🇺🇸
TPI-Abuse
2026-09-01 13:55:25
(21 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.156.124.27 (27.124.156.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.156.124.27 (27.124.156.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 09:55:18.005613 2026] [security2:error] [pid 3504:tid 3504] [client 34.156.124.27:47636] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.tracytappan.net"] [uri "/wp-config.php.bak"] [unique_id "apbZRsHg0kUDHWw2mY_sswAAAE0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-01 12:35:30
(22 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.156.124.27 (27.124.156.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.156.124.27 (27.124.156.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 08:35:23.478211 2026] [security2:error] [pid 26797:tid 26797] [client 34.156.124.27:48196] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cesstravelvlogs.michaelsabbey.org"] [uri "/.env.local"] [unique_id "apbGix-IMjSzZjFi0um8-wAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
Apache
2026-09-01 09:14:56
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.156.124.27 (BE/Belgium/27.124.156.34.bc.goog ...
show more
(mod_security) mod_security (id:210492) triggered by 34.156.124.27 (BE/Belgium/27.124.156.34.bc.googleusercontent.com): 5 in the last 300 secs (CF_ENABLE)
show less
Brute-Force
Web App Attack
🇺🇸
xxkodedxx
2026-09-01 08:46:34
(1 day ago)
[Zorvexus edge-defense] GET .env / WordPress honeypot probe
Trigger: 1× honeypot-get, 2× edge-block ...
show more
[Zorvexus edge-defense] GET .env / WordPress honeypot probe
Trigger: 1× honeypot-get, 2× edge-block in 10m window.
Origin: BE / AS396982 Google LLC
Active: 08:45:37→08:45:39 UTC
Volume: 5 HTTP req, 20 honeypot probe(s)
Bait taken: /.env.example, /actuator/env, /.env.save, /.env.bak, /.env.local
Status mix: 302×3 444×2
UA: "crusader-worker/1.0"
Auto-banned 30d. zorvexus-banner.
show less
Bad Web Bot
Web App Attack
🇩🇪
maxpower
2026-09-01 07:53:34
(1 day ago)
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 34.156.124.27 (BE/Belgium/27.124.156.34. ...
show more
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 34.156.124.27 (BE/Belgium/27.124.156.34.bc.googleusercontent.com): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 34.156.124.27 - - [01/Sep/2026:09:53:29 +0200] "GET /wp-config.php.bak HTTP/1.1" 403 146 "-" "crusader-worker/1.0" "-" host=samitecnopetrol.it
show less
Port Scan
🇫🇷
masterguru
2026-09-01 07:51:13
(1 day ago)
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 34.156.124.27 (BE/Belgium/27.124.156. ...
show more
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 34.156.124.27 (BE/Belgium/27.124.156.34.bc.googleusercontent.com): 1 in the last 3600 secs (0-195)
show less
Hacking
🇩🇪
raph
2026-09-01 07:41:26
(1 day ago)
[DOT FILES] crawler *.env*, .git*, .config*, etc.
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-01 07:22:49
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.156.124.27 (27.124.156.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.156.124.27 (27.124.156.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 03:22:40.920585 2026] [security2:error] [pid 32324:tid 32324] [client 34.156.124.27:33312] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "musicshowcase.us"] [uri "/wp-config.php.swp"] [unique_id "apZ9QH4b2igo1Cm-AVG96QAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
FD-IX
2026-09-01 07:12:20
(1 day ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-01 07:06:53
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.156.124.27 (27.124.156.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.156.124.27 (27.124.156.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 03:06:44.235485 2026] [security2:error] [pid 25745:tid 25762] [client 34.156.124.27:36106] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mouserart.com"] [uri "/.env.prod"] [unique_id "apZ5hIBdI55s7-WYQ1o3twAAAQ8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
jcbriar
2026-09-01 06:31:44
(1 day ago)
Searching for vulnerable scripts
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-01 06:12:40
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.156.124.27 (27.124.156.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.156.124.27 (27.124.156.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 02:03:01.841105 2026] [security2:error] [pid 23057:tid 23057] [client 34.156.124.27:55434] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.avmarep.com"] [uri "/.env.local"] [unique_id "apZqlbwdBS4c4s6HOyoXNwAAADU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
kosada.com
2026-09-01 05:22:14
(1 day ago)
Repeated requests for suspicious nonexistent URLs, for example: /.env.production (HTTP port 443)
Web App Attack
🇲🇾
Rizzy
2026-09-01 05:12:07
(1 day ago)
Multiple WAF Violations
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-01 05:01:31
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.156.124.27 (27.124.156.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.156.124.27 (27.124.156.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 01:01:25.645323 2026] [security2:error] [pid 22317:tid 22317] [client 34.156.124.27:47454] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "abcollie.com"] [uri "/.env.local"] [unique_id "apZcJeT3e5VDSKh_6EMtjgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack