🇬🇧
consul.to
2026-09-04 11:04:47
(1 hour ago)
Web attack/malicious scanning detected
Web App Attack
🇩🇪
LRob
2026-09-04 10:42:59
(1 hour ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /wp-config.php.bak (+12 more) | 2026-09-04 10:42 UTC
show less
Hacking
Web App Attack
🇨🇭
zynex
2026-09-04 10:21:37
(1 hour ago)
URL Probing: /wp-config.php.bak
Web App Attack
🇬🇧
Aetherweb Ark
2026-09-04 10:10:30
(1 hour ago)
(mod_security) mod_security (id:949110) triggered by 34.148.127.28 (US/United States/28.127.148.34.b ...
show more
(mod_security) mod_security (id:949110) triggered by 34.148.127.28 (US/United States/28.127.148.34.bc.googleusercontent.com): N in the last X secs
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 10:06:59
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.148.127.28 (28.127.148.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.148.127.28 (28.127.148.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 06:06:54.484469 2026] [security2:error] [pid 27772:tid 27772] [client 34.148.127.28:49476] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.fiberscribe.com"] [uri "/.env.backup"] [unique_id "apqYPhjDPntBgF5GZl-HogAAADk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇲🇾
Rizzy
2026-09-04 08:55:56
(3 hours ago)
Multiple WAF Violations
Brute-Force
Web App Attack
🇳🇱
MyGlobalFlowers
2026-09-04 08:45:12
(3 hours ago)
Multiple WAF Violations
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 08:27:11
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.148.127.28 (28.127.148.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.148.127.28 (28.127.148.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 04:27:04.314521 2026] [security2:error] [pid 21792:tid 21792] [client 34.148.127.28:49386] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.russiacoin.info"] [uri "/.env.local"] [unique_id "apqA2JHlAnhM_4gHSkjjqgAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇮🇹
clamehost.it
2026-09-04 07:48:18
(4 hours ago)
Automatic report - Brute Force attack using this IP address
Brute-Force
Anonymous
2026-09-04 07:36:50
(4 hours ago)
[server.tmg.gr] httpd-config-scan: sites=www.mastermind.gr; logs=/var/log/httpd/domains/tmg.gr.log; ...
show more
[server.tmg.gr] httpd-config-scan: sites=www.mastermind.gr; logs=/var/log/httpd/domains/tmg.gr.log; samples=/.env.local | /wp-config.php~ | /.env.prod
show less
Hacking
Web App Attack
🇩🇪
FeG Deutschland
2026-09-04 07:04:07
(5 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 1247
Exploited Host
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 07:00:40
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.148.127.28 (28.127.148.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.148.127.28 (28.127.148.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 03:00:34.792312 2026] [security2:error] [pid 20448:tid 20448] [client 34.148.127.28:47382] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.panadata.com"] [uri "/.env.backup"] [unique_id "appskjySL90Cy1ckLPuz0AAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
maxpower
2026-09-04 06:27:18
(5 hours ago)
(nginx_hardened) REGOLA 3 - Nginx Hardening Triggered 34.148.127.28 (US/United States/28.127.148.34. ...
show more
(nginx_hardened) REGOLA 3 - Nginx Hardening Triggered 34.148.127.28 (US/United States/28.127.148.34.bc.googleusercontent.com): 3 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 2026/09/04 08:27:11 [error] 2616843#2616843: *2611488 access forbidden by rule, client: 34.148.127.28, server: analisibioenergetica.com, request: "GET /wp-config.php.swp HTTP/1.1", host: "blogdigiovanni.it"
2026/09/04 08:27:11 [error] 2616855#2616855: *2611491 access forbidden by rule, client: 34.148.127.28, server: analisibioenergetica.com, request: "GET /wp-config.php.bak HTTP/1.1", host: "blogdigiovanni.it"
2026/09/04 08:27:11 [error] 2616852#2616852: *2611504 access forbidden by rule, client: 34.148.127.28, server: analisibioenergetica.com, request: "GET /wp-config.php~ HTTP/1.1", host: "blogdigiovanni.it"
show less
Port Scan
Anonymous
2026-09-04 06:04:17
(6 hours ago)
Banned by Firewall
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 05:58:31
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.148.127.28 (28.127.148.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.148.127.28 (28.127.148.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 01:58:26.031948 2026] [security2:error] [pid 20125:tid 20125] [client 34.148.127.28:45834] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.aroilcontrolsystem.com"] [uri "/.env.bak"] [unique_id "appeAhVq1dLOSuA4n_RuwwAAAC0"]
show less
Brute-Force
Bad Web Bot
Web App Attack