๐ฒ๐พ
Rizzy
2026-09-01 10:07:06
(19 minutes ago)
Multiple WAF Violations
Brute-Force
Web App Attack
๐ฌ๐ง
Aetherweb Ark
2026-09-01 09:53:43
(32 minutes ago)
(mod_security) mod_security (id:949110) triggered by 34.187.59.40 (40.59.187.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:949110) triggered by 34.187.59.40 (40.59.187.34.bc.googleusercontent.com): N in the last X secs
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 09:40:38
(45 minutes ago)
(mod_security) mod_security (id:210492) triggered by 34.187.59.40 (40.59.187.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.187.59.40 (40.59.187.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 05:40:32.520169 2026] [security2:error] [pid 21447:tid 21447] [client 34.187.59.40:48974] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "spiritofacorn.com"] [uri "/wp-config.php~"] [unique_id "apadkLlETSgJ9qvVrBlX5QAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-09-01 09:36:05
(50 minutes ago)
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 34.187.59.40 (NL/The Netherlands/40.5 ...
show more
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 34.187.59.40 (NL/The Netherlands/40.59.187.34.bc.googleusercontent.com): 1 in the last 3600 secs (0-195)
show less
Hacking
๐ฉ๐ช
wpadm3
2026-09-01 06:40:54
(3 hours ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
๐ซ๐ฎ
paissangroup
2026-09-01 06:28:32
(3 hours ago)
Multiple WAF Violations
Web App Attack
๐ฉ๐ช
itsolon
2026-09-01 06:15:07
(4 hours ago)
[01/Sep/2026:08:15:07 +0200] 178824330730.117996 34.187.59.40 37652 217.154.7.177 443
[01/Sep/2026:0 ...
show more
[01/Sep/2026:08:15:07 +0200] 178824330730.117996 34.187.59.40 37652 217.154.7.177 443
[01/Sep/2026:08:15:07 +0200] 178824330742.077652 34.187.59.40 37720 217.154.7.177 443
[01/Sep/2026:08:15:07 +0200] 178824330797.461861 34.187.59.40 37688 217.154.7.177 443
[01/Sep/2026:08:15:07 +0200] 17882433077.248812 34.187.59.40 37672 217.154.7.177 443
[01/Sep/2026:08:15:07 +0200] 178824330752.355497 34.187.59.40 37622 217.154.7.177 443
...
show less
Port Scan
Hacking
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 05:33:44
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.187.59.40 (40.59.187.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.187.59.40 (40.59.187.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 01:33:36.851717 2026] [security2:error] [pid 30425:tid 30425] [client 34.187.59.40:59434] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "thegrabbagshow.com"] [uri "/.env.local"] [unique_id "apZjsPUf6E5w6p1U1z311wAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-09-01 04:48:47
(5 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
๐จ๐ญ
zynex
2026-09-01 04:19:35
(6 hours ago)
URL Probing: /.env
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 03:30:17
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.187.59.40 (40.59.187.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.187.59.40 (40.59.187.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 23:30:12.950100 2026] [security2:error] [pid 28575:tid 28582] [client 34.187.59.40:39956] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "idwic.spiritualchristian.com"] [uri "/.env.bak"] [unique_id "apZGxEqCN7_eadEqktdVWgAAAEU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-01 03:03:04
(7 hours ago)
Web App Attack
Brute-Force
Exploited Host
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-09-01 02:55:45
(7 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-01 02:54:05
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.187.59.40 (40.59.187.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.187.59.40 (40.59.187.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 22:54:00.731892 2026] [security2:error] [pid 5008:tid 5008] [client 34.187.59.40:35732] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "junoproperties.com"] [uri "/.env.prod"] [unique_id "apY-SHzm2BXaoxLRfnfq6QAAAEw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-01 02:30:04
(7 hours ago)
suspicious request in access.log
Web App Attack