๐บ๐ธ
TPI-Abuse
2026-08-28 19:13:19
(26 minutes ago)
(mod_security) mod_security (id:210492) triggered by 34.139.68.175 (175.68.139.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.139.68.175 (175.68.139.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 15:13:13.503647 2026] [security2:error] [pid 28454:tid 28454] [client 34.139.68.175:58606] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.paolagallardo.ipostsocialmedia.com"] [uri "/wp-config.php.swp"] [unique_id "apHdyQws8sSAg26rcK7GXAAAACI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
itsolon
2026-08-28 18:29:27
(1 hour ago)
[28/Aug/2026:20:29:22 +0200] 178794176258.068106 34.139.68.175 0 217.154.7.177 443
[28/Aug/2026:20:2 ...
show more
[28/Aug/2026:20:29:22 +0200] 178794176258.068106 34.139.68.175 0 217.154.7.177 443
[28/Aug/2026:20:29:22 +0200] 178794176223.647458 34.139.68.175 0 217.154.7.177 443
[28/Aug/2026:20:29:22 +0200] 178794176268.128551 34.139.68.175 0 217.154.7.177 443
[28/Aug/2026:20:29:22 +0200] 178794176289.133030 34.139.68.175 0 217.154.7.177 443
[28/Aug/2026:20:29:22 +0200] 178794176288.084042 34.139.68.175 0 217.154.7.177 443
...
show less
Port Scan
Hacking
Brute-Force
Web App Attack
๐ฉ๐ช
gadix
2026-08-28 18:13:23
(1 hour ago)
[28/Aug/2026:20:13:23.191866 +0200] apHPwyYUBxCubAmmO4Rq6wAAAAw 34.139.68.175 34220 127.0.0.1 7081
[ ...
show more
[28/Aug/2026:20:13:23.191866 +0200] apHPwyYUBxCubAmmO4Rq6wAAAAw 34.139.68.175 34220 127.0.0.1 7081
[28/Aug/2026:20:13:23.199254 +0200] apHPwyYUBxCubAmmO4Rq7AAAAAo 34.139.68.175 34244 127.0.0.1 7081
[28/Aug/2026:20:13:23.200896 +0200] apHPwyYUBxCubAmmO4Rq7QAAAA0 34.139.68.175 34260 127.0.0.1 7081
...
show less
Web App Attack
๐ซ๐ท
ecode hosting
2026-08-28 17:16:04
(2 hours ago)
Domain : oztekintel.com
Rule : hack
2026-08-28 17:00:19 10.100.1.20 GET /wp-config.php.bak - 443 - 3 ...
show more
Domain : oztekintel.com
Rule : hack
2026-08-28 17:00:19 10.100.1.20 GET /wp-config.php.bak - 443 - 34.139.68.175 HTTP/1.1 crusader-worker/1.0 - oztekintel.com 404 0 64 0 103 1459 - -
show less
Hacking
SQL Injection
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-08-28 16:07:38
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.139.68.175 (175.68.139.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.139.68.175 (175.68.139.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 12:07:31.433313 2026] [security2:error] [pid 25792:tid 25792] [client 34.139.68.175:48730] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "nathsharmaandcompany.com"] [uri "/.env.local"] [unique_id "apGyQ6A6uB-5Mqp4RnOyMwAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-08-28 15:42:06
(3 hours ago)
Multiple WAF Violations
Web App Attack
Anonymous
2026-08-28 14:15:02
(5 hours ago)
suspicious request in access.log
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 14:09:52
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.139.68.175 (175.68.139.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.139.68.175 (175.68.139.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 10:09:47.613981 2026] [security2:error] [pid 19664:tid 19709] [client 34.139.68.175:42294] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.artbox.cibernetic.com"] [uri "/.env.prod"] [unique_id "apGWq3OzscTQeWZ4X8CsdgAAAY0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-28 14:04:11
(5 hours ago)
(config_exploit_scan) Configuratie Scanner / Nep GPTBot 34.139.68.175 (US/United States/175.68.139.3 ...
show more
(config_exploit_scan) Configuratie Scanner / Nep GPTBot 34.139.68.175 (US/United States/175.68.139.34.bc.googleusercontent.com): 3 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 34.139.68.175 - - [28/Aug/2026:16:04:07 +0200] "GET /.env.local HTTP/1.1" 406 4831 "-" "crusader-worker/1.0"
34.139.68.175 - - [28/Aug/2026:16:04:07 +0200] "GET /.env.save HTTP/1.1" 406 4830 "-" "crusader-worker/1.0"
34.139.68.175 - - [28/Aug/2026:16:04:07 +0200] "GET /.env.backup HTTP/1.1" 406 4831 "-" "crusader-worker/1.0"
show less
Port Scan
๐ฉ๐ช
dpsbs
2026-08-28 12:46:56
(6 hours ago)
multiple ips intrustions detected
Hacking
๐บ๐ธ
TPI-Abuse
2026-08-28 12:07:16
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.139.68.175 (175.68.139.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.139.68.175 (175.68.139.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 08:07:08.943072 2026] [security2:error] [pid 23598:tid 23598] [client 34.139.68.175:59578] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "holtzheimer.net"] [uri "/.env"] [unique_id "apF57Cq8gfQ1bGijcO6O_QAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-08-28 12:06:39
(7 hours ago)
Scanning/Probing (20)
Brute-Force
Web App Attack
๐ธ๐ช
vaia.cloud
2026-08-28 11:45:03
(7 hours ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
๐ฉ๐ช
enjoyably
2026-08-28 10:53:59
(8 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐ฎ๐น
VHosting
2026-08-28 10:20:04
(9 hours ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack