🇩🇪
FeG Deutschland
2026-09-04 13:49:10
(1 day ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 13:36:14
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.153.209.124 (124.209.153.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.153.209.124 (124.209.153.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 09:36:06.225799 2026] [security2:error] [pid 13395:tid 13395] [client 34.153.209.124:49506] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "five21.com"] [uri "/.env.prod"] [unique_id "aprJRgXDBtDqHXA8l8rbBAAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-04 13:30:02
(1 day ago)
suspicious request in access.log
Web App Attack
Anonymous
2026-09-04 13:26:11
(1 day ago)
[ns3.backorder.gr] httpd-config-scan: logs=/var/log/httpd/access_log; samples=/wp-config.php.swp | / ...
show more
[ns3.backorder.gr] httpd-config-scan: logs=/var/log/httpd/access_log; samples=/wp-config.php.swp | /.env.prod | /.env.bak
show less
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 13:21:08
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.153.209.124 (124.209.153.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.153.209.124 (124.209.153.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 09:21:03.015190 2026] [security2:error] [pid 26557:tid 26596] [client 34.153.209.124:49672] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "conservativelabor.com"] [uri "/.env.bak"] [unique_id "aprFv1IYldfnp1qG2Jd0WQAAAcA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 10:53:13
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.153.209.124 (124.209.153.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.153.209.124 (124.209.153.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 06:53:09.161678 2026] [security2:error] [pid 30547:tid 30547] [client 34.153.209.124:43704] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mylert.org"] [uri "/.env"] [unique_id "apqjFbsz1tKbmOH14En5DgAAADA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇮🇩
penjaga BRIN
2026-09-04 10:33:51
(1 day ago)
Suspicious malicious activity
Hacking
🇺🇸
MPL
2026-09-04 10:29:27
(1 day ago)
tcp ports: 80,443 (80 or more attempts)
Port Scan
🇺🇸
TPI-Abuse
2026-09-04 10:22:51
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.153.209.124 (124.209.153.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.153.209.124 (124.209.153.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 06:22:47.916255 2026] [security2:error] [pid 28955:tid 28955] [client 34.153.209.124:38748] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "nsea.quest.greighhouse.com"] [uri "/.env.backup"] [unique_id "apqb9zTF7Td56UBb7lVZrgAAADk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 10:06:03
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.153.209.124 (124.209.153.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.153.209.124 (124.209.153.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 06:05:55.061922 2026] [security2:error] [pid 28929:tid 28929] [client 34.153.209.124:47972] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.hardemancountyjournal.com"] [uri "/.env.dev"] [unique_id "apqYA5mHWIYOKuBm9uSM6wAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
ISPLtd
2026-09-04 09:58:18
(1 day ago)
Sep 4 06:58:18 34.153.209.124 TCP SPT=50940 DPT=80 SYN
Sep 4 06:58:18 34.153.209.124 TCP SPT=50980 ...
show more
Sep 4 06:58:18 34.153.209.124 TCP SPT=50940 DPT=80 SYN
Sep 4 06:58:18 34.153.209.124 TCP SPT=50980 DPT=80 SYN
Sep 4 06:58:18 34.153.209.124 TCP SPT=50996 DPT=80 SYN
...
show less
DDoS Attack
🇺🇸
TPI-Abuse
2026-09-04 09:19:49
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.153.209.124 (124.209.153.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.153.209.124 (124.209.153.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 05:19:43.626334 2026] [security2:error] [pid 9136:tid 9136] [client 34.153.209.124:59540] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kaneprotectivecoatings.com"] [uri "/.env.dev"] [unique_id "apqNL7NX4SX3WZU2CDK6SAAAACQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
FD-IX
2026-09-04 08:18:47
(1 day ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
🇳🇱
WeCloudit-Anti-Abuse
2026-09-04 06:32:41
(2 days ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
🇩🇪
LRob
2026-09-04 06:15:50
(2 days ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /.env.bak (+4 more) | 2026-09-04 06:15 UTC
show less
Hacking
Web App Attack