๐บ๐ธ
TPI-Abuse
2026-08-27 18:57:16
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.20.139.16 (16.139.20.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.20.139.16 (16.139.20.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 14:57:12.929586 2026] [security2:error] [pid 14321:tid 14321] [client 34.20.139.16:48686] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "tropicalteethwhitening.com.scottwithers.xyz"] [uri "/.env.production"] [unique_id "apCIiO5oju3daa4D21YDfAAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-27 18:55:23
(1 hour ago)
34.20.139.16 - - [27/Aug/2026:20:55:16 +0200] "GET /.env.backup HTTP/1.1" 403 12583 "-" "crusader-wo ...
show more
34.20.139.16 - - [27/Aug/2026:20:55:16 +0200] "GET /.env.backup HTTP/1.1" 403 12583 "-" "crusader-worker/1.0"
34.20.139.16 - - [27/Aug/2026:20:55:16 +0200] "GET /.env HTTP/1.1" 403 12583 "-" "crusader-worker/1.0"
34.20.139.16 - - [27/Aug/2026:20:55:16 +0200] "GET /storage/logs/laravel.log HTTP/1.1" 403 12583 "-" "crusader-worker/1.0"
34.20.139.16 - - [27/Aug/2026:20:55:16 +0200] "GET /wp-config.php~ HTTP/1.1" 403 12583 "-" "crusader-worker/1.0"
34.20.139.16 - - [27/Aug/2026:20:55:16 +0200] "GET /.env.example HTTP/1.1" 403 12583 "-" "crusader-worker/1.0"
34.20.139.16 - - [27/Aug/2026:20:55:16 +0200] "GET /.env.bak HTTP/1.1" 403 12583 "-" "crusader-worker/1.0"
34.20.139.16 - - [27/Aug/2026:20:55:16 +0200] "GET /.env.dev HTTP/1.1" 403 12583 "-" "crusader-worker/1.0"
34.20.139.16 - - [27/Aug/2026:20:55:16 +0200] "GET /wp-config.php.bak HTTP/1.1" 403 12583 "-" "crusader-worker/1.0"
34.20.139.16 - - [27/Aug/2026:20:55:16 +0200] "GET /actuator/configprops HTTP/1.1" 403 12583 "-" "crusader-wor
...
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
Holger
2026-08-27 18:49:15
(1 hour ago)
Bruteforce WebAttack
Brute-Force
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-08-27 18:09:17
(1 hour ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
Anonymous
2026-08-27 17:10:23
(2 hours ago)
IP banned by Fail2Ban in jail nginx-abusive-ips
Web App Attack
Brute-Force
Bad Web Bot
๐ฉ๐ช
FeG Deutschland
2026-08-27 17:03:28
(3 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
๐จ๐ญ
4server
2026-08-27 16:10:15
(3 hours ago)
[ThuAug2718:10:09.8107542026][security2:error][pid1579653:tid1579889][client34.20.139.16:0]ModSecuri ...
show more
[ThuAug2718:10:09.8107542026][security2:error][pid1579653:tid1579889][client34.20.139.16:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\".env\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"610\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"swiss-domain-name.ch\"][uri\"/.env.dev\"][unique_id\"apBhYZlpmP_HpyHpXRbRcQAAAMM\"]
show less
Hacking
Web App Attack
๐จ๐ฆ
polycoda
2026-08-27 14:46:26
(5 hours ago)
AutoBlock: ๐ฏ Vulnerability Scanner (Non Decay-Based)
Hacking
Bad Web Bot
Web App Attack
Anonymous
2026-08-27 14:01:18
(6 hours ago)
Banned by Fail2Ban on server
Web App Attack
๐ซ๐ฎ
6kilowatti
2026-08-27 12:34:18
(7 hours ago)
34.20.139.16 - - [27/Aug/2026:15:34:18 +0300] "GET /.env.backup HTTP/1.1" 404 22269 "-" "crusader-wo ...
show more
34.20.139.16 - - [27/Aug/2026:15:34:18 +0300] "GET /.env.backup HTTP/1.1" 404 22269 "-" "crusader-worker/1.0"
...
show less
Web App Attack
๐ง๐พ
lns.bz
2026-08-27 12:27:44
(7 hours ago)
Too many 404 requests [BY]
Web App Attack
๐ฉ๐ช
wpadm4
2026-08-27 12:11:28
(7 hours ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 12:09:45
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.20.139.16 (16.139.20.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.20.139.16 (16.139.20.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 08:09:38.721852 2026] [security2:error] [pid 16124:tid 16124] [client 34.20.139.16:40410] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "narrowacresbees.com"] [uri "/.env.dev"] [unique_id "apApAu0BLg9E1YGhiJwzewAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
myintarweb
2026-08-27 11:19:28
(8 hours ago)
34.20.139.16 - mail.madmick.co.uk [27/Aug/2026:12:19:27 +0100] 443 "GET /wp-config.php.swp HTTP/1.1" ...
show more
34.20.139.16 - mail.madmick.co.uk [27/Aug/2026:12:19:27 +0100] 443 "GET /wp-config.php.swp HTTP/1.1" 301 6926 "-" "crusader-worker/1.0"
34.20.139.16 - mail.madmick.co.uk [27/Aug/2026:12:19:27 +0100] 443 "GET /.env HTTP/1.1" 301 6926 "-" "crusader-worker/1.0"
34.20.139.16 - mail.madmick.co.uk [27/Aug/2026:12:19:27 +0100] 443 "GET /.env.old HTTP/1.1" 301 6926 "-" "crusader-worker/1.0"
34.20.139.16 - mail.madmick.co.uk [27/Aug/2026:12:19:27 +0100] 443 "GET /.env.dev HTTP/1.1" 301 6926 "-" "crusader-worker/1.0"
34.20.139.16 - mail.madmick.co.uk [27/Aug/2026:12:19:27 +0100] 443 "GET /.env.production HTTP/1.1" 301 6926 "-" "crusader-worker/1.0"
34.20.139.16 - mail.madmick.co.uk [27/Aug/2026:12:19:27 +0100] 443 "GET /wp-config.php.bak HTTP/1.1" 301 6926 "-" "crusader-worker/1.0"
34.20.139.16 - mail.madmick.co.uk [27/Aug/2026:12:19:27 +0100] 443 "GET /.env.example HTTP/1.1" 301 6926 "-" "crusader-worker/1.0"
34.20.139.16 - mail.madmick.co.uk [27/Aug/2026:12:19:27 +0100] 443 "GET /.env.local HT
...
show less
Hacking
Bad Web Bot
Web App Attack
๐ฉ๐ช
webanyone
2026-08-27 11:17:28
(8 hours ago)
WAF repeated trigger detected by Fail2Ban in plesk-modsecurity jail
Web App Attack