🇵🇾
armandosaucedo.me
2026-09-04 15:21:43
(12 hours ago)
Threat Intelligence via ARMTI, Web Attack: GET /.env.dev
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 15:20:56
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.175.181.29 (29.181.175.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.175.181.29 (29.181.175.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 11:20:52.034534 2026] [security2:error] [pid 19328:tid 19328] [client 34.175.181.29:60010] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.thewritekellys.com"] [uri "/.env"] [unique_id "aprh1EWv7_GYh1fdiTFgegAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇮🇩
Burayot
2026-09-04 15:02:20
(12 hours ago)
LF_MODSEC: (mod_security) mod_security (id:949110) triggered by 34.175.181.29 (ES/Spain/29.181.175.3 ...
show more
LF_MODSEC: (mod_security) mod_security (id:949110) triggered by 34.175.181.29 (ES/Spain/29.181.175.34.bc.googleusercontent.com): 2 in the last 3600 secs
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 14:06:43
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.175.181.29 (29.181.175.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.175.181.29 (29.181.175.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 10:06:37.497997 2026] [security2:error] [pid 22979:tid 22979] [client 34.175.181.29:34412] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.72blues.com"] [uri "/wp-config.php.swp"] [unique_id "aprQbeEfUJXNKZLoyHKjkQAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
e.fierstra
2026-09-04 13:27:02
(14 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
Anonymous
2026-09-04 13:16:57
(14 hours ago)
Web application attack detected.
Web App Attack
🇳🇱
WeCloudit-Anti-Abuse
2026-09-04 12:56:41
(14 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
🇨🇭
zynex
2026-09-04 12:01:03
(15 hours ago)
URL Probing: /wp-config.php.bak
Web App Attack
🇮🇩
penjaga BRIN
2026-09-04 10:56:30
(16 hours ago)
Suspicious malicious activity
Hacking
Anonymous
2026-09-04 10:20:04
(17 hours ago)
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-04 10:18:07
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.175.181.29 (29.181.175.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.175.181.29 (29.181.175.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 06:18:01.135577 2026] [security2:error] [pid 24897:tid 24897] [client 34.175.181.29:49106] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "pathpa.org"] [uri "/wp-config.php~"] [unique_id "apqa2Wct4o3xTVBJCUA4TwAAACA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 09:51:10
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.175.181.29 (29.181.175.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.175.181.29 (29.181.175.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 05:51:06.331715 2026] [security2:error] [pid 29118:tid 29118] [client 34.175.181.29:41408] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "handymaneats.com.pluralmatrix.net"] [uri "/wp-config.php.swp"] [unique_id "apqUior9Jvfx8RgyGYxXdgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇸🇪
vaia.cloud
2026-09-04 09:40:02
(17 hours ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 09:18:38
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.175.181.29 (29.181.175.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.175.181.29 (29.181.175.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 05:18:31.279035 2026] [security2:error] [pid 31157:tid 31191] [client 34.175.181.29:50344] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "justwondering.net"] [uri "/wp-config.php.bak"] [unique_id "apqM5w3ftUW3UjUe0T6oOwAAAEM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
raph
2026-09-04 08:45:16
(18 hours ago)
[Wordpress] crawler /wp-admin/*, /wp-content/*, etc.
Bad Web Bot
Web App Attack