🇺🇸
TPI-Abuse
2026-09-08 13:10:29
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.138.77.242 (242.77.138.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.138.77.242 (242.77.138.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 09:10:25.818586 2026] [security2:error] [pid 7677:tid 7677] [client 34.138.77.242:35108] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ftp.lemobba.com"] [uri "/wp-config.php~"] [unique_id "aqAJQUGYSWBNrsJBVm1UEwAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 11:43:03
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.138.77.242 (242.77.138.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.138.77.242 (242.77.138.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 07:42:55.439788 2026] [security2:error] [pid 6956:tid 6956] [client 34.138.77.242:42708] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ftp.thetallships.com"] [uri "/.env.save"] [unique_id "ap_0vxPJ3MwU91e_uMHX7QAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
consul.to
2026-09-08 09:56:34
(6 hours ago)
Web attack/malicious scanning detected
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 09:48:12
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.138.77.242 (242.77.138.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.138.77.242 (242.77.138.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 05:48:06.644741 2026] [security2:error] [pid 29260:tid 29260] [client 34.138.77.242:59324] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.mkdesignndetailing.com"] [uri "/.env"] [unique_id "ap_Z1m2s_d85I4-eb8VA_QAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇧🇪
cmbplf
2026-09-08 09:44:52
(6 hours ago)
448 requests with url.path *.sql.gz
Brute-Force
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-08 08:48:15
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.138.77.242 (242.77.138.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.138.77.242 (242.77.138.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 04:48:11.365201 2026] [security2:error] [pid 16227:tid 16227] [client 34.138.77.242:40828] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.perkowski.net"] [uri "/wp-config.php.swp"] [unique_id "ap_Ly7cj8ZJZRa7ESX1OeAAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇧🇷
SOC-BR
2026-09-08 07:28:44
(8 hours ago)
Attack detected by Fortinet - applications3: Spring.Boot.Actuator.Unauthorized.Access - 2026-09-07 1 ...
show more
Attack detected by Fortinet - applications3: Spring.Boot.Actuator.Unauthorized.Access - 2026-09-07 11:40:07 - Source Port 59496
show less
Port Scan
Hacking
🇺🇸
TPI-Abuse
2026-09-08 04:21:47
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.138.77.242 (242.77.138.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.138.77.242 (242.77.138.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 00:21:42.617265 2026] [security2:error] [pid 11832:tid 11832] [client 34.138.77.242:38398] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.iee-usa.com"] [uri "/.env.bak"] [unique_id "ap-NVgREn2Wsa0pk1TVH9wAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
lavnet.net
2026-09-08 04:13:40
(11 hours ago)
34.138.77.242 - - [08/Sep/2026:04:13:40 +0000] "GET /.env.example HTTP/1.1" 404 4361 "-" "crusader-w ...
show more
34.138.77.242 - - [08/Sep/2026:04:13:40 +0000] "GET /.env.example HTTP/1.1" 404 4361 "-" "crusader-worker/1.0"
34.138.77.242 - - [08/Sep/2026:04:13:40 +0000] "GET /env HTTP/1.1" 404 4360 "-" "crusader-worker/1.0"
34.138.77.242 - - [08/Sep/2026:04:13:40 +0000] "GET /.env.backup HTTP/1.1" 404 4361 "-" "crusader-worker/1.0"
34.138.77.242 - - [08/Sep/2026:04:13:40 +0000] "GET /.env.save HTTP/1.1" 404 4361 "-" "crusader-worker/1.0"
34.138.77.242 - - [08/Sep/2026:04:13:40 +0000] "GET /.env.prod HTTP/1.1" 404 4360 "-" "crusader-worker/1.0"
34.138.77.242 - - [08/Sep/2026:04:13:40 +0000] "GET /wp-config.php.bak HTTP/1.1" 404 4361 "-" "crusader-worker/1.0"
...
show less
Brute-Force
🇺🇸
TPI-Abuse
2026-09-08 02:29:32
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.138.77.242 (242.77.138.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.138.77.242 (242.77.138.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 22:29:27.001178 2026] [security2:error] [pid 13214:tid 13214] [client 34.138.77.242:58202] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.sierrablue.farm"] [uri "/.env.old"] [unique_id "ap9zB2upCm6JfkzhaJb2rAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-07 20:57:50
(19 hours ago)
Blocked by siteaihub.com: live autoban: 10 attacks in 5min
Hacking
Bad Web Bot
🇪🇸
raiolanetworks.com
2026-09-06 16:36:25
(1 day ago)
Honeypot detection: web application attack. 3 events observed. Reported automatically from a honeypo ...
show more
Honeypot detection: web application attack. 3 events observed. Reported automatically from a honeypot sensor.
show less
Web App Attack
🇩🇪
4server
2026-09-06 03:53:59
(2 days ago)
[SunSep0605:53:53.2049952026][security2:error][pid2403698:tid2403732][client34.138.77.242:0]ModSecur ...
show more
[SunSep0605:53:53.2049952026][security2:error][pid2403698:tid2403732][client34.138.77.242:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Patternmatch\"\(\?i\)\(\?:/\(\?:\^\|/\)\\\\\\\\.\(env\|git\|svn\|hg\|DS_Store\)\|/\(\?:wp-config\|\\\\\\\\.htaccess\|\\\\\\\\.htpasswd\)\|\\\\\\\\.\(\?:sql\|bak\|old\|log\)\$\)\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"156\"][id\"960720\"][msg\"Forbiddenfileaccessattempt\"][severity\"CRITICAL\"][hostname\"cpcontacts.albertiarnaldoluigi.ch\"][uri\"/wp-config.php~\"][unique_id\"apzj0S5sCNT_GLHdYTk1tQAAAYA\"]
show less
Port Scan
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 03:48:37
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.138.77.242 (242.77.138.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.138.77.242 (242.77.138.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 23:48:32.201609 2026] [security2:error] [pid 25651:tid 25651] [client 34.138.77.242:39730] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.beachweddingnapkins.com"] [uri "/wp-config.php.swp"] [unique_id "apzikHCvbfLAMLtAYuKLvwAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 03:00:59
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.138.77.242 (242.77.138.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.138.77.242 (242.77.138.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 23:00:53.905504 2026] [security2:error] [pid 2772:tid 2772] [client 34.138.77.242:37624] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "walterjhoodco.com"] [uri "/.env.backup"] [unique_id "apzXZaEJJa-FtwmP-yRt9gAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack