π³π±
Cloud86 B.V.
2026-09-01 23:26:02
(7 hours ago)
categories: DDoS Attack
DDoS Attack
πΊπΈ
TPI-Abuse
2026-09-01 13:49:10
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.141.40.42 (42.40.141.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.141.40.42 (42.40.141.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 09:49:05.641968 2026] [security2:error] [pid 226455:tid 226557] [client 34.141.40.42:46850] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.tomithai.com"] [uri "/wp-config.php.swp"] [unique_id "apbX0bAlSH7yQ6QV7T0uzwAAAM0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-01 13:45:31
(17 hours ago)
Observed scanned 12 known-sensitive endpoint(s), e.g.: /, /%2eenv, /.ENV, /.env, /.env.bak, /.env.ol ...
show more
Observed scanned 12 known-sensitive endpoint(s), e.g.: /, /%2eenv, /.ENV, /.env, /.env.bak, /.env.old
show less
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-01 12:22:28
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.141.40.42 (42.40.141.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.141.40.42 (42.40.141.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 08:22:24.965090 2026] [security2:error] [pid 22241:tid 22328] [client 34.141.40.42:37686] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "schecter.org"] [uri "/.env.example"] [unique_id "apbDgGXeETkt3gyVFH9E5wAAAMQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
FD-IX
2026-09-01 11:09:26
(20 hours ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-01 11:01:45
(20 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.141.40.42 (42.40.141.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.141.40.42 (42.40.141.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 07:01:41.538403 2026] [security2:error] [pid 12137:tid 12137] [client 34.141.40.42:53462] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.manninglandservices.com"] [uri "/.env.local"] [unique_id "apawldkR44D-H0pKRGWFOAAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π¬π§
consul.to
2026-09-01 10:14:22
(21 hours ago)
Web attack/malicious scanning detected
Web App Attack
πΊπΈ
daveoctober
2026-09-01 10:11:23
(21 hours ago)
October Sentinel: honeypot triggered
Bad Web Bot
Web App Attack
πΊπ¦
URAN Publishing Service
2026-09-01 09:54:14
(21 hours ago)
[01/Sep/2026:12:54:14 +0300] -- 34.141.40.42 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.env. ...
show more
[01/Sep/2026:12:54:14 +0300] -- 34.141.40.42 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.env.backup HTTP/1.1
show less
Bad Web Bot
Web App Attack
π΅π«
www.gregorymariani.com
2026-09-01 09:23:14
(21 hours ago)
34.141.40.42 - - [01/Sep/2026:09:23:13 +0000] "GET /.env.save HTTP/1.1" 401 172 "-" "crusader-worker ...
show more
34.141.40.42 - - [01/Sep/2026:09:23:13 +0000] "GET /.env.save HTTP/1.1" 401 172 "-" "crusader-worker/1.0" 410 0.000 [default-comfy-mars-service-80] [] - - - - 61c624645309429d4a55591d2be33fa8
34.141.40.42 - - [01/Sep/2026:09:23:13 +0000] "GET /.env.local HTTP/1.1" 401 172 "-" "crusader-worker/1.0" 411 0.000 [default-comfy-mars-service-80] [] - - - - 923dae6671f667e2ed0b474dda48d66a
34.141.40.42 - - [01/Sep/2026:09:23:13 +0000] "GET /crusader-404-probe HTTP/1.1" 401 172 "-" "crusader-worker/1.0" 419 0.000 [default-comfy-mars-service-80] [] - - - - 9a9f77511b38a310db0811216eaf94e2
...
show less
Brute-Force
πΊπΈ
TPI-Abuse
2026-09-01 09:21:20
(22 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.141.40.42 (42.40.141.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.141.40.42 (42.40.141.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 05:21:16.437949 2026] [security2:error] [pid 4414:tid 4414] [client 34.141.40.42:52934] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "survey.joebankx.com"] [uri "/wp-config.php~"] [unique_id "apaZDNaxKsjxYEL2AG8Y3wAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-01 09:20:13
(22 hours ago)
IP banned by Fail2Ban in jail nginx-abusive-ips
Web App Attack
Brute-Force
Bad Web Bot
πΊπ¦
Olexiy Backend
2026-09-01 08:32:12
(22 hours ago)
34.141.40.42
...
Bad Web Bot
Web App Attack
Anonymous
2026-09-01 07:41:43
(23 hours ago)
Observed scanned 1 known-sensitive endpoint(s), e.g.: /.env.production
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-01 06:43:23
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.141.40.42 (42.40.141.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.141.40.42 (42.40.141.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 02:43:19.879334 2026] [security2:error] [pid 3382:tid 3382] [client 34.141.40.42:39356] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "swindontkd.swindon-itf.com"] [uri "/.env"] [unique_id "apZ0ByHgJh_sU5qnvFpi9gAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack