🇺🇸
mc4bbs
2026-09-06 06:21:39
(8 hours ago)
Automated Apache detection on Windows host. 5 suspicious HTTP requests within 300 seconds. Examples: ...
show more
Automated Apache detection on Windows host. 5 suspicious HTTP requests within 300 seconds. Examples: GET /.env -> 404 UA=""; GET /.env.production -> 404 UA=""; GET /.env.prod -> 404 UA=""; GET /.env.backup -> 404 UA=""; GET /actuator/env -> 404 UA=""
show less
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-06 03:38:07
(11 hours ago)
(mod_security) mod_security (id:949110) triggered by 34.151.234.235 (235.234.151.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:949110) triggered by 34.151.234.235 (235.234.151.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 23:38:03.036866 2026] [security2:error] [pid 29831:tid 29831] [client 34.151.234.235:35326] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "pmg-zolphy.com"] [uri "/storage/logs/laravel.log"] [unique_id "apzgG2itwDEiWEi2owVTnwAAACQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇱🇻
garmtech.com
2026-09-06 03:05:56
(11 hours ago)
Attempted access to sensitive endpoint (/.env.dev) detected. Automated scan or unauthorized probing.
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 02:56:35
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.151.234.235 (235.234.151.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.151.234.235 (235.234.151.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 22:56:27.791712 2026] [security2:error] [pid 4649:tid 4649] [client 34.151.234.235:40570] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.angelabcomics.com"] [uri "/.env.old"] [unique_id "apzWW5oE8V3Vht1Qh-an2QAAACc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
Petros Stefanakis
2026-09-06 01:59:05
(13 hours ago)
(mod_security) mod_security triggered on hostname [redacted] 34.151.234.235 (BR/Brazil/235.234.151.3 ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.151.234.235 (BR/Brazil/235.234.151.34.bc.googleusercontent.com)
show less
SQL Injection
🇺🇸
TPI-Abuse
2026-09-06 01:51:02
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.151.234.235 (235.234.151.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.151.234.235 (235.234.151.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 21:50:56.088802 2026] [security2:error] [pid 24505:tid 24505] [client 34.151.234.235:56252] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sailinghonu.com"] [uri "/.env.dev"] [unique_id "apzHALwZJclBM6OHRt-t5QAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
e.fierstra
2026-09-06 01:27:52
(13 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 00:29:55
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.151.234.235 (235.234.151.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.151.234.235 (235.234.151.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 20:29:50.483575 2026] [security2:error] [pid 1449:tid 1449] [client 34.151.234.235:41922] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "naominixon.com"] [uri "/.env.example"] [unique_id "apyz_jYwJGXhy7OMQs-ZvwAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-06 00:14:47
(14 hours ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-06 00:11:04
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.151.234.235 (235.234.151.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.151.234.235 (235.234.151.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 20:10:59.312465 2026] [security2:error] [pid 12785:tid 12785] [client 34.151.234.235:58966] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www2.davisllp.com"] [uri "/wp-config.php.swp"] [unique_id "apyvk0g9F0l1i6lSjrL0zgAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
FD-IX
2026-09-06 00:04:04
(14 hours ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
Anonymous
2026-09-05 23:59:30
(15 hours ago)
Aggressive web scan
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 23:53:06
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.151.234.235 (235.234.151.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.151.234.235 (235.234.151.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 19:52:58.403189 2026] [security2:error] [pid 20907:tid 20907] [client 34.151.234.235:57344] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.andrewrmarshall.com"] [uri "/.env.save"] [unique_id "apyrWi9gidPB6pgZysIFEgAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 22:39:21
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.151.234.235 (235.234.151.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.151.234.235 (235.234.151.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 18:39:12.487991 2026] [security2:error] [pid 11646:tid 11701] [client 34.151.234.235:45094] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ftp.certifiedecommerceconsultant.com"] [uri "/wp-config.php~"] [unique_id "apyaEMhY564o5wKLIwiHmgAAAQQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
FeG Deutschland
2026-09-05 22:19:17
(16 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack