🇳🇱
e.fierstra
2026-08-29 17:50:51
(31 minutes ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
🇳🇱
debestelapp
2026-08-29 17:35:08
(46 minutes ago)
Web App Attack
Anonymous
2026-08-29 16:10:04
(2 hours ago)
| Suspicious URL access.
Web App Attack
Hacking
SQL Injection
🇬🇧
OptimusGO
2026-08-29 15:21:37
(3 hours ago)
Malicious activity detected: web_attack
Server: commstackbc (185.127.18.66)
Attack: web_attack
Time ...
show more
Malicious activity detected: web_attack
Server: commstackbc (185.127.18.66)
Attack: web_attack
Timestamp: 2026-08-29 16:21:37 UTC
Log evidence:
34.125.142.130 - - [29/Aug/2026:16:21:31 +0100] "GET / HTTP/1.1" 200 409 "-" "Mozilla/5.0 (Linux; Android 8; Mi 8 Explorer Edition; Build/OPM3.221001.211) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/130.0.6723.101 Mobile Safari/537.36"
08/29/2026-16:21:36.398507 [wDrop] [**] [1:7000500:1] FINSERV CRITICAL: Aggressive Port Scan [**] [Classification: Attempted Information Leak] [Priority: 2] {TCP} 34.125.142.130:14794 -> 185.127.18.66:443
08/29/2026-16:21:36.398507 [**] [1:9000060:2] AUTONOMOUS Long-term Reconnaissance [**] [Classification: (null)] [Priority: 2] {TCP} 34.125.142.130:14794 -> 185.127.18.66:443
show less
Port Scan
Brute-Force
🇩🇪
ghostwarriors
2026-08-29 13:20:29
(5 hours ago)
Webpage scraping
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-29 11:45:24
(6 hours ago)
Portscan: TCP/8080 (3x), TCP/8443 (3x), TCP/443, TCP/80
Port Scan
🇩🇪
ger-stg-sifi1
2026-08-29 11:38:57
(6 hours ago)
(wordpress) Failed wordpress login using wp-login.php or xmlrpc.php
Web App Attack
🇩🇪
FeG Deutschland
2026-08-29 10:02:03
(8 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 1247
Exploited Host
Web App Attack
🇺🇸
TPI-Abuse
2026-08-29 10:00:15
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.125.142.130 (130.142.125.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.125.142.130 (130.142.125.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 06:00:09.850336 2026] [security2:error] [pid 27489:tid 27489] [client 34.125.142.130:7324] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.drgas.com"] [uri "/@fs/.env"] [unique_id "apKtqcmgr-SJyF8lNsB82AAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇿
Antinson
2026-08-29 09:16:20
(9 hours ago)
Scraping with a high error ratio and request rate
Bad Web Bot
🇩🇪
Hazzard
2026-08-29 08:44:54
(9 hours ago)
(mod_security) mod_security triggered on hostname [redacted]): (CF_ENABLE)
SQL Injection
🇺🇸
TPI-Abuse
2026-08-29 08:41:24
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.125.142.130 (130.142.125.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.125.142.130 (130.142.125.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 04:41:20.397128 2026] [security2:error] [pid 19893:tid 19893] [client 34.125.142.130:10512] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.scoretopicturenetwork.com"] [uri "/@fs/.env"] [unique_id "apKbMOs6CnqnG3KaQZuaOgAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-29 08:21:42
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.125.142.130 (130.142.125.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.125.142.130 (130.142.125.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 04:21:36.285164 2026] [security2:error] [pid 85711:tid 85818] [client 34.125.142.130:24234] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sellarsmail.com"] [uri "/@fs/.env.production"] [unique_id "apKWkEQvfVR31JRUvG6VqgAAAMg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇸🇪
vaia.cloud
2026-08-29 08:10:02
(10 hours ago)
crowdsecurity/http-probing
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-08-29 07:27:07
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.125.142.130 (130.142.125.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.125.142.130 (130.142.125.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 03:27:02.512603 2026] [security2:error] [pid 19814:tid 19814] [client 34.125.142.130:37110] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.tracytappan.net"] [uri "/@fs/root/.env"] [unique_id "apKJxlg0GxoQCHvQIkcFbQAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack