🇩🇪
Enno
2026-09-06 06:08:04
(7 hours ago)
X09::Fail2Ban: automated bot scanning / credential probing detected.
Bad Web Bot
Web App Attack
🇬🇧
openstrike.co.uk
2026-09-06 05:13:00
(8 hours ago)
26 attacks on env grabbing URLs, PHP URLs:
GET /.env.dev HTTP/1.1
GET /wp-config.php.bak HTTP/1.1
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 03:25:44
(10 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.148.157.134 (134.157.148.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 34.148.157.134 (134.157.148.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 23:25:37.879252 2026] [security2:error] [pid 3689612:tid 3689612] [client 34.148.157.134:53708] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||chick-p2.larryyang.net|F|2"] [data ".env.backup"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "chick-p2.larryyang.net"] [uri "/.env.backup"] [unique_id "apzdMcbSDO1yLAHokCgW_wAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
Mangelot Hosting
2026-09-06 02:27:21
(11 hours ago)
(wp_config_access) srv101 WordPress wp-config Scan 34.148.157.134 (US/United States/134.157.148.34.b ...
show more
(wp_config_access) srv101 WordPress wp-config Scan 34.148.157.134 (US/United States/134.157.148.34.bc.googleusercontent.com): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs:
show less
Web App Attack
🇩🇪
enjoyably
2026-09-06 02:10:43
(11 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-06 02:03:21
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.148.157.134 (134.157.148.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.148.157.134 (134.157.148.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 22:03:15.900865 2026] [security2:error] [pid 3505773:tid 3505833] [client 34.148.157.134:40434] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mcp.fnaandpartners.com"] [uri "/wp-config.php.swp"] [unique_id "apzJ4ycrIQhcuqFjqhX_PgAAAUM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
Octopuce
2026-09-06 02:01:31
(12 hours ago)
Aggressive web search of vulnerable pages: /.env.production /.env.dev /.env.local /.env.save /wp-con ...
show more
Aggressive web search of vulnerable pages: /.env.production /.env.dev /.env.local /.env.save /wp-config.php.swp /wp-config.php.bak /.env.exampl ...
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 00:42:57
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.148.157.134 (134.157.148.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.148.157.134 (134.157.148.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 20:42:52.925901 2026] [security2:error] [pid 18171:tid 18171] [client 34.148.157.134:57640] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "abogadoparticular.com"] [uri "/.env.old"] [unique_id "apy3DJq5TwRXwHn9H3GtkgAAADA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
e.fierstra
2026-09-06 00:38:28
(13 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 00:08:59
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.148.157.134 (134.157.148.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.148.157.134 (134.157.148.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 20:08:55.639132 2026] [security2:error] [pid 22358:tid 22358] [client 34.148.157.134:58000] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "nrvoutdoors.com"] [uri "/.env.bak"] [unique_id "apyvFzxudb6JsIrhY2d8-gAAACA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-05 23:00:03
(15 hours ago)
suspicious request in access.log
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 22:59:04
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.148.157.134 (134.157.148.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.148.157.134 (134.157.148.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 18:58:59.272450 2026] [security2:error] [pid 12196:tid 12196] [client 34.148.157.134:52082] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.kathydumesnilart.com"] [uri "/.env.old"] [unique_id "apyes7k6ObkNsqicgZUD2gAAACI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
FeG Deutschland
2026-09-05 22:47:23
(15 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
🇮🇹
clamehost.it
2026-09-05 22:39:51
(15 hours ago)
Automatic report - Brute Force attack using this IP address
Brute-Force
🇺🇸
TPI-Abuse
2026-09-05 22:11:56
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.148.157.134 (134.157.148.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.148.157.134 (134.157.148.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 18:11:45.588645 2026] [security2:error] [pid 11597:tid 11597] [client 34.148.157.134:51740] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.caribbeantracking.com"] [uri "/.env"] [unique_id "apyToTC4AzoTR0LDTzMpZgAAAC4"]
show less
Brute-Force
Bad Web Bot
Web App Attack