π²π½
octageeks.com
2026-09-02 04:07:58
(12 hours ago)
Wordpress malicious attack:[octablocked]
Web App Attack
Anonymous
2026-09-02 04:06:32
(12 hours ago)
Trying to access config files
Web App Attack
π³π±
homeshowdomain.nl
2026-09-01 22:00:01
(18 hours ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-08-31.
show less
Web App Attack
SSH
Hacking
πΊπΈ
TPI-Abuse
2026-09-01 13:50:09
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.148.173.196 (196.173.148.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.148.173.196 (196.173.148.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 09:50:01.478913 2026] [security2:error] [pid 16210:tid 16210] [client 34.148.173.196:51390] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.guthrieclan.us"] [uri "/.env.prod"] [unique_id "apbYCQfONuSefoRLFbkfogAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
netclix.gr
2026-09-01 12:49:17
(1 day ago)
(mod_security) mod_security triggered on hostname [redacted] 34.148.173.196 (US/United States/196.17 ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.148.173.196 (US/United States/196.173.148.34.bc.googleusercontent.com): (CF_ENABLE)
show less
SQL Injection
πΊπΈ
TPI-Abuse
2026-09-01 12:16:59
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.148.173.196 (196.173.148.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.148.173.196 (196.173.148.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 08:16:54.593351 2026] [security2:error] [pid 29323:tid 29580] [client 34.148.173.196:33158] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "saryagroup.pershia.net"] [uri "/.env.dev"] [unique_id "apbCNoL9jUd1Jc6zHxsZHAAAAM0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π¬π§
Apache
2026-09-01 11:19:24
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.148.173.196 (US/United States/196.173.148.34 ...
show more
(mod_security) mod_security (id:210492) triggered by 34.148.173.196 (US/United States/196.173.148.34.bc.googleusercontent.com): 5 in the last 300 secs (CF_ENABLE)
show less
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-01 10:15:42
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.148.173.196 (196.173.148.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.148.173.196 (196.173.148.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 06:15:37.589813 2026] [security2:error] [pid 226452:tid 226463] [client 34.148.173.196:42808] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "agrigrailtech.com"] [uri "/wp-config.php.swp"] [unique_id "apalyd8rDBwRmC-l-5gnYwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
BlueWire Hosting
2026-09-01 09:42:05
(1 day ago)
High-confidence malicious configuration/VCS probe
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-01 09:15:42
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.148.173.196 (196.173.148.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.148.173.196 (196.173.148.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 05:15:33.864828 2026] [security2:error] [pid 5386:tid 5386] [client 34.148.173.196:46296] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "tdj.franchiseconsultants.org"] [uri "/.env.old"] [unique_id "apaXtbX3n_8cemby2W7giwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
SΓ©fora Srl
2026-09-01 08:55:57
(1 day ago)
crowdsecurity/http-probing detected by CrowdSec
Web App Attack
π·π΄
clauss
2026-09-01 08:18:48
(1 day ago)
34.148.173.196 - - [01/Sep/2026:11:18:47 +0300] "GET /_ignition/health-check HTTP/2.0" 301 0 "-" "cr ...
show more
34.148.173.196 - - [01/Sep/2026:11:18:47 +0300] "GET /_ignition/health-check HTTP/2.0" 301 0 "-" "crusader-worker/1.0"
34.148.173.196 - - [01/Sep/2026:11:18:48 +0300] "GET /actuator/env HTTP/2.0" 301 0 "-" "crusader-worker/1.0"
...
show less
Web App Attack
π³π±
WeCloudit-Anti-Abuse
2026-09-01 07:52:37
(1 day ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
π©πͺ
FD-IX
2026-09-01 07:12:14
(1 day ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-01 06:43:32
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.148.173.196 (196.173.148.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.148.173.196 (196.173.148.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 02:43:24.787326 2026] [security2:error] [pid 27909:tid 27909] [client 34.148.173.196:41174] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "teachingthestars.com"] [uri "/wp-config.php~"] [unique_id "apZ0DKLd65rXqDhCLQYicAAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack