Anonymous
2026-09-06 01:14:34
(44 minutes ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
🇺🇸
mnsf
2026-09-06 01:05:37
(53 minutes ago)
Scanning/Probing (20)
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 00:53:30
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.168.145.128 (128.145.168.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.168.145.128 (128.145.168.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 20:53:23.787513 2026] [security2:error] [pid 28617:tid 28617] [client 34.168.145.128:40174] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ericadamsdesign.com"] [uri "/.env.production"] [unique_id "apy5g9md4affhjJotLArUAAAACU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 00:17:56
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.168.145.128 (128.145.168.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.168.145.128 (128.145.168.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 20:17:52.722601 2026] [security2:error] [pid 26542:tid 26542] [client 34.168.145.128:56196] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "alrevora.com"] [uri "/.env"] [unique_id "apyxMFRzZWEAsGu7rWAkhgAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇪🇸
alferez
2026-09-05 23:33:19
(2 hours ago)
Searching .(env|sql|zip|tar|rar) files
Hacking
Exploited Host
Web App Attack
🇺🇸
Victor López
2026-09-05 23:05:53
(2 hours ago)
reparaya.com.co 34.168.145.128 - - [05/Sep/2026:18:05:53 -0500] "GET /wp-config.php.swp HTTP/1.1" 40 ...
show more
reparaya.com.co 34.168.145.128 - - [05/Sep/2026:18:05:53 -0500] "GET /wp-config.php.swp HTTP/1.1" 404 31438 "-" "crusader-worker/1.0" MISS
reparaya.com.co 34.168.145.128 - - [05/Sep/2026:18:05:53 -0500] "GET /wp-config.php~ HTTP/1.1" 404 31438 "-" "crusader-worker/1.0" MISS
reparaya.com.co 34.168.145.128 - - [05/Sep/2026:18:05:53 -0500] "GET /wp-config.php.bak HTTP/1.1" 404 31438 "-" "crusader-worker/1.0" MISS
...
show less
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 22:59:26
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.168.145.128 (128.145.168.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.168.145.128 (128.145.168.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 18:59:23.017222 2026] [security2:error] [pid 27023:tid 27023] [client 34.168.145.128:36120] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.puckerbottombikinis.com"] [uri "/.env.local"] [unique_id "apyey0Oj97piOMSiO3KqTQAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
dynamix
2026-09-05 22:55:20
(3 hours ago)
Multiple WAF Violations
Web App Attack
Anonymous
2026-09-05 22:23:44
(3 hours ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 22:14:49
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.168.145.128 (128.145.168.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.168.145.128 (128.145.168.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 18:14:44.911093 2026] [security2:error] [pid 22177:tid 22218] [client 34.168.145.128:34900] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mx3.absurdotron.com"] [uri "/.env.prod"] [unique_id "apyUVLFrBBBv6RD6KBfvrQAAAMQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
MatCat
2026-09-05 22:05:12
(3 hours ago)
Banned by fail2ban: apache-webprobe
Port Scan
Bad Web Bot
Anonymous
2026-09-05 21:55:01
(4 hours ago)
suspicious request in access.log
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 21:36:15
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.168.145.128 (128.145.168.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.168.145.128 (128.145.168.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 17:36:07.442204 2026] [security2:error] [pid 17252:tid 17252] [client 34.168.145.128:41370] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "settummanque.net.scoutinsignia.com"] [uri "/.env.old"] [unique_id "apyLR98nclwu2xFmN0kWjgAAAEw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇮🇹
VHosting
2026-09-05 20:20:04
(5 hours ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
🇳🇱
Savvii
2026-09-03 08:01:25
(2 days ago)
20 attempts against mh-misbehave-ban on iron
Brute-Force
Bad Web Bot
Web App Attack