🇳🇱
oisecnet
2026-09-04 21:02:35
(1 hour ago)
Automated report: Unauthorized vulnerability scanning detected on 2026-09-04. 621 requests from this ...
show more
Automated report: Unauthorized vulnerability scanning detected on 2026-09-04. 621 requests from this IP.
show less
Port Scan
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 15:20:07
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.175.110.63 (63.110.175.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.175.110.63 (63.110.175.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 11:20:00.940553 2026] [security2:error] [pid 9199:tid 9199] [client 34.175.110.63:57020] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.title36.com"] [uri "/.env.old"] [unique_id "aprhoGmPDpXPOUbdkhH1-wAAAIw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
todix
2026-09-04 14:05:27
(8 hours ago)
Web App Attack Exploid from 34.175.110.63
Web App Attack
🇺🇸
Starburst SysOp Team
2026-09-04 14:03:00
(8 hours ago)
Attempt to access a backup or working file. Pattern match "\\\\. (920500-stl2-14)
Hacking
🇩🇪
maxpower
2026-09-04 12:37:41
(10 hours ago)
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 34.175.110.63 (ES/Spain/63.110.175.34.bc ...
show more
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 34.175.110.63 (ES/Spain/63.110.175.34.bc.googleusercontent.com): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 34.175.110.63 - - [04/Sep/2026:14:37:36 +0200] "GET /wp-config.php.bak HTTP/1.1" 403 146 "-" "crusader-worker/1.0" "-" host=samimanutenzionisrl.it
show less
Port Scan
🇺🇸
TPI-Abuse
2026-09-04 12:35:06
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.175.110.63 (63.110.175.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.175.110.63 (63.110.175.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 08:34:58.084470 2026] [security2:error] [pid 18188:tid 18188] [client 34.175.110.63:57986] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ftp.henrietteg.com"] [uri "/wp-config.php.swp"] [unique_id "apq68ghCwUh6guAp1KSr6wAAADo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 11:37:09
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.175.110.63 (63.110.175.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.175.110.63 (63.110.175.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 07:37:01.129656 2026] [security2:error] [pid 11175:tid 11175] [client 34.175.110.63:39260] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "247.fishing"] [uri "/.env.bak"] [unique_id "apqtXT58jZHAhkDEXiUcOAAAAEI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 11:17:14
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.175.110.63 (63.110.175.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.175.110.63 (63.110.175.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 07:17:08.775157 2026] [security2:error] [pid 23706:tid 23706] [client 34.175.110.63:57424] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.cadimpressions.com"] [uri "/.env"] [unique_id "apqotGnVkr8s6_J72tcV3wAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 10:22:47
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.175.110.63 (63.110.175.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.175.110.63 (63.110.175.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 06:22:41.598676 2026] [security2:error] [pid 8051:tid 8051] [client 34.175.110.63:40412] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "nowell.net"] [uri "/wp-config.php~"] [unique_id "apqb8aR-uvdFwjqmBDBIQAAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 10:01:27
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.175.110.63 (63.110.175.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.175.110.63 (63.110.175.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 06:01:21.979831 2026] [security2:error] [pid 31338:tid 31338] [client 34.175.110.63:58250] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.buckinghambar.com"] [uri "/.env.production"] [unique_id "apqW8UwAH4SRKk43as3xIAAAACc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
e.fierstra
2026-09-04 08:26:43
(14 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
🇷🇺
DZBOT
2026-09-04 08:21:24
(14 hours ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 08:16:39
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.175.110.63 (63.110.175.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.175.110.63 (63.110.175.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 04:16:31.948602 2026] [security2:error] [pid 14161:tid 14161] [client 34.175.110.63:39804] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "dragonmaker.combustionlogic.com"] [uri "/.env.old"] [unique_id "app-X_hz16AFd4BbyLaqlwAAADo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
thetomtaylor.co.uk
2026-09-04 07:08:00
(15 hours ago)
Fail2Ban - [WEB]Custom exploit pattern detected on customexploits ... [ice01,ice02,wa01,wa02]
Hacking
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 06:58:02
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.175.110.63 (63.110.175.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.175.110.63 (63.110.175.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 02:57:58.649183 2026] [security2:error] [pid 143160:tid 143160] [client 34.175.110.63:57500] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "calfirstrealty.net"] [uri "/.env.bak"] [unique_id "appr9klOQEoKvDdvCehwFwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack