Anonymous
2026-08-27 21:20:55
(13 hours ago)
Wordpress vulnerability scanning
...
Web App Attack
๐บ๐ธ
mnsf
2026-08-27 20:05:13
(14 hours ago)
Abuse Detected (9)
Brute-Force
Web App Attack
๐ซ๐ฎ
Kimmo Rieskaniemi
2026-08-27 19:12:03
(15 hours ago)
CrowdSec triggered crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐บ๐ธ
kuj
2026-08-27 18:46:57
(15 hours ago)
2026-08-27T12:46:56.690211-06:00 derp derper[586]: 2026/08/27 12:46:56 http: TLS handshake error fro ...
show more
2026-08-27T12:46:56.690211-06:00 derp derper[586]: 2026/08/27 12:46:56 http: TLS handshake error from 34.173.172.195:55704: acme/autocert: host "20.184.117.136.bc.googleusercontent.com" not configured in HostWhitelist
2026-08-27T12:46:56.691295-06:00 derp derper[586]: 2026/08/27 12:46:56 http: TLS handshake error from 34.173.172.195:55710: acme/autocert: host "20.184.117.136.bc.googleusercontent.com" not configured in HostWhitelist
2026-08-27T12:46:56.691454-06:00 derp derper[586]: 2026/08/27 12:46:56 http: TLS handshake error from 34.173.172.195:55714: acme/autocert: host "20.184.117.136.bc.googleusercontent.com" not configured in HostWhitelist
...
show less
Port Scan
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-08-27 18:34:11
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.173.172.195 (195.172.173.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.173.172.195 (195.172.173.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 14:34:04.407558 2026] [security2:error] [pid 29741:tid 29741] [client 34.173.172.195:46650] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.andrewweigel.andrew.weigel.name"] [uri "/.env.example"] [unique_id "apCDHMEziHD25_u_vh-L7gAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Hazzard
2026-08-27 18:17:18
(16 hours ago)
(mod_security) mod_security triggered on hostname [redacted]): (CF_ENABLE)
SQL Injection
๐ณ๐ฑ
SysAdmin Dylan
2026-08-27 17:53:27
(16 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.173.172.195 (US/United States/195.172.173.34 ...
show more
(mod_security) mod_security (id:210730) triggered by 34.173.172.195 (US/United States/195.172.173.34.bc.googleusercontent.com): 10 in the last 3600 secs
show less
Brute-Force
Anonymous
2026-08-27 17:15:06
(17 hours ago)
suspicious request in access.log
Web App Attack
๐ฉ๐ช
LRob
2026-08-27 17:13:24
(17 hours ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /.env.old (+12 more) | 2026-08-27 17:13 UTC
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 16:49:17
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.173.172.195 (195.172.173.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.173.172.195 (195.172.173.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 12:49:12.179572 2026] [security2:error] [pid 32638:tid 32638] [client 34.173.172.195:38598] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "neff.family.name"] [uri "/.env.production"] [unique_id "apBqiBYtXwaqX0vLHHGBDgAAADQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
ghostwarriors
2026-08-27 15:50:19
(18 hours ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack
๐ฉ๐ช
yitzhaq
2026-08-27 15:47:11
(18 hours ago)
34.173.172.195 - - [27/Aug/2026:17:47:08 +0200] "GET /wp-config.php~ HTTP/1.1" 404 30699 "-" "crusad ...
show more
34.173.172.195 - - [27/Aug/2026:17:47:08 +0200] "GET /wp-config.php~ HTTP/1.1" 404 30699 "-" "crusader-worker/1.0"
34.173.172.195 - - [27/Aug/2026:17:47:08 +0200] "GET /wp-config.php.bak HTTP/1.1" 404 30698 "-" "crusader-worker/1.0"
34.173.172.195 - - [27/Aug/2026:17:47:08 +0200] "GET /.env.production HTTP/1.1" 404 30699 "-" "crusader-worker/1.0"
34.173.172.195 - - [27/Aug/2026:17:47:08 +0200] "GET /actuator/env HTTP/1.1" 404 30699 "-" "crusader-worker/1.0"
34.173.172.195 - - [27/Aug/2026:17:47:08 +0200] "GET /actuator/configprops HTTP/1.1" 404 30699 "-" "crusader-worker/1.0"
34.173.172.195 - - [27/Aug/2026:17:47:08 +0200] "GET /.env.example HTTP/1.1" 404 30699 "-" "crusader-worker/1.0"
34.173.172.195 - - [27/Aug/2026:17:47:08 +0200] "GET /.env.prod HTTP/1.1" 404 30699 "-" "crusader-worker/1.0"
34.173.172.195 - - [27/Aug/2026:17:47:08 +0200] "GET /.env.backup HTTP/1.1" 404 30698 "-" "crusader-worker/1.0"
34.173.172.195 - - [27/Aug/2026:17:47:08 +0200] "GET /.env.save HTTP/1.1" 404 3069
show less
Web App Attack
Brute-Force
๐ฉ๐ช
ger-stg-sifi1
2026-08-27 15:27:38
(18 hours ago)
(wordpress) Failed wordpress login using wp-login.php or xmlrpc.php
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 14:53:08
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.173.172.195 (195.172.173.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.173.172.195 (195.172.173.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 10:52:59.696880 2026] [security2:error] [pid 5659:tid 5659] [client 34.173.172.195:46674] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "btccasting.com"] [uri "/.env.production"] [unique_id "apBPS66izEnmYwO4S1Xc0AAAACU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐พ
lns.bz
2026-08-27 14:48:57
(19 hours ago)
Too many 404 requests [BY]
Web App Attack