🇩🇪
Hugopvigo
2026-09-06 17:02:42
(2 hours ago)
[Sun Sep 06 19:02:42.303044 2026] [authz_core:error] [pid 3069951:tid 126890379572928] [client 34.14 ...
show more
[Sun Sep 06 19:02:42.303044 2026] [authz_core:error] [pid 3069951:tid 126890379572928] [client 34.140.164.105:50158] AH01630: client denied by server configuration: /var/www/html/wordpress/backup.tar.gz
[Sun Sep 06 19:02:42.303632 2026] [authz_core:error] [pid 3069951:tid 126891132425920] [client 34.140.164.105:50164] AH01630: client denied by server configuration: /var/www/html/wordpress/backup.sql
[Sun Sep 06 19:02:42.303711 2026] [authz_core:error] [pid 3125798:tid 126891008698048] [client 34.140.164.105:50200] AH01630: client denied by server configuration: /var/www/html/wordpress/database.sql
...
show less
Hacking
Brute-Force
Web App Attack
SSH
🇨🇭
DasBiberlein
2026-09-06 06:25:54
(13 hours ago)
RdpGuard detected brute-force attempt on HTTP
Brute-Force
🇸🇪
Lemmy
2026-09-06 06:22:02
(13 hours ago)
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 05:04:48
(14 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.140.164.105 (105.164.140.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 34.140.164.105 (105.164.140.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 01:04:41.316456 2026] [security2:error] [pid 31574:tid 31574] [client 34.140.164.105:43258] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||accomplishedmagazine.com.gemexpressions.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "accomplishedmagazine.com.gemexpressions.com"] [uri "/backup.sql"] [unique_id "apz0aX9tmax2MiYlpQcDDgAAAFg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 03:51:58
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.140.164.105 (105.164.140.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.140.164.105 (105.164.140.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 23:51:51.412203 2026] [security2:error] [pid 2888:tid 2888] [client 34.140.164.105:54790] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.skyesongtollers.com"] [uri "/.env"] [unique_id "apzjVxyvSAaq1YLOAASU8wAAAIk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 03:01:19
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.140.164.105 (105.164.140.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.140.164.105 (105.164.140.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 23:01:13.088444 2026] [security2:error] [pid 7858:tid 7858] [client 34.140.164.105:41234] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.circleofsound.org"] [uri "/.env.old"] [unique_id "apzXeVeoPl0sNtpte2o55QAAAGo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-06 02:35:03
(17 hours ago)
suspicious request in access.log
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 01:59:07
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.140.164.105 (105.164.140.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.140.164.105 (105.164.140.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 21:59:00.415421 2026] [security2:error] [pid 3745:tid 3745] [client 34.140.164.105:37392] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mccarterestates.com"] [uri "/wp-config.php.swp"] [unique_id "apzI5GI0fDe5oM8vBRup4gAAACM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
kosada.com
2026-09-06 01:33:54
(18 hours ago)
Repeated exploit attempts, for example: /.env.save /.env (HTTP/1.1 port 443)
Web App Attack
Anonymous
2026-09-06 01:30:04
(18 hours ago)
Bot / scanning and/or hacking attempts: GET /.env.prod HTTP/1.1, GET /wp-config.php.swp HTTP/1.1, GE ...
show more
Bot / scanning and/or hacking attempts: GET /.env.prod HTTP/1.1, GET /wp-config.php.swp HTTP/1.1, GET /.env.bak HTTP/1.1, GET /storage/logs/laravel.log HTTP/1.1, GET /actuator/env HTTP/1.1, GET /wp-config.php~ HTTP/1.1, GET /crusader-404-probe HTTP/1.1, GET /actuator/configprops HTTP/1.1, GET /.env.example HTTP/1.1, GET /env HTTP/1.1, GET /.env.save HTTP/1.1, GET /.env.old HTTP/1.1, GET /.env HTTP/1.1
show less
Hacking
Web App Attack
🇳🇱
e.fierstra
2026-09-06 01:27:59
(18 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
🇬🇧
consul.to
2026-09-06 00:35:01
(19 hours ago)
Web attack/malicious scanning detected
Web App Attack
🇩🇪
neckaralb-admin.de
2026-09-06 00:33:11
(19 hours ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 00:16:03
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.140.164.105 (105.164.140.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.140.164.105 (105.164.140.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 20:16:00.123271 2026] [security2:error] [pid 20161:tid 20174] [client 34.140.164.105:50768] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "anglicancommission.com"] [uri "/.env.prod"] [unique_id "apywwM_VgwQvGGlVJ-nSfQAAAEs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
dynamix
2026-09-06 00:09:42
(19 hours ago)
Multiple WAF Violations
Web App Attack