🇨🇦
aks4226
2026-09-05 07:40:27
(2 hours ago)
Bot search, attacking common web applications.
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 15:19:17
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.185.175.127 (127.175.185.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.185.175.127 (127.175.185.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 11:19:11.794472 2026] [security2:error] [pid 8858:tid 8858] [client 34.185.175.127:60556] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.tek-front.com"] [uri "/.env.production"] [unique_id "aprhb1THWtagOxqH57PPvAAAAIM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 14:11:10
(20 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.185.175.127 (127.175.185.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.185.175.127 (127.175.185.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 10:11:02.082012 2026] [security2:error] [pid 23002:tid 23020] [client 34.185.175.127:35080] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.love-spells-magic.com"] [uri "/wp-config.php.swp"] [unique_id "aprRdsUEohzoiyy4PKUVnAAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇧🇷
chronos
2026-09-04 13:09:12
(21 hours ago)
2026-09-04 09:49:27 UTC-3||Unauthorized connection attempt detected for port scanning
Port Scan
🇧🇷
chronos
2026-09-04 12:49:27
(21 hours ago)
Web traffic. Possible probing or exploitation attempts. | Port: 443 | Proto: TCP | Location: Germany ...
show more
Web traffic. Possible probing or exploitation attempts. | Port: 443 | Proto: TCP | Location: Germany, Frankfurt am Main
show less
Exploited Host
Brute-Force
Hacking
🇫🇷
masterguru
2026-09-04 10:32:04
(1 day ago)
Attempt to access a backup or working file. Pattern match "\\\\. (920500-193)
Hacking
🇷🇴
clauss
2026-09-04 10:11:41
(1 day ago)
34.185.175.127 - - [04/Sep/2026:13:11:39 +0300] "GET /storage/logs/laravel.log HTTP/2.0" 403 146 "-" ...
show more
34.185.175.127 - - [04/Sep/2026:13:11:39 +0300] "GET /storage/logs/laravel.log HTTP/2.0" 403 146 "-" "crusader-worker/1.0"
34.185.175.127 - - [04/Sep/2026:13:11:40 +0300] "GET /_ignition/health-check HTTP/2.0" 404 13686 "-" "crusader-worker/1.0"
...
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 10:07:16
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.185.175.127 (127.175.185.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.185.175.127 (127.175.185.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 06:07:10.435398 2026] [security2:error] [pid 16567:tid 16567] [client 34.185.175.127:53188] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.kraatzrussell.com"] [uri "/wp-config.php.bak"] [unique_id "apqYTnkS77Ako10miEzqHQAAACo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 09:35:13
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.185.175.127 (127.175.185.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.185.175.127 (127.175.185.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 05:35:07.572846 2026] [security2:error] [pid 21800:tid 21800] [client 34.185.175.127:49592] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "qualuedata.com"] [uri "/.env.backup"] [unique_id "apqQy37ZtEfNX58n9f8kiAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
e.fierstra
2026-09-04 09:05:38
(1 day ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
🇻🇳
trung.fun
2026-09-04 08:29:32
(1 day ago)
DDoS, Hack, Brute Force, Web Attack
...
DDoS Attack
Web Spam
Hacking
Brute-Force
Web App Attack
🇫🇷
masterguru
2026-09-04 08:22:04
(1 day ago)
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 34.185.175.127 (DE/Germany/127.175.18 ...
show more
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 34.185.175.127 (DE/Germany/127.175.185.34.bc.googleusercontent.com): 2 in the last 3600 secs (0-196)
show less
Hacking
🇺🇸
TPI-Abuse
2026-09-04 08:21:03
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.185.175.127 (127.175.185.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.185.175.127 (127.175.185.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 04:20:57.928815 2026] [security2:error] [pid 22894:tid 22894] [client 34.185.175.127:41804] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.martinez-morera.com"] [uri "/.env"] [unique_id "app_aSXBTqky8O2RDg7wZAAAAEM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
FD-IX
2026-09-04 08:20:38
(1 day ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
Anonymous
2026-09-04 08:14:06
(1 day ago)
Blocked by siteaihub.com: auto: matched exact:/.env
Hacking
Bad Web Bot