🇺🇸
TPI-Abuse
2026-09-04 15:15:43
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.121.17.137 (137.17.121.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.121.17.137 (137.17.121.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 11:15:37.068434 2026] [security2:error] [pid 21440:tid 21440] [client 34.121.17.137:56962] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.djmrmusic.com"] [uri "/wp-config.php.swp"] [unique_id "aprgmSjmkQHMWLpEQpSgugAAAC4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
MusicLibrary
2026-09-04 14:34:16
(19 hours ago)
Attempted access to sensitive configuration files (.env, .git, etc.)
Bad Web Bot
Web App Attack
🇺🇸
MPL
2026-09-04 14:32:18
(19 hours ago)
tcp ports: 80,443 (76 or more attempts)
Port Scan
🇺🇸
TPI-Abuse
2026-09-04 14:07:02
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.121.17.137 (137.17.121.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.121.17.137 (137.17.121.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 10:06:52.747653 2026] [security2:error] [pid 26473:tid 26508] [client 34.121.17.137:53226] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.certificationwiki.com"] [uri "/wp-config.php.bak"] [unique_id "aprQfCXXwczvxj3cIwPZdQAAAFE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 12:31:45
(21 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.121.17.137 (137.17.121.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.121.17.137 (137.17.121.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 08:31:37.098160 2026] [security2:error] [pid 13627:tid 13627] [client 34.121.17.137:54056] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ftp.southtncardio.com"] [uri "/wp-config.php.bak"] [unique_id "apq6KZNLdkNDenGrg0usAAAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇸🇪
vaia.cloud
2026-09-04 11:55:03
(22 hours ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
🇮🇹
VHosting
2026-09-04 11:45:03
(22 hours ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
🇺🇸
kosada.com
2026-09-04 11:24:16
(22 hours ago)
Repeated exploit attempts, for example: /.env.example /.env (HTTP/1.1 port 443)
Web App Attack
Anonymous
2026-09-04 11:05:44
(22 hours ago)
Trapped by Fail2Ban: Too many login failures from 34.121.17.137
Brute-Force
Hacking
🇺🇸
TPI-Abuse
2026-09-04 10:56:36
(23 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.121.17.137 (137.17.121.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.121.17.137 (137.17.121.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 06:56:31.848988 2026] [security2:error] [pid 23159:tid 23159] [client 34.121.17.137:48988] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||bitcoincasting.usaangelinvestors.com|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "bitcoincasting.usaangelinvestors.com"] [uri "/wp-config.php.bak"] [unique_id "apqj34obMG5e76rOtfesbAAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
WeCloudit-Anti-Abuse
2026-09-04 10:52:55
(23 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
Anonymous
2026-09-04 10:52:34
(23 hours ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack