๐บ๐ธ
mnsf
2026-08-29 00:08:49
(11 minutes ago)
Abuse Detected (10)
Brute-Force
Web App Attack
๐ฉ๐ช
LRob
2026-08-28 23:52:44
(27 minutes ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /wp-config.php~ (+12 more) | 2026-08-28 23:52 UTC
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 23:43:05
(37 minutes ago)
(mod_security) mod_security (id:210492) triggered by 34.134.58.178 (178.58.134.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.134.58.178 (178.58.134.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 19:43:00.643850 2026] [security2:error] [pid 2719:tid 2719] [client 34.134.58.178:37790] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.scc1.us"] [uri "/.env.local"] [unique_id "apIdBKwo9E0H3EOfaMCXUwAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
gadix
2026-08-28 23:34:20
(46 minutes ago)
[29/Aug/2026:01:34:18.363271 +0200] apIa-lYH19tetM6pesJhngAAAAE 34.134.58.178 36582 127.0.0.1 7081
[ ...
show more
[29/Aug/2026:01:34:18.363271 +0200] apIa-lYH19tetM6pesJhngAAAAE 34.134.58.178 36582 127.0.0.1 7081
[29/Aug/2026:01:34:18.365779 +0200] apIa-iFpQ99ZRmP-sDCGIAAAAAA 34.134.58.178 36586 127.0.0.1 7081
[29/Aug/2026:01:34:18.368459 +0200] apIa-qIKUwwVpQtH5yu5TwAAAAU 34.134.58.178 36598 127.0.0.1 7081
...
show less
Web App Attack
Anonymous
2026-08-28 23:14:02
(1 hour ago)
Bot / scanning and/or hacking attempts: GET /env HTTP/1.1, GET /.env.backup HTTP/1.1, GET /wp-config ...
show more
Bot / scanning and/or hacking attempts: GET /env HTTP/1.1, GET /.env.backup HTTP/1.1, GET /wp-config.php~ HTTP/1.1, GET /.env.prod HTTP/1.1
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 21:50:43
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.134.58.178 (178.58.134.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.134.58.178 (178.58.134.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 17:50:35.697628 2026] [security2:error] [pid 2787:tid 2787] [client 34.134.58.178:53508] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "larrystransmissions.com"] [uri "/.env.local"] [unique_id "apICqyNHsQ0eQ2YtKzcJHwAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 21:34:26
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.134.58.178 (178.58.134.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.134.58.178 (178.58.134.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 17:34:17.689977 2026] [security2:error] [pid 8663:tid 8663] [client 34.134.58.178:34008] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "delunafamily.com"] [uri "/.env.old"] [unique_id "apH-2XXrEi6tiVS_8SWIxgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐ช
AutosOnShow
2026-08-28 21:34:05
(2 hours ago)
blocked for webapp attack | path requested: / | seen at 2026-08-28 21:33:07.688 |
Web App Attack
๐ธ๐ช
vaia.cloud
2026-08-28 21:10:01
(3 hours ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
๐จ๐ฟ
ddw
2026-08-28 20:10:36
(4 hours ago)
ModSecurity detection - Rules: 949110(Inbound Anomaly Score Exceeded (Total Score: 10))
Web App Attack
๐ณ๐ฑ
debestelapp
2026-08-28 20:00:07
(4 hours ago)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 19:13:36
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.134.58.178 (178.58.134.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.134.58.178 (178.58.134.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 15:13:29.501858 2026] [security2:error] [pid 31286:tid 31286] [client 34.134.58.178:34046] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "alexthepunk.com"] [uri "/.env.production"] [unique_id "apHd2USLhoEFGmbUADhZFwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
antlac1
2026-08-28 19:05:38
(5 hours ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 18:54:11
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.134.58.178 (178.58.134.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.134.58.178 (178.58.134.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 14:54:05.879237 2026] [security2:error] [pid 26149:tid 26149] [client 34.134.58.178:52598] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.ifilemuseum.title26.com"] [uri "/.env.backup"] [unique_id "apHZTewSqqXyrG4wRcNJpgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-28 18:49:40
(5 hours ago)
CrowdSec ban: crowdsecurity/http-probing
Port Scan