πΊπΈ
TPI-Abuse
2026-09-01 13:53:31
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.168.193.47 (47.193.168.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.168.193.47 (47.193.168.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 09:53:27.948090 2026] [security2:error] [pid 8913:tid 8913] [client 34.168.193.47:46870] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.4115thewestford.com"] [uri "/wp-config.php~"] [unique_id "apbY16fABvcTS8sjVC5rLgAAAEI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-01 12:35:28
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.168.193.47 (47.193.168.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.168.193.47 (47.193.168.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 08:35:25.145486 2026] [security2:error] [pid 28867:tid 28867] [client 34.168.193.47:49430] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cidv.net.globalweb123.com"] [uri "/.env.local"] [unique_id "apbGjZqL3bh6Ff5fJbmPywAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
Petros Stefanakis
2026-09-01 10:55:49
(4 hours ago)
(mod_security) mod_security triggered on hostname [redacted] 34.168.193.47 (US/United States/47.193. ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.168.193.47 (US/United States/47.193.168.34.bc.googleusercontent.com)
show less
SQL Injection
Anonymous
2026-09-01 10:25:02
(4 hours ago)
suspicious request in access.log
Web App Attack
π²πΎ
Rizzy
2026-09-01 10:04:01
(5 hours ago)
Multiple WAF Violations
Brute-Force
Web App Attack
π«π·
masterguru
2026-09-01 09:49:20
(5 hours ago)
Attempt to access a backup or working file. Pattern match "\\\\. (920500-193)
Hacking
π©πͺ
big-cloud.nl
2026-09-01 09:21:28
(5 hours ago)
Try to access /.env
Web App Attack
π·π΄
clauss
2026-09-01 08:55:13
(6 hours ago)
34.168.193.47 - - [01/Sep/2026:11:55:13 +0300] "GET /actuator/env HTTP/2.0" 404 8161 "-" "crusader-w ...
show more
34.168.193.47 - - [01/Sep/2026:11:55:13 +0300] "GET /actuator/env HTTP/2.0" 404 8161 "-" "crusader-worker/1.0"
34.168.193.47 - - [01/Sep/2026:11:55:13 +0300] "GET /actuator/configprops HTTP/2.0" 404 8069 "-" "crusader-worker/1.0"
...
show less
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-01 08:43:36
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.168.193.47 (47.193.168.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.168.193.47 (47.193.168.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 04:43:31.881819 2026] [security2:error] [pid 6043:tid 6043] [client 34.168.193.47:43836] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "shop.jbaydeliveries.com"] [uri "/.env.bak"] [unique_id "apaQM-3wetYS858YGNjNQwAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-01 08:23:00
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.168.193.47 (47.193.168.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.168.193.47 (47.193.168.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 04:22:54.037300 2026] [security2:error] [pid 19138:tid 19138] [client 34.168.193.47:34166] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mandytony.tonylai.com"] [uri "/.env.bak"] [unique_id "apaLXjwff8RaX4cPL8n5kwAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
ISPLtd
2026-09-01 08:14:34
(6 hours ago)
Sep 1 05:14:33 34.168.193.47 TCP SPT=56232 DPT=80 SYN
Sep 1 05:14:33 34.168.193.47 TCP SPT=56238 D ...
show more
Sep 1 05:14:33 34.168.193.47 TCP SPT=56232 DPT=80 SYN
Sep 1 05:14:33 34.168.193.47 TCP SPT=56238 DPT=80 SYN
Sep 1 05:14:33 34.168.193.47 TCP SPT=56242 DPT=80 SYN
...
show less
DDoS Attack
Anonymous
2026-09-01 06:32:12
(8 hours ago)
Web application attack detected.
Web App Attack
π©πͺ
niedson
2026-09-01 06:30:02
(8 hours ago)
Automated scanning for exposed secrets: repeated requests for multiple distinct credential paths (.e ...
show more
Automated scanning for exposed secrets: repeated requests for multiple distinct credential paths (.env variants, .git metadata, .ssh private keys, .aws/credentials). Unsolicited. Reported automatically.
show less
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-01 06:08:07
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.168.193.47 (47.193.168.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.168.193.47 (47.193.168.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 02:07:58.426095 2026] [security2:error] [pid 8998:tid 8998] [client 34.168.193.47:45772] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.register-yacht-belgium.com"] [uri "/.env.production"] [unique_id "apZrvs_WU90J2cw31SAmeAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-01 05:44:30
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.168.193.47 (47.193.168.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.168.193.47 (47.193.168.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 01:44:22.608541 2026] [security2:error] [pid 25437:tid 25437] [client 34.168.193.47:40982] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "elpais.mx"] [uri "/.env.backup"] [unique_id "apZmNhf1gjslAR6qDdYpiQAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack