๐ท๐ด
clauss
2026-09-01 13:57:48
(2 hours ago)
34.141.62.124 - - [01/Sep/2026:16:57:47 +0300] "GET /wp-config.php.swp HTTP/1.1" 401 36 "-" "crusade ...
show more
34.141.62.124 - - [01/Sep/2026:16:57:47 +0300] "GET /wp-config.php.swp HTTP/1.1" 401 36 "-" "crusader-worker/1.0"
34.141.62.124 - - [01/Sep/2026:16:57:47 +0300] "GET /actuator/env HTTP/1.1" 401 36 "-" "crusader-worker/1.0"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 13:56:20
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.141.62.124 (124.62.141.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.141.62.124 (124.62.141.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 09:56:16.550219 2026] [security2:error] [pid 23049:tid 23049] [client 34.141.62.124:54892] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.vaezi.com"] [uri "/wp-config.php.swp"] [unique_id "apbZgPhGuQRZo5YZkuojUQAAACk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
alferez
2026-09-01 13:02:53
(3 hours ago)
Searching .(env|sql|zip|tar|rar) files
Hacking
Exploited Host
Web App Attack
๐จ๐ญ
4server
2026-09-01 12:37:41
(3 hours ago)
[TueSep0114:37:33.7522962026][security2:error][pid3279182:tid3279503][client34.141.62.124:0]ModSecur ...
show more
[TueSep0114:37:33.7522962026][security2:error][pid3279182:tid3279503][client34.141.62.124:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\".env\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"610\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"carolin-mizio.ch.81-17-25-250.cpanel.site\"][uri\"/.env.local\"][unique_id\"apbHDYd4NhccL0i7RDaAfwAAARU\"]
show less
Hacking
Web App Attack
๐ซ๐ท
masterguru
2026-09-01 12:14:18
(4 hours ago)
Restricted File Access Attempt. Matched phrase ".env" at REQUEST_FILENAME. (930130-195)
Hacking
Web App Attack
๐ฎ๐ฉ
Burayot
2026-09-01 11:39:24
(4 hours ago)
LF_MODSEC: (mod_security) mod_security (id:949110) triggered by 34.141.62.124 (DE/Germany/124.62.141 ...
show more
LF_MODSEC: (mod_security) mod_security (id:949110) triggered by 34.141.62.124 (DE/Germany/124.62.141.34.bc.googleusercontent.com): 2 in the last 3600 secs
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 11:00:14
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.141.62.124 (124.62.141.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.141.62.124 (124.62.141.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 07:00:07.787297 2026] [security2:error] [pid 20744:tid 20744] [client 34.141.62.124:35852] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "web233.dnchosting.com"] [uri "/.env.production"] [unique_id "apawN10GD1OEyeFp0eLfqgAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ท๐ธ
Smel
2026-09-01 10:22:02
(6 hours ago)
HTTP/80/443/8080 Unauthorized Probe, Hack -
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 10:17:51
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.141.62.124 (124.62.141.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.141.62.124 (124.62.141.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 06:17:47.400340 2026] [security2:error] [pid 18384:tid 18414] [client 34.141.62.124:47596] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "accreditedfinancialanalyst.com"] [uri "/wp-config.php.bak"] [unique_id "apamS42cWXFxcFZVhtXTvgAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
MusicLibrary
2026-09-01 10:04:07
(6 hours ago)
Attempted access to sensitive configuration files (.env, .git, etc.)
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 08:48:54
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.141.62.124 (124.62.141.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.141.62.124 (124.62.141.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 04:48:49.829779 2026] [security2:error] [pid 23236:tid 23236] [client 34.141.62.124:57708] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "seychelles-boat-registration.com"] [uri "/.env"] [unique_id "apaRcTwq1TeyFub5Nc5DSAAAADY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฒ๐พ
Rizzy
2026-09-01 08:44:37
(7 hours ago)
Multiple WAF Violations
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 07:10:39
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.141.62.124 (124.62.141.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.141.62.124 (124.62.141.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 03:10:32.442127 2026] [security2:error] [pid 3329:tid 3329] [client 34.141.62.124:43888] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mrepoch.art"] [uri "/.env.backup"] [unique_id "apZ6aJnepgkb6zoGvfsIDwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 06:42:16
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.141.62.124 (124.62.141.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.141.62.124 (124.62.141.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 02:42:11.816459 2026] [security2:error] [pid 15091:tid 15091] [client 34.141.62.124:46222] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "talleyrealtyofdothan.taltonfamily.com"] [uri "/.env.backup"] [unique_id "apZzw_D24U0ekUgp-QbGFwAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
COMAITE
2026-09-01 06:26:00
(9 hours ago)
Suspicious URL access.
Web App Attack