Anonymous
2026-09-06 03:33:46
(4 hours ago)
[da.kdns.gr] httpd-config-scan: logs=/var/log/httpd/access_log; samples=/.env.backup | /wp-config.ph ...
show more
[da.kdns.gr] httpd-config-scan: logs=/var/log/httpd/access_log; samples=/.env.backup | /wp-config.php.swp | /.env
show less
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 02:58:20
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.182.180.117 (117.180.182.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.182.180.117 (117.180.182.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 22:58:16.726072 2026] [security2:error] [pid 30338:tid 30338] [client 34.182.180.117:54648] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.allcostaricarentals.com"] [uri "/.env"] [unique_id "apzWyBaohXuxWIgJP-ZOLQAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
dbmwebdesign
2026-09-06 02:10:05
(6 hours ago)
WAF repeated trigger detected by Fail2Ban in plesk-modsecurity jail
Web App Attack
🇺🇸
cwytech
2026-09-06 01:59:42
(6 hours ago)
Fleet-wide ban from the Ghostfleet 👻. Triggered by scenario: crowdsecurity/http-sensitive-files.
Bad Web Bot
Web App Attack
🇳🇱
WeCloudit-Anti-Abuse
2026-09-06 01:48:19
(6 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-06 01:32:38
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.182.180.117 (117.180.182.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.182.180.117 (117.180.182.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 21:32:29.993884 2026] [security2:error] [pid 17119:tid 17119] [client 34.182.180.117:44970] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "monogrampartynapkins.com"] [uri "/.env.dev"] [unique_id "apzCrUE2mAxuBTHA1bCMzAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
Starburst SysOp Team
2026-09-06 01:16:01
(7 hours ago)
Restricted File Access Attempt. Matched phrase ".env" at REQUEST_FILENAME. (930130-mnz6-1)
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 00:02:25
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.182.180.117 (117.180.182.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.182.180.117 (117.180.182.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 20:02:18.292774 2026] [security2:error] [pid 2036:tid 2036] [client 34.182.180.117:35638] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "karishma.byles.net"] [uri "/wp-config.php.swp"] [unique_id "apytijNJ79O3MeqKPF9JXAAAAFQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇮🇩
sockominfo
2026-09-06 00:00:28
(8 hours ago)
Reported by TangerangKota-CSIRT. Status: MALICIOUS
Hacking
Email Spam
Anonymous
2026-09-05 23:24:46
(8 hours ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 23:12:54
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.182.180.117 (117.180.182.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.182.180.117 (117.180.182.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 19:12:48.423179 2026] [security2:error] [pid 8800:tid 8800] [client 34.182.180.117:44044] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "86mountaineers.pluralmatrix.net"] [uri "/wp-config.php~"] [unique_id "apyh8LVJvTSQ528k5lcy3QAAAHA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-05 23:05:01
(9 hours ago)
suspicious request in access.log
Web App Attack
🇺🇸
factor1
2026-09-05 22:52:48
(9 hours ago)
CrowdSec at athena Reports Abuse
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 22:51:47
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.182.180.117 (117.180.182.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.182.180.117 (117.180.182.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 18:51:43.155483 2026] [security2:error] [pid 19756:tid 19756] [client 34.182.180.117:58010] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "dorioconnell.com"] [uri "/.env"] [unique_id "apyc_xlDTnNWAzARQ1hwMAAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
WeCloudit-Anti-Abuse
2026-09-05 22:39:03
(9 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking