Anonymous
2026-09-06 06:19:52
(5 hours ago)
RdpGuard detected brute-force attempt on HTTP
Brute-Force
Anonymous
2026-09-06 06:07:38
(5 hours ago)
WordPress Sensitive System Files Information Disclosure.
Hacking
🇩🇪
bazter.pro
2026-09-06 06:05:14
(5 hours ago)
Fail2Ban: plesk-bot-aggressive - 15 failures
Port Scan
Bad Web Bot
Web App Attack
🇲🇽
octageeks.com
2026-09-06 04:23:18
(6 hours ago)
Wordpress malicious attack:[octablocked]
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 03:53:45
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.106.162.225 (225.162.106.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.106.162.225 (225.162.106.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 23:53:38.840024 2026] [security2:error] [pid 11952:tid 11952] [client 34.106.162.225:54408] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.astrology7.com"] [uri "/wp-config.php~"] [unique_id "apzjwnIt_LNAqNOeLqEJLgAAACg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 03:26:19
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.106.162.225 (225.162.106.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.106.162.225 (225.162.106.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 23:26:15.116117 2026] [security2:error] [pid 14206:tid 14206] [client 34.106.162.225:39500] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "caribeanvacationsturs.com"] [uri "/.env"] [unique_id "apzdVxeWQUgid605p_uvtQAAAEI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇱🇻
garmtech.com
2026-09-06 03:00:16
(8 hours ago)
Attempted access to sensitive endpoint (/.env.bak) detected. Automated scan or unauthorized probing.
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 02:29:56
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.106.162.225 (225.162.106.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.106.162.225 (225.162.106.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 22:29:50.689612 2026] [security2:error] [pid 12579:tid 12579] [client 34.106.162.225:54186] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "soulwolf.com"] [uri "/.env.bak"] [unique_id "apzQHs_v0LWe46jba0aPgwAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 01:45:11
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.106.162.225 (225.162.106.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.106.162.225 (225.162.106.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 21:45:03.789392 2026] [security2:error] [pid 24505:tid 24505] [client 34.106.162.225:47522] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ftp.willmarksynthetics.com"] [uri "/.env.save"] [unique_id "apzFn7wZJclBM6OHRt-t4QAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
WeCloudit-Anti-Abuse
2026-09-06 00:38:48
(10 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
🇬🇧
Aetherweb Ark
2026-09-06 00:36:39
(10 hours ago)
(mod_security) mod_security (id:949110) triggered by 34.106.162.225 (US/United States/225.162.106.34 ...
show more
(mod_security) mod_security (id:949110) triggered by 34.106.162.225 (US/United States/225.162.106.34.bc.googleusercontent.com): N in the last X secs
show less
Web App Attack
🇦🇺
2000cn.com.au
2026-09-06 00:34:38
(10 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-06 00:30:12
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.106.162.225 (225.162.106.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.106.162.225 (225.162.106.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 20:30:05.354127 2026] [security2:error] [pid 3496288:tid 3496288] [client 34.106.162.225:33570] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "nancybcatering.com"] [uri "/.env"] [unique_id "apy0DR_MBA-Pds4YNaFHugAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-06 00:28:51
(10 hours ago)
(config_exploit_scan) Configuratie Scanner / Nep GPTBot 34.106.162.225 (US/United States/225.162.106 ...
show more
(config_exploit_scan) Configuratie Scanner / Nep GPTBot 34.106.162.225 (US/United States/225.162.106.34.bc.googleusercontent.com): 3 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 34.106.162.225 - - [06/Sep/2026:02:28:46 +0200] "GET /.env.old HTTP/1.1" 406 4831 "-" "crusader-worker/1.0"
34.106.162.225 - - [06/Sep/2026:02:28:46 +0200] "GET /.env.production HTTP/1.1" 406 4830 "-" "crusader-worker/1.0"
34.106.162.225 - - [06/Sep/2026:02:28:46 +0200] "GET /.env.prod HTTP/1.1" 406 4829 "-" "crusader-worker/1.0"
show less
Port Scan
🇺🇸
mnsf
2026-09-06 00:05:51
(11 hours ago)
Scanning/Probing (16)
Brute-Force
Web App Attack