๐บ๐ธ
TPI-Abuse
2026-09-01 13:55:04
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.181.177.38 (38.177.181.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.181.177.38 (38.177.181.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 09:54:58.979523 2026] [security2:error] [pid 28202:tid 28202] [client 34.181.177.38:45042] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.turtletaekwondo.com"] [uri "/.env.backup"] [unique_id "apbZMjuxG85zLydrySS6CgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 13:06:47
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.181.177.38 (38.177.181.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.181.177.38 (38.177.181.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 09:06:40.742058 2026] [security2:error] [pid 17973:tid 17973] [client 34.181.177.38:44656] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "pinetreedistrict.rimaine.org"] [uri "/.env"] [unique_id "apbN4N6rLLEuGdiKXHIRqwAAACg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-01 12:33:22
(1 day ago)
Blocked by ModSec and CSF
Port Scan
๐บ๐ธ
daveoctober
2026-09-01 11:58:37
(1 day ago)
October Sentinel: honeypot triggered
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob
2026-09-01 11:09:44
(1 day ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /.env.production (+12 more) | 2026-09-01 11:09 UTC
show less
Hacking
Web App Attack
๐ฉ๐ช
FD-IX
2026-09-01 11:08:27
(1 day ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 11:01:49
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.181.177.38 (38.177.181.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.181.177.38 (38.177.181.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 07:01:44.391538 2026] [security2:error] [pid 25485:tid 25485] [client 34.181.177.38:55550] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.ken-parker.com"] [uri "/wp-config.php~"] [unique_id "apawmFCm2HjIF7nace3-FgAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
Aetherweb Ark
2026-09-01 10:50:22
(1 day ago)
(mod_security) mod_security (id:949110) triggered by 34.181.177.38 (US/United States/38.177.181.34.b ...
show more
(mod_security) mod_security (id:949110) triggered by 34.181.177.38 (US/United States/38.177.181.34.bc.googleusercontent.com): N in the last X secs
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 10:45:25
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.181.177.38 (38.177.181.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.181.177.38 (38.177.181.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 06:45:18.477210 2026] [security2:error] [pid 18444:tid 18444] [client 34.181.177.38:52736] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "perlcreative.com"] [uri "/wp-config.php.swp"] [unique_id "apasvmrdSpM5jEsg_tcqXQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-09-01 10:03:32
(1 day ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
๐จ๐ญ
zynex
2026-09-01 09:59:41
(1 day ago)
URL Probing: /.env
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 07:51:09
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.181.177.38 (38.177.181.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.181.177.38 (38.177.181.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 03:51:02.844931 2026] [security2:error] [pid 24972:tid 24972] [client 34.181.177.38:50556] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ftp.proplanarchitects.com"] [uri "/.env.bak"] [unique_id "apaD5sk-jBIuf39JC1F2RAAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 06:37:05
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.181.177.38 (38.177.181.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.181.177.38 (38.177.181.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 02:37:02.224513 2026] [security2:error] [pid 25555:tid 25555] [client 34.181.177.38:34244] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "texaspamman.com"] [uri "/.env.backup"] [unique_id "apZyjl_9mJo-GgDxqAttawAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 06:08:10
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.181.177.38 (38.177.181.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.181.177.38 (38.177.181.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 02:08:04.431297 2026] [security2:error] [pid 15370:tid 15370] [client 34.181.177.38:53596] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.179vfs.com"] [uri "/.env.prod"] [unique_id "apZrxBVyh5icnH3KWsob4wAAACI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-09-01 05:26:05
(1 day ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack