Anonymous
2026-08-27 22:10:43
(40 minutes ago)
WordPress Enforcement Protection.
Web App Attack
๐ฉ๐ช
factor1
2026-08-27 20:43:01
(2 hours ago)
CrowdSec at thor Reports Abuse
Web App Attack
๐ฉ๐ช
Uwe Sarpe
2026-08-27 20:09:15
(2 hours ago)
[Thu Aug 27 22:09:14.623440 2026] [access_compat:error] [pid 564914:tid 564914] [client 34.139.75.13 ...
show more
[Thu Aug 27 22:09:14.623440 2026] [access_compat:error] [pid 564914:tid 564914] [client 34.139.75.134:59796] AH01797: client denied by server configuration: /var/www/.env.example
[Thu Aug 27 22:09:14.624700 2026] [access_compat:error] [pid 564919:tid 564919] [client 34.139.75.134:59712] AH01797: client denied by server configuration: /var/www/.env.dev
[Thu Aug 27 22:09:14.625817 2026] [access_compat:error] [pid 564913:tid 564913] [client 34.139.75.134:59720] AH01797: client denied by server configuration: /var/www/crusader-404-probe
[Thu Aug 27 22:09:14.627259 2026] [access_compat:error] [pid 564915:tid 564915] [client 34.139.75.134:59698] AH01797: client denied by server configuration: /var/www/.env.prod
[Thu Aug 27 22:09:14.628219 2026] [access_compat:error] [pid 564921:tid 564921] [client 34.139.75.134:59744] AH01797: client denied by server configuration: /var/www/wp-config.php.swp
...
show less
Brute-Force
Web App Attack
๐ณ๐ฑ
debestelapp
2026-08-27 19:05:07
(3 hours ago)
Web App Attack
๐ท๐บ
DZBOT
2026-08-27 19:04:07
(3 hours ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 18:52:37
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.139.75.134 (134.75.139.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.139.75.134 (134.75.139.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 14:52:31.676601 2026] [security2:error] [pid 3364193:tid 3364233] [client 34.139.75.134:56082] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "anthonydalessandro.com"] [uri "/wp-config.php~"] [unique_id "apCHb2Frw0a5QvBUUd_Z_wAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
4server
2026-08-27 18:46:03
(4 hours ago)
[ThuAug2720:46:01.0400912026][security2:error][pid1560900:tid1561108][client34.139.75.134:0]ModSecur ...
show more
[ThuAug2720:46:01.0400912026][security2:error][pid1560900:tid1561108][client34.139.75.134:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:5\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.10\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"fitnessgallery.ch.136-243-54-122.cpanel.site\"][uri\"/.env.dev\"][unique_id\"apCF6XL5hi00rfGDg-sujwAAAEw\"]
show less
Port Scan
Brute-Force
Web App Attack
๐ฉ๐ช
LRob
2026-08-27 18:39:44
(4 hours ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /.env.example (+6 more) | 2026-08-27 18:39 UTC
show less
Hacking
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-08-27 17:50:50
(5 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 17:40:53
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.139.75.134 (134.75.139.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.139.75.134 (134.75.139.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 13:40:46.336310 2026] [security2:error] [pid 31492:tid 31492] [client 34.139.75.134:57918] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.file.kircali.net"] [uri "/wp-config.php.bak"] [unique_id "apB2ntSjEA6_0aFGSdAEOgAAACw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 17:07:24
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.139.75.134 (134.75.139.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.139.75.134 (134.75.139.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 13:07:19.579107 2026] [security2:error] [pid 23383:tid 23383] [client 34.139.75.134:33036] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jnpmarinesolutions.com"] [uri "/.env.bak"] [unique_id "apBux-sStt5bwjaKSMRqlwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 16:18:31
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.139.75.134 (134.75.139.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.139.75.134 (134.75.139.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 12:18:28.218907 2026] [security2:error] [pid 10696:tid 10761] [client 34.139.75.134:46802] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "graphicninjastudios.com.kincers.com"] [uri "/.env.local"] [unique_id "apBjVETnz39pcL7wjuyVZQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 16:01:59
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.139.75.134 (134.75.139.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.139.75.134 (134.75.139.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 12:01:51.257252 2026] [security2:error] [pid 20452:tid 20452] [client 34.139.75.134:49292] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.estate36.yankeetownfishing.com"] [uri "/.env"] [unique_id "apBfb47nsHz-nmRKaVrixAAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
MM-bot
2026-08-27 15:47:44
(7 hours ago)
URL-probe: HTTP/1.1 GET request on /.env (2026-08-27 17:47:44 UTC+2)
Web App Attack
Hacking
๐ฉ๐ช
neckaralb-admin.de
2026-08-27 15:42:34
(7 hours ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack