๐ฉ๐ช
ger-stg-sifi1
2026-08-29 08:42:40
(2 minutes ago)
(wordpress) Failed wordpress login using wp-login.php or xmlrpc.php
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-29 08:37:35
(7 minutes ago)
(mod_security) mod_security (id:210492) triggered by 34.146.196.198 (198.196.146.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.146.196.198 (198.196.146.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 04:37:27.352701 2026] [security2:error] [pid 23027:tid 23027] [client 34.146.196.198:58966] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.benlbrown.com"] [uri "/@fs/root/.env"] [unique_id "apKaR71ApFmqx-wqmxX8bgAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
Apache
2026-08-29 07:42:14
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.146.196.198 (JP/Japan/198.196.146.34.bc.goog ...
show more
(mod_security) mod_security (id:210492) triggered by 34.146.196.198 (JP/Japan/198.196.146.34.bc.googleusercontent.com): 5 in the last 300 secs (CF_ENABLE)
show less
Brute-Force
Web App Attack
๐ณ๐ฑ
Site.eu
2026-08-29 07:37:45
(1 hour ago)
Excessive multi-domain requests
Brute-Force
๐ฉ๐ช
FeG Deutschland
2026-08-29 07:32:26
(1 hour ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 1247
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-29 07:05:50
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.146.196.198 (198.196.146.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.146.196.198 (198.196.146.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 03:05:43.724384 2026] [security2:error] [pid 15451:tid 15451] [client 34.146.196.198:65012] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.isleofcain.com"] [uri "/@fs/src/.env"] [unique_id "apKExygz7ajXR5p-Uqyn4gAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-29 06:44:58
(2 hours ago)
2026/08/29 03:44:57 [error] 2325135#2325135: *120241 access forbidden by rule, client: 34.146.196.19 ...
show more
2026/08/29 03:44:57 [error] 2325135#2325135: *120241 access forbidden by rule, client: 34.146.196.198, server: blog.sorotop.com.br, request: "GET /@fs/.env?raw?? HTTP/1.1", host: "blog.sorotop.com.br"
2026/08/29 03:44:57 [error] 2325136#2325136: *120242 access forbidden by rule, client: 34.146.196.198, server: blog.sorotop.com.br, request: "GET /@fs/src/.env?raw?? HTTP/1.1", host: "blog.sorotop.com.br"
2026/08/29 03:44:57 [error] 2325133#2325133: *120243 access forbidden by rule, client: 34.146.196.198, server: blog.sorotop.com.br, request: "GET /@fs/app/.env?raw?? HTTP/1.1", host: "blog.sorotop.com.br"
...
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-08-29 05:58:17
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.146.196.198 (198.196.146.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.146.196.198 (198.196.146.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 01:58:13.027903 2026] [security2:error] [pid 282146:tid 282163] [client 34.146.196.198:63936] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.mcp.volcano-sa.com"] [uri "/@fs/root/.env"] [unique_id "apJ09QNfDYkvhC1rmnqqQQAAAQ0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Octopuce
2026-08-29 05:57:40
(2 hours ago)
Aggressive web search of vulnerable pages: /uploads../.env /img../.env /.env /_nuxt/../.env /app/.en ...
show more
Aggressive web search of vulnerable pages: /uploads../.env /img../.env /.env /_nuxt/../.env /app/.env ...
show less
Web App Attack
๐ณ๐ฑ
debestelapp
2026-08-29 05:50:08
(2 hours ago)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-29 05:16:09
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.146.196.198 (198.196.146.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.146.196.198 (198.196.146.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 01:16:05.328413 2026] [security2:error] [pid 11737:tid 11737] [client 34.146.196.198:24746] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.periodthreads.com"] [uri "/@fs/.env"] [unique_id "apJrFabotXkoicKk0xSXrQAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-08-29 04:51:26
(3 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
๐ฉ๐ช
gadix
2026-08-29 04:32:46
(4 hours ago)
[29/Aug/2026:06:32:44.634332 +0200] apJg7OTq2n5ZLRYHMzwsCwAAAFc 34.146.196.198 41300 127.0.0.1 7081
...
show more
[29/Aug/2026:06:32:44.634332 +0200] apJg7OTq2n5ZLRYHMzwsCwAAAFc 34.146.196.198 41300 127.0.0.1 7081
[29/Aug/2026:06:32:44.639731 +0200] apJg7OTq2n5ZLRYHMzwsDQAAAEA 34.146.196.198 41332 127.0.0.1 7081
[29/Aug/2026:06:32:44.641927 +0200] apJg7N7z4ql3U73Vf52m0AAAABE 34.146.196.198 41336 127.0.0.1 7081
...
show less
Web App Attack
๐ฌ๐ง
consul.to
2026-08-29 04:30:56
(4 hours ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-29 04:29:33
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.146.196.198 (198.196.146.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.146.196.198 (198.196.146.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 00:29:26.107586 2026] [security2:error] [pid 29831:tid 29831] [client 34.146.196.198:16752] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.swindon-itf.com"] [uri "/@fs/.env"] [unique_id "apJgJudErE-N2pbAEEBpegAAADk"]
show less
Brute-Force
Bad Web Bot
Web App Attack