [security2:error] [pid 11657:tid 11657] [client 34.104.230.169:49750] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "thecrimsonpirate.com"] [uri "/.env.old"] [unique_id "apy6d07RWHHMG4HLXloD0wAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-06 00:14:43
(11 hours ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-05 23:50:23
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.104.230.169 (169.230.104.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.104.230.169 (169.230.104.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 19:50:18.727397 2026] [security2:error] [pid 10531:tid 10531] [client 34.104.230.169:53162] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "grandriverhomes.com"] [uri "/wp-config.php~"] [unique_id "apyquuYsx0K0WCTfe1O4BAAAACI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 23:22:55
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.104.230.169 (169.230.104.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.104.230.169 (169.230.104.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 19:22:47.672644 2026] [security2:error] [pid 3505773:tid 3505849] [client 34.104.230.169:54534] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "koublacat.com"] [uri "/.env.prod"] [unique_id "apykRycrIQhcuqFjqhXbBAAAAVM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-05 22:18:23
(13 hours ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 22:12:25
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.104.230.169 (169.230.104.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.104.230.169 (169.230.104.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 18:12:19.386807 2026] [security2:error] [pid 24838:tid 24838] [client 34.104.230.169:52722] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "navarreunited.nysasports.com"] [uri "/.env.example"] [unique_id "apyTwxjSFUXJeZrrMB8CwQAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
ghostwarriors
2026-09-05 21:50:08
(13 hours ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack
🇩🇪
yitzhaq
2026-09-05 21:30:00
(14 hours ago)
34.104.230.169 - - [05/Sep/2026:23:29:57 +0200] "GET /wp-config.php~ HTTP/1.1" 307 4567 "-" "crusade ...
show more
34.104.230.169 - - [05/Sep/2026:23:29:57 +0200] "GET /wp-config.php~ HTTP/1.1" 307 4567 "-" "crusader-worker/1.0"
34.104.230.169 - - [05/Sep/2026:23:29:57 +0200] "GET /wp-config.php.bak HTTP/1.1" 307 4573 "-" "crusader-worker/1.0"
34.104.230.169 - - [05/Sep/2026:23:29:57 +0200] "GET /.env.local HTTP/1.1" 307 4560 "-" "crusader-worker/1.0"
34.104.230.169 - - [05/Sep/2026:23:29:57 +0200] "GET /.env.old HTTP/1.1" 307 4554 "-" "crusader-worker/1.0"
34.104.230.169 - - [05/Sep/2026:23:29:57 +0200] "GET /.env.bak HTTP/1.1" 307 4555 "-" "crusader-worker/1.0"
34.104.230.169 - - [05/Sep/2026:23:29:57 +0200] "GET /.env.example HTTP/1.1" 307 4562 "-" "crusader-worker/1.0"
34.104.230.169 - - [05/Sep/2026:23:29:57 +0200] "GET /actuator/configprops HTTP/1.1" 307 4580 "-" "crusader-worker/1.0"
34.104.230.169 - - [05/Sep/2026:23:29:57 +0200] "GET /.env.dev HTTP/1.1" 307 4555 "-" "crusader-worker/1.0"
34.104.230.169 - - [05/Sep/2026:23:29:57 +0200] "GET /actuator/env HTTP/1.1" 307 4563 "-" "crusader-wor
show less
Web App Attack
Brute-Force
🇮🇹
VHosting
2026-09-05 20:40:04
(15 hours ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
🇬🇧
gurnip
2026-09-05 16:04:55
(19 hours ago)
Vulnerability probe of page /actuator/sessions, not found on server.
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-02 23:16:09
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.104.230.169 (169.230.104.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.104.230.169 (169.230.104.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 19:16:01.494206 2026] [security2:error] [pid 13327:tid 13327] [client 34.104.230.169:59928] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/config/config.yml" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.barbaraehill.com"] [uri "/app/config/config.yml"] [unique_id "apiuMQ7srMLIAOaCmxt2kAAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
Penny Packer
2026-09-02 10:55:32
(4 days ago)
Fail2Ban apache-tripwires
Web App Attack
🇺🇸
TPI-Abuse
2026-09-01 04:32:12
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 34.104.230.169 (169.230.104.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.104.230.169 (169.230.104.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 00:32:01.851006 2026] [security2:error] [pid 10412:tid 10412] [client 34.104.230.169:56322] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/config/config.yml" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.belize-boat-registration.com"] [uri "/app/config/config.yml"] [unique_id "apZVQalZBiMpJ0xQA83m5QAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack