π©πͺ
Roper123
2026-09-01 11:37:24
(13 minutes ago)
Web exploits
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-01 11:08:34
(42 minutes ago)
(mod_security) mod_security (id:210492) triggered by 34.151.214.49 (49.214.151.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.151.214.49 (49.214.151.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 07:08:27.955739 2026] [security2:error] [pid 12589:tid 12589] [client 34.151.214.49:39388] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.abramson-offner.com"] [uri "/.env.bak"] [unique_id "apayKzwfG7imjaSuG439MAAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-01 11:00:35
(50 minutes ago)
(mod_security) mod_security triggered on hostname [redacted])
SQL Injection
π¦πΊ
aranguren.org
2026-09-01 10:45:26
(1 hour ago)
34.151.214.49 - - [01/Sep/2026:20:45:25 +1000] "GET /.env.prod HTTP/1.1" 404 995 "-" "crusader-worke ...
show more
34.151.214.49 - - [01/Sep/2026:20:45:25 +1000] "GET /.env.prod HTTP/1.1" 404 995 "-" "crusader-worker/1.0"
34.151.214.49 - - [01/Sep/2026:20:45:25 +1000] "GET /.env HTTP/1.1" 404 995 "-" "crusader-worker/1.0"
34.151.214.49 - - [01/Sep/2026:20:45:25 +1000] "GET /wp-config.php.swp HTTP/1.1" 404 995 "-" "crusader-worker/1.0"
34.151.214.49 - - [01/Sep/2026:20:45:25 +1000] "GET /.env.local HTTP/1.1" 404 995 "-" "crusader-worker/1.0"
34.151.214.49 - - [01/Sep/2026:20:45:25 +1000] "GET /wp-config.php.bak HTTP/1.1" 404 995 "-" "crusader-worker/1.0"
34.151.214.49 - - [01/Sep/2026:20:45:25 +1000] "GET /.env.bak HTTP/1.1" 404 995 "-" "crusader-worker/1.0"
...
show less
Bad Web Bot
π«π·
masterguru
2026-09-01 09:15:35
(2 hours ago)
URL file extension is restricted by policy. String match within ".ani/ .asa/ .asax/ .ascx/ .back/ .b ...
show more
URL file extension is restricted by policy. String match within ".ani/ .asa/ .asax/ .ascx/ .back/ .backup/ .bak/ .bck/ .bk/ .bkp/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .cnf/ .com/ .compositefont/ .config/ .conf/ .copy/ .crt/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dist/ .dll/ .dos/ .dpkg-dist/ .drv/ .gadget/ .hta/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .inf/ .ini/ .jks/ .jse/ .key/ .licx/ .lnk/ .log/ .mdb/ .msc/ .ocx/ .old/ .pass/ .pdb/ .pfx/ .pif/ .pem/ .pol/ .prf/ .printer/ .pwd/ .rdb/ .rdp/ .reg/ .resources/ .resx/ .sav/ .save/ .scr/ .sct/ .sh/ .shs/ .sql/ .sqlite/ .sqlite3/ .swap/ .swo/ .swp/ .sys/ .temp/ .tfstate/ .tlb/ .tmp/ .vb/ .vbe/ .vbs/ .vbproj/ .vsdisco/ .vxd/ .webinfo/ .ws/ .wsc/ .wsf/ .wsh/ .xsd/ .xsx/" at TX:extension. (920440-193)
show less
Hacking
πΊπΈ
TPI-Abuse
2026-09-01 08:48:46
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.151.214.49 (49.214.151.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.151.214.49 (49.214.151.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 04:48:40.673519 2026] [security2:error] [pid 27035:tid 27125] [client 34.151.214.49:52334] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "seanmeriwether.com"] [uri "/wp-config.php.swp"] [unique_id "apaRaD8ubYaUsYzyC6xWrgAAAQY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
yitzhaq
2026-09-01 07:38:19
(4 hours ago)
34.151.214.49 - - [01/Sep/2026:09:38:17 +0200] "GET /wp-config.php.bak HTTP/1.1" 404 431 "-" "crusad ...
show more
34.151.214.49 - - [01/Sep/2026:09:38:17 +0200] "GET /wp-config.php.bak HTTP/1.1" 404 431 "-" "crusader-worker/1.0"
34.151.214.49 - - [01/Sep/2026:09:38:17 +0200] "GET /wp-config.php~ HTTP/1.1" 404 431 "-" "crusader-worker/1.0"
34.151.214.49 - - [01/Sep/2026:09:38:17 +0200] "GET /env HTTP/1.1" 404 431 "-" "crusader-worker/1.0"
34.151.214.49 - - [01/Sep/2026:09:38:17 +0200] "GET /.env.bak HTTP/1.1" 404 431 "-" "crusader-worker/1.0"
34.151.214.49 - - [01/Sep/2026:09:38:17 +0200] "GET /storage/logs/laravel.log HTTP/1.1" 404 431 "-" "crusader-worker/1.0"
34.151.214.49 - - [01/Sep/2026:09:38:17 +0200] "GET /wp-config.php.swp HTTP/1.1" 404 431 "-" "crusader-worker/1.0"
34.151.214.49 - - [01/Sep/2026:09:38:17 +0200] "GET /.env.example HTTP/1.1" 404 431 "-" "crusader-worker/1.0"
34.151.214.49 - - [01/Sep/2026:09:38:17 +0200] "GET /.env.production HTTP/1.1" 404 431 "-" "crusader-worker/1.0"
34.151.214.49 - - [01/Sep/2026:09:38:17 +0200] "GET /.env HTTP/1.1" 404 431 "-" "crusader-worker/1.0"
34.1
show less
Web App Attack
Brute-Force
πΊπΈ
TPI-Abuse
2026-09-01 07:10:08
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.151.214.49 (49.214.151.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.151.214.49 (49.214.151.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 03:10:00.645980 2026] [security2:error] [pid 3342:tid 3342] [client 34.151.214.49:47876] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mrappliancesales.net.mrappliancega.com"] [uri "/.env"] [unique_id "apZ6SHtZfED9L_YZzWaLswAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π¨π¦
Anytech
2026-09-01 07:08:27
(4 hours ago)
Blocked by ConnMonitor
Web App Attack
πΊπΈ
ersei.net
2026-09-01 06:46:06
(5 hours ago)
Web app exploiting
Web App Attack
π³π±
MyGlobalFlowers
2026-09-01 06:35:13
(5 hours ago)
Multiple WAF Violations
Web App Attack
Anonymous
2026-09-01 06:33:38
(5 hours ago)
Web application attack detected.
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-01 06:07:31
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.151.214.49 (49.214.151.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.151.214.49 (49.214.151.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 02:07:23.591966 2026] [security2:error] [pid 11645:tid 11645] [client 34.151.214.49:37038] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.larkinplumbingservice.com"] [uri "/.env"] [unique_id "apZrm2rI8cCBDBU34uaJIwAAADI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-01 05:20:29
(6 hours ago)
GET /.env HTTP/1.1
...
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-01 05:05:47
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.151.214.49 (49.214.151.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.151.214.49 (49.214.151.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 01:05:41.121114 2026] [security2:error] [pid 7554:tid 7554] [client 34.151.214.49:50008] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.ik3co.com"] [uri "/.env.backup"] [unique_id "apZdJTtnn0UI8Bq2YvuGMQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack