🇧🇾
lns.bz
2026-09-05 07:42:31
(3 hours ago)
Too many 404 requests [BY]
Web App Attack
🇳🇱
Savvii
2026-09-05 06:53:42
(4 hours ago)
15 attempts against mh-modsecurity-ban on mars
Brute-Force
Web App Attack
🇵🇱
TaKeN
2026-09-05 06:47:17
(4 hours ago)
Automated Wazuh local observation. Wazuh rule 31151 lvl=10 detected repeated HTTP web application pr ...
show more
Automated Wazuh local observation. Wazuh rule 31151 lvl=10 detected repeated HTTP web application probing from this source IP. Observed 1 matching blocked event(s) between 2026-09-05T08:47:17+02:00 and 2026-09-05T08:47:17+02:00. Sample requested paths: /_ignition/health-check.
show less
Web App Attack
Hacking
🇳🇱
e.fierstra
2026-09-04 15:00:41
(20 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 14:50:29
(20 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.142.37.201 (201.37.142.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.142.37.201 (201.37.142.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 10:50:25.326056 2026] [security2:error] [pid 17195:tid 17195] [client 34.142.37.201:51896] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "carlosmoltherapy.com.carlosmol.com"] [uri "/wp-config.php~"] [unique_id "aprasQcQJiZMC48Ja6THlQAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 14:08:46
(21 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.142.37.201 (201.37.142.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.142.37.201 (201.37.142.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 10:08:41.943848 2026] [security2:error] [pid 26556:tid 26647] [client 34.142.37.201:46156] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.oldnorthwestlandco.com"] [uri "/.env.example"] [unique_id "aprQ6RGE3qyeT5IYYBD_uwAAAZg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
raph
2026-09-04 14:02:40
(21 hours ago)
[Wordpress] crawler /wp-admin/*, /wp-content/*, etc.
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 13:42:02
(21 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.142.37.201 (201.37.142.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.142.37.201 (201.37.142.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 09:41:58.728028 2026] [security2:error] [pid 11497:tid 11497] [client 34.142.37.201:49928] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "tugofwarrior.com.teamwakimphotography.com"] [uri "/.env.example"] [unique_id "aprKppiGW_zq0iCsA3eooAAAADM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
WeCloudit-Anti-Abuse
2026-09-04 13:26:46
(22 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
🇩🇪
Dominik Lysiak
2026-09-04 12:55:24
(22 hours ago)
34.142.37.201 - - [04/Sep/2026:14:55:24 +0200] "GET /.env HTTP/1.1" 444 0 "-" "crusader-worker/1.0"
...
show more
34.142.37.201 - - [04/Sep/2026:14:55:24 +0200] "GET /.env HTTP/1.1" 444 0 "-" "crusader-worker/1.0"
34.142.37.201 - - [04/Sep/2026:14:55:24 +0200] "GET /wp-config.php.bak HTTP/1.1" 444 0 "-" "crusader-worker/1.0"
34.142.37.201 - - [04/Sep/2026:14:55:24 +0200] "GET /wp-config.php~ HTTP/1.1" 444 0 "-" "crusader-worker/1.0"
...
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 12:52:34
(22 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.142.37.201 (201.37.142.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.142.37.201 (201.37.142.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 08:52:31.061801 2026] [security2:error] [pid 10272:tid 10272] [client 34.142.37.201:47516] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "matthewhestad.help"] [uri "/.env.bak"] [unique_id "apq_D57IcJOhoUvZuA03AQAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 12:36:31
(22 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.142.37.201 (201.37.142.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.142.37.201 (201.37.142.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 08:36:27.170159 2026] [security2:error] [pid 26297:tid 26297] [client 34.142.37.201:55564] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "saltcityprint.com"] [uri "/wp-config.php.swp"] [unique_id "apq7S8cIgRQC2p9A6CXRpAAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
FD-IX
2026-09-04 12:33:20
(22 hours ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 12:18:51
(23 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.142.37.201 (201.37.142.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.142.37.201 (201.37.142.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 08:18:43.495708 2026] [security2:error] [pid 13687:tid 13687] [client 34.142.37.201:49470] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "musisatge.com"] [uri "/.env.bak"] [unique_id "apq3I9e1xXzqDE5_SSpvTQAAACk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 11:14:13
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.142.37.201 (201.37.142.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.142.37.201 (201.37.142.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 07:14:09.453933 2026] [security2:error] [pid 17168:tid 17168] [client 34.142.37.201:41896] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "aaronnosan.com"] [uri "/.env.dev"] [unique_id "apqoAb9YMxwmPcxvR15JvAAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack