๐บ๐ธ
TPI-Abuse
2026-09-01 11:55:58
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.168.6.243 (243.6.168.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.168.6.243 (243.6.168.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 07:55:53.336267 2026] [security2:error] [pid 1424:tid 1424] [client 34.168.6.243:60676] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "dci.legal.kountz.org"] [uri "/.env.save"] [unique_id "apa9SbDyZk9xuHcGtCTEmAAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 11:13:20
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.168.6.243 (243.6.168.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.168.6.243 (243.6.168.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 07:13:15.831402 2026] [security2:error] [pid 25944:tid 25944] [client 34.168.6.243:49574] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "wp.hotpay.co"] [uri "/wp-config.php~"] [unique_id "apazSy7wmujcVF-AX4tHgQAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 10:56:34
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.168.6.243 (243.6.168.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.168.6.243 (243.6.168.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 06:56:27.855099 2026] [security2:error] [pid 22238:tid 22255] [client 34.168.6.243:52004] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.mouserart.com"] [uri "/.env.save"] [unique_id "apavWxMcZO0zCjph-eGwrQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
SCHAPPY
2026-09-01 10:26:37
(4 hours ago)
Malicious activity from IP detected: crowdsecurity/http-sensitive-files.
Web App Attack
Hacking
๐ฉ๐ช
big-cloud.nl
2026-09-01 09:47:46
(4 hours ago)
Try to access /.env
Web App Attack
Anonymous
2026-09-01 09:41:41
(5 hours ago)
Web App Attack
Brute-Force
Exploited Host
Web App Attack
Anonymous
2026-09-01 09:40:01
(5 hours ago)
suspicious request in access.log
Web App Attack
๐ฉ๐ช
Vegascosmetics
2026-09-01 09:37:42
(5 hours ago)
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after first-seen suspicion / AbuseIPDB repu ...
show more
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after first-seen suspicion / AbuseIPDB reputation policy (no URL signature). Evidence: Suspicion-Ban (Score 85>=65, Abuse 100, NonEU, first-seen)
show less
Hacking
Exploited Host
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-09-01 08:50:23
(5 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
๐ฉ๐ช
4server
2026-09-01 08:24:36
(6 hours ago)
[TueSep0110:24:33.2571602026][security2:error][pid3899282:tid3899400][client34.168.6.243:0]ModSecuri ...
show more
[TueSep0110:24:33.2571602026][security2:error][pid3899282:tid3899400][client34.168.6.243:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Patternmatch\"\(\?i\)\(\?:/\(\?:\^\|/\)\\\\\\\\.\(env\|git\|svn\|hg\|DS_Store\)\|/\(\?:wp-config\|\\\\\\\\.htaccess\|\\\\\\\\.htpasswd\)\|\\\\\\\\.\(\?:sql\|bak\|old\|log\)\$\)\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"156\"][id\"960720\"][msg\"Forbiddenfileaccessattempt\"][severity\"CRITICAL\"][hostname\"martinairsagl.ch\"][uri\"/wp-config.php.swp\"][unique_id\"apaLwTDfe8_laP5AohqSvAAAANY\"]
show less
Port Scan
Brute-Force
Web App Attack
Anonymous
2026-09-01 08:18:49
(6 hours ago)
34.168.6.243 - - [01/Sep/2026:10:18:42 +0200] "GET /wp-config.php~ HTTP/1.1" 403 146 "-" "crusader-w ...
show more
34.168.6.243 - - [01/Sep/2026:10:18:42 +0200] "GET /wp-config.php~ HTTP/1.1" 403 146 "-" "crusader-worker/1.0"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 07:46:34
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.168.6.243 (243.6.168.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.168.6.243 (243.6.168.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 03:46:26.245125 2026] [security2:error] [pid 15455:tid 15455] [client 34.168.6.243:34846] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "galysh.us"] [uri "/.env.local"] [unique_id "apaC0gZDu22ghOLlC2z8IwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
raph
2026-09-01 07:38:33
(7 hours ago)
[Wordpress] crawler /wp-admin/*, /wp-content/*, etc.
Bad Web Bot
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-09-01 07:20:23
(7 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐ฉ๐ช
FD-IX
2026-09-01 07:12:42
(7 hours ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack