๐ฉ๐ช
Vegascosmetics
2026-08-29 04:33:16
(4 days ago)
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after admin/path reconnaissance / port-scan ...
show more
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after admin/path reconnaissance / port-scan-like web scan. Evidence: AttackPattern: /actuator/ (Match: /actuator/)
show less
Port Scan
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-29 03:33:13
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 34.148.134.164 (164.134.148.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.148.134.164 (164.134.148.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 23:33:07.727980 2026] [security2:error] [pid 7381:tid 7385] [client 34.148.134.164:58184] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "accsesame.com"] [uri "/.env.bak"] [unique_id "apJS801B9tjNBLLj44HbIQAAAEE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-29 03:12:27
(4 days ago)
34.148.134.164 - - [29/Aug/2026:05:12:26 +0200] "GET /wp-config.php~ HTTP/1.1" 404 449 "-" "crusader ...
show more
34.148.134.164 - - [29/Aug/2026:05:12:26 +0200] "GET /wp-config.php~ HTTP/1.1" 404 449 "-" "crusader-worker/1.0"
34.148.134.164 - - [29/Aug/2026:05:12:26 +0200] "GET /wp-config.php~ HTTP/1.1" 404 300 "-" "crusader-worker/1.0"
34.148.134.164 - - [29/Aug/2026:05:12:27 +0200] "GET /wp-config.php.bak HTTP/1.1" 404 449 "-" "crusader-worker/1.0"
34.148.134.164 - - [29/Aug/2026:05:12:27 +0200] "GET /wp-config.php.bak HTTP/1.1" 404 300 "-" "crusader-worker/1.0"
34.148.134.164 - - [29/Aug/2026:05:12:27 +0200] "GET /wp-config.php.swp HTTP/1.1" 404 449 "-" "crusader-worker/1.0"
...
show less
Brute-Force
Web App Attack
Anonymous
2026-08-29 02:48:15
(4 days ago)
Web application attack detected.
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-29 02:18:52
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 34.148.134.164 (164.134.148.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.148.134.164 (164.134.148.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 22:18:43.748259 2026] [security2:error] [pid 19929:tid 19929] [client 34.148.134.164:57680] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.srtmgmt.com.srtmanagementservices.com"] [uri "/.env.save"] [unique_id "apJBg8StHPgX-kIf1mdRhQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
daveoctober
2026-08-29 00:38:34
(4 days ago)
October Sentinel: honeypot triggered
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-29 00:33:04
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 34.148.134.164 (164.134.148.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.148.134.164 (164.134.148.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 20:32:55.760505 2026] [security2:error] [pid 30435:tid 30435] [client 34.148.134.164:45906] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "pilates-slings.eu"] [uri "/.env.prod"] [unique_id "apIot4Jnhdr_eBpuetmScAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-08-29 00:09:02
(4 days ago)
Abuse Detected (19)
Brute-Force
Web App Attack
๐ฉ๐ช
ger-stg-sifi1
2026-08-28 23:54:28
(4 days ago)
(wordpress) Failed wordpress login using wp-login.php or xmlrpc.php
Web App Attack
๐ฒ๐พ
Rizzy
2026-08-28 23:39:57
(4 days ago)
Multiple WAF Violations
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 23:22:46
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 34.148.134.164 (164.134.148.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.148.134.164 (164.134.148.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 19:22:43.184342 2026] [security2:error] [pid 9294:tid 9294] [client 34.148.134.164:36636] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.carbonless.needtoorder.us"] [uri "/.env.dev"] [unique_id "apIYQz02wiBNmN8DSUYb6QAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 22:27:11
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 34.148.134.164 (164.134.148.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.148.134.164 (164.134.148.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 18:27:04.924501 2026] [security2:error] [pid 11198:tid 11198] [client 34.148.134.164:32930] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.saikungproperty.com"] [uri "/wp-config.php.bak"] [unique_id "apILOK3T8SXATZgwkt9bqQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
4server
2026-08-28 21:22:43
(4 days ago)
[FriAug2823:22:37.6949942026][security2:error][pid3193460:tid3193591][client34.148.134.164:0]ModSecu ...
show more
[FriAug2823:22:37.6949942026][security2:error][pid3193460:tid3193591][client34.148.134.164:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Patternmatch\"\(\?i\)\(\?:/\(\?:\^\|/\)\\\\\\\\.\(env\|git\|svn\|hg\|DS_Store\)\|/\(\?:wp-config\|\\\\\\\\.htaccess\|\\\\\\\\.htpasswd\)\|\\\\\\\\.\(\?:sql\|bak\|old\|log\)\$\)\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"156\"][id\"960720\"][msg\"Forbiddenfileaccessattempt\"][severity\"CRITICAL\"][hostname\"bluecirclecapital.ch.136-243-54-122.cpanel.site\"][uri\"/.env.old\"][unique_id\"apH8HXOu_syYL7e9foLtlgAAARE\"]
show less
Port Scan
Brute-Force
Web App Attack
Anonymous
2026-08-28 20:35:12
(4 days ago)
Blocked by ModSec and CSF
Port Scan
๐ธ๐ช
vaia.cloud
2026-08-28 20:05:07
(4 days ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack