🇫🇷
mail.avx.gr
2026-09-04 10:55:41
(8 minutes ago)
(nginxENVSCAN) nginx environment-file scanner detected from 34.173.124.29 (US/United States/Iowa/Cou ...
show more
(nginxENVSCAN) nginx environment-file scanner detected from 34.173.124.29 (US/United States/Iowa/Council Bluffs/29.124.173.34.bc.googleusercontent.com)
show less
Hacking
🇩🇪
FeG Deutschland
2026-09-04 10:50:57
(13 minutes ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 1247
Exploited Host
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 10:49:15
(15 minutes ago)
(mod_security) mod_security (id:210492) triggered by 34.173.124.29 (29.124.173.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.173.124.29 (29.124.173.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 06:49:08.040834 2026] [security2:error] [pid 31157:tid 31202] [client 34.173.124.29:39282] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "video.kd9uri.com"] [uri "/.env.bak"] [unique_id "apqiJA3ftUW3UjUe0T6x0gAAAE0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇸🇪
vaia.cloud
2026-09-04 10:45:02
(19 minutes ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
🇩🇪
MusicLibrary
2026-09-04 10:36:03
(28 minutes ago)
Probing foreign-stack admin panels / known exploit paths (Joomla, phpMyAdmin, phpunit, OWA, etc.)
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 10:03:36
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.173.124.29 (29.124.173.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.173.124.29 (29.124.173.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 06:03:30.482313 2026] [security2:error] [pid 28615:tid 28615] [client 34.173.124.29:51994] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ballast-capital.com"] [uri "/wp-config.php.bak"] [unique_id "apqXcthMg7yhBoBOtAAjQQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 09:37:31
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.173.124.29 (29.124.173.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.173.124.29 (29.124.173.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 05:37:27.736784 2026] [security2:error] [pid 29866:tid 29866] [client 34.173.124.29:50552] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "greathomesrealty.net"] [uri "/.env.old"] [unique_id "apqRVz-6IlBwHEsuBpvfigAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
agenciahypelab.com.br
2026-09-04 09:35:55
(1 hour ago)
WordPress login brute-force detectado e bloqueado pelo CSF/LFD. Trigger: LF_TRIGGER
Brute-Force
SSH
🇦🇺
AWW-Admin
2026-09-04 09:24:14
(1 hour ago)
(mod_security) mod_security triggered on hostname [redacted] 34.173.124.29 (US/United States/29.124. ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.173.124.29 (US/United States/29.124.173.34.bc.googleusercontent.com)
show less
SQL Injection
🇫🇷
dynamix
2026-09-04 08:24:50
(2 hours ago)
Multiple WAF Violations
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 08:16:43
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.173.124.29 (29.124.173.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.173.124.29 (29.124.173.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 04:16:35.675076 2026] [security2:error] [pid 14299:tid 14299] [client 34.173.124.29:57120] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.floorsanding.org"] [uri "/wp-config.php~"] [unique_id "app-Y4b9H2AtnWfANyQRSQAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 07:48:21
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.173.124.29 (29.124.173.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.173.124.29 (29.124.173.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 03:48:16.130999 2026] [security2:error] [pid 1354:tid 1354] [client 34.173.124.29:39842] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ftp.bahamascruisersguide.com"] [uri "/wp-config.php.swp"] [unique_id "app3wNZw3aNXi5UAgCbsqQAAAEg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
Aetherweb Ark
2026-09-04 05:53:57
(5 hours ago)
(mod_security) mod_security (id:949110) triggered by 34.173.124.29 (US/United States/29.124.173.34.b ...
show more
(mod_security) mod_security (id:949110) triggered by 34.173.124.29 (US/United States/29.124.173.34.bc.googleusercontent.com): N in the last X secs
show less
Web App Attack
🇨🇦
Anytech
2026-09-04 05:16:00
(5 hours ago)
Blocked by Conn-Monitor: env-probing
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-04 05:15:52
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.173.124.29 (29.124.173.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.173.124.29 (29.124.173.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 01:15:44.466573 2026] [security2:error] [pid 1724:tid 1724] [client 34.173.124.29:45726] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "worthhomes4rent.com"] [uri "/.env.prod"] [unique_id "appUAHqm1JiKXzg5IKCuJQAAACM"]
show less
Brute-Force
Bad Web Bot
Web App Attack