๐ฉ๐ช
SwinT
2026-08-27 23:00:05
(19 seconds ago)
WAF repeated trigger detected by Fail2Ban in plesk-modsecurity jail
Web App Attack
Anonymous
2026-08-27 21:26:31
(1 hour ago)
Blocked by ModSec and CSF
Port Scan
๐บ๐ธ
eber965
2026-08-27 21:22:31
(1 hour ago)
[Thu Aug 27 17:22:30 2026] [authz_core:error] [pid 1791916:tid 140216488670976] [client 34.128.87.21 ...
show more
[Thu Aug 27 17:22:30 2026] [authz_core:error] [pid 1791916:tid 140216488670976] [client 34.128.87.214:36640] AH01630: client denied by server configuration: /var/www/html/.env.production
[Thu Aug 27 17:22:30 2026] [authz_core:error] [pid 1533042:tid 140216872445696] [client 34.128.87.214:36610] AH01630: client denied by server configuration: /var/www/html/.env
[Thu Aug 27 17:22:30 2026] [authz_core:error] [pid 1533042:tid 140216094410496] [client 34.128.87.214:36668] AH01630: client denied by server configuration: /var/www/html/.env.backup
[Thu Aug 27 17:22:30 2026] [authz_core:error] [pid 1532883:tid 140216614496000] [client 34.128.87.214:36678] AH01630: client denied by server configuration: /var/www/html/.env.old
[Thu Aug 27 17:22:30 2026] [authz_core:error] [pid 1532883:tid 140215507216128] [client 34.128.87.214:36624] AH01630: client denied by server configuration: /var/www/html/.env.local
...
show less
Brute-Force
๐ฉ๐ช
Gwyneth Llewelyn
2026-08-27 20:08:53
(2 hours ago)
2026/08/27 21:08:42 [error] 380595#380595: *967737 access forbidden by rule, client: 34.128.87.214, ...
show more
2026/08/27 21:08:42 [error] 380595#380595: *967737 access forbidden by rule, client: 34.128.87.214, server: [redacted], request: "GET /.env HTTP/1.1", host: "[redacted]"
34.128.87.214 - - [27/Aug/2026:21:08:42 +0100] "GET /.env HTTP/1.1" 403 2599 "-" "crusader-worker/1.0"
2026/08/27 21:08:51 [error] 380596#380596: *967742 access forbidden by rule, client: 34.128.87.214, server: [redacted], request: "GET //.env HTTP/1.1", host: "[redacted]"
show less
Brute-Force
Web App Attack
๐บ๐ธ
Rayulcifer
2026-08-27 19:58:40
(3 hours ago)
34.128.87.214 - - [27/Aug/2026:14:58:39 -0500] "GET /.env HTTP/1.1" 200 1139 "-" "crusader-worker/1. ...
show more
34.128.87.214 - - [27/Aug/2026:14:58:39 -0500] "GET /.env HTTP/1.1" 200 1139 "-" "crusader-worker/1.0"
...
show less
Open Proxy
Port Scan
Hacking
Web App Attack
SSH
๐ซ๐ฎ
YF
2026-08-27 17:00:43
(5 hours ago)
WordPress config file probe
Web App Attack
๐ฉ๐ช
4server
2026-08-27 16:46:02
(6 hours ago)
[ThuAug2718:45:58.1951422026][security2:error][pid1443300:tid1443566][client34.128.87.214:0]ModSecur ...
show more
[ThuAug2718:45:58.1951422026][security2:error][pid1443300:tid1443566][client34.128.87.214:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Patternmatch\"\(\?i\)\(\?:/\(\?:\^\|/\)\\\\\\\\.\(env\|git\|svn\|hg\|DS_Store\)\|/\(\?:wp-config\|\\\\\\\\.htaccess\|\\\\\\\\.htpasswd\)\|\\\\\\\\.\(\?:sql\|bak\|old\|log\)\$\)\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"156\"][id\"960720\"][msg\"Forbiddenfileaccessattempt\"][severity\"CRITICAL\"][hostname\"www.studio-portale.ch.136-243-54-122.cpanel.site\"][uri\"/.env.bak\"][unique_id\"apBpxnrP94oAfYNJIsz0JQAAAQo\"]
show less
Port Scan
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 16:29:07
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.128.87.214 (214.87.128.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.128.87.214 (214.87.128.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 12:29:00.094410 2026] [security2:error] [pid 10029:tid 10029] [client 34.128.87.214:48002] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "smartstylehair.com"] [uri "/.env.backup"] [unique_id "apBlzEC8Yz1Kd4QTuOLcfAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-27 16:18:04
(6 hours ago)
34.128.87.214 - - [27/Aug/2026:18:18:03 +0200] "GET /wp-config.php.swp HTTP/1.1" 404 1583 "-" "crusa ...
show more
34.128.87.214 - - [27/Aug/2026:18:18:03 +0200] "GET /wp-config.php.swp HTTP/1.1" 404 1583 "-" "crusader-worker/1.0"
34.128.87.214 - - [27/Aug/2026:18:18:03 +0200] "GET /wp-config.php.swp HTTP/1.1" 404 1252 "-" "crusader-worker/1.0"
34.128.87.214 - - [27/Aug/2026:18:18:03 +0200] "GET /actuator/configprops HTTP/1.1" 404 1583 "-" "crusader-worker/1.0"
34.128.87.214 - - [27/Aug/2026:18:18:03 +0200] "GET /actuator/configprops HTTP/1.1" 404 1252 "-" "crusader-worker/1.0"
34.128.87.214 - - [27/Aug/2026:18:18:03 +0200] "GET /.env.bak HTTP/1.1" 403 1561 "-" "crusader-worker/1.0"
34.128.87.214 - - [27/Aug/2026:18:18:03 +0200] "GET /.env.bak HTTP/1.1" 403 1230 "-" "crusader-worker/1.0"
34.128.87.214 - - [27/Aug/2026:18:18:03 +0200] "GET /.env.production HTTP/1.1" 404 1583 "-" "crusader-worker/1.0"
34.128.87.214 - - [27/Aug/2026:18:18:03 +0200] "GET /.env.production HTTP/1.1" 404 1252 "-" "crusader-worker/1.0"
34.128.87.214 - - [27/Aug/2026:18:18:03 +0200] "GET /env HTTP/1.1" 404 1583 "-" "crusade
...
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
0x44
2026-08-27 16:07:25
(6 hours ago)
TCP SYN Discovery - Flooding
DDoS Attack
Anonymous
2026-08-27 15:35:25
(7 hours ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
๐ท๐บ
DZBOT
2026-08-27 15:24:25
(7 hours ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 15:06:10
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.128.87.214 (214.87.128.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.128.87.214 (214.87.128.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 11:06:03.688955 2026] [security2:error] [pid 14048:tid 14048] [client 34.128.87.214:51906] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "drbbenefits.com"] [uri "/.env.production"] [unique_id "apBSW7EhRndXkArpLNELNQAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 14:50:48
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.128.87.214 (214.87.128.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.128.87.214 (214.87.128.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 10:50:42.712360 2026] [security2:error] [pid 4605:tid 4605] [client 34.128.87.214:43852] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.contrarianadvisors.royal-barbershop.com"] [uri "/.env.dev"] [unique_id "apBOwjU2M3BLwncdnPzicwAAACM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Mangelot Hosting
2026-08-27 13:30:58
(9 hours ago)
(wp_config_access) srv104 WordPress wp-config Scan 34.128.87.214 (ID/Indonesia/214.87.128.34.bc.goog ...
show more
(wp_config_access) srv104 WordPress wp-config Scan 34.128.87.214 (ID/Indonesia/214.87.128.34.bc.googleusercontent.com): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs:
show less
Web App Attack