๐บ๐ธ
TPI-Abuse
2026-08-27 10:07:07
(44 minutes ago)
(mod_security) mod_security (id:210492) triggered by 34.156.0.106 (106.0.156.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.156.0.106 (106.0.156.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 06:07:04.142014 2026] [security2:error] [pid 2697:tid 2697] [client 34.156.0.106:34758] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.medioskreativos.com.spyasociados.com"] [uri "/wp-config.php~"] [unique_id "apAMSL-vSYQURdFTyXVWSwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
debestelapp
2026-08-27 09:55:06
(56 minutes ago)
Web App Attack
๐ช๐ธ
yvoictra
2026-08-27 09:22:39
(1 hour ago)
34.156.0.106 - - [27/Aug/2026:11:22:39 +0200] "GET /.env.dev HTTP/1.1" 404 19 "-" "crusader-worker/1 ...
show more
34.156.0.106 - - [27/Aug/2026:11:22:39 +0200] "GET /.env.dev HTTP/1.1" 404 19 "-" "crusader-worker/1.0"
34.156.0.106 - - [27/Aug/2026:11:22:39 +0200] "GET /env HTTP/1.1" 404 19 "-" "crusader-worker/1.0"
34.156.0.106 - - [27/Aug/2026:11:22:39 +0200] "GET /actuator/env HTTP/1.1" 404 19 "-" "crusader-worker/1.0"
34.156.0.106 - - [27/Aug/2026:11:22:39 +0200] "GET /.env.bak HTTP/1.1" 404 19 "-" "crusader-worker/1.0"
34.156.0.106 - - [27/Aug/2026:11:22:39 +0200] "GET /.env.old HTTP/1.1" 404 19 "-" "crusader-worker/1.0"
...
show less
Brute-Force
Web App Attack
๐ซ๐ท
Catalin Negru
2026-08-27 09:04:02
(1 hour ago)
Recidive ban by fail2ban on server.blackbit.ro
Brute-Force
๐ฉ๐ช
0x44
2026-08-27 08:40:02
(2 hours ago)
TCP SYN Discovery - Flooding
DDoS Attack
๐ง๐ท
Halux
2026-08-27 08:29:48
(2 hours ago)
34.156.0.106 Probing protected path or service
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 08:21:00
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.156.0.106 (106.0.156.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.156.0.106 (106.0.156.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 04:20:52.192576 2026] [security2:error] [pid 32543:tid 32543] [client 34.156.0.106:56260] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.albionglobalmarketing.com"] [uri "/wp-config.php.swp"] [unique_id "ao_zZCSjJhlgxuJ_uDaa0gAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-08-27 07:06:55
(3 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-08-27 06:29:06
(4 hours ago)
Restricted File Access Attempt. Matched phrase ".env" at REQUEST_FILENAME. (930130-197)
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 06:28:42
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.156.0.106 (106.0.156.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.156.0.106 (106.0.156.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 02:28:35.266510 2026] [security2:error] [pid 4055:tid 4055] [client 34.156.0.106:35506] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.hotdog.to.raularrue.com"] [uri "/.env.example"] [unique_id "ao_ZExNkd2McQtAPoeuBzgAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐ณ
evicky2002
2026-08-27 06:00:33
(4 hours ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2026-08-27 05:55:27
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.156.0.106 (106.0.156.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.156.0.106 (106.0.156.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 01:55:22.220816 2026] [security2:error] [pid 5244:tid 5244] [client 34.156.0.106:50634] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "honeybeeplace.com"] [uri "/.env.bak"] [unique_id "ao_RSnEMOhCrTD90M-pR0wAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-27 05:44:51
(5 hours ago)
34.156.0.106 - - [27/Aug/2026:05:44:51 +0000] "GET /.env.local HTTP/1.1" 404 4401 "-" "crusader-work ...
show more
34.156.0.106 - - [27/Aug/2026:05:44:51 +0000] "GET /.env.local HTTP/1.1" 404 4401 "-" "crusader-worker/1.0"
...
show less
Bad Web Bot
Web App Attack
๐ญ๐บ
bcsaba
2026-08-27 05:37:33
(5 hours ago)
Probing for .env file:
34.156.0.106 - - [27/Aug/2026:07:34:23 +0200] "GET /.env.prod HTTP/1.1" 403 1 ...
show more
Probing for .env file:
34.156.0.106 - - [27/Aug/2026:07:34:23 +0200] "GET /.env.prod HTTP/1.1" 403 146 "-" "crusader-worker/1.0"
show less
Web App Attack
Anonymous
2026-08-27 05:23:05
(5 hours ago)
Bot / scanning and/or hacking attempts: GET /.env.save HTTP/1.1, GET /crusader-404-probe HTTP/1.1, G ...
show more
Bot / scanning and/or hacking attempts: GET /.env.save HTTP/1.1, GET /crusader-404-probe HTTP/1.1, GET /actuator/env HTTP/1.1, GET /env HTTP/1.1, GET /.env.prod HTTP/1.1, GET /.env.bak HTTP/1.1, GET /_ignition/health-check HTTP/1.1, GET /storage/logs/laravel.log HTTP/1.1, GET /.env.old HTTP/1.1, GET /wp-config.php~ HTTP/1.1, GET /.env.example HTTP/1.1, GET /.env.local HTTP/1.1, GET /wp-config.php.bak HTTP/1.1, GET /.env.production HTTP/1.1, GET /.env.backup HTTP/1.1, GET /actuator/configprops HTTP/1.1, GET /.env.dev HTTP/1.1, GET /.env HTTP/1.1
show less
Hacking
Web App Attack