๐บ๐ธ
mccsoft.io
2026-09-01 14:04:33
(5 hours ago)
Web application attack / vulnerability scanning against our public nginx web server (TCP 80/443). So ...
show more
Web application attack / vulnerability scanning against our public nginx web server (TCP 80/443). Source matched a blocked-path security rule (jail nginx-444); server returned HTTP 444 (connection closed without response). TCP three-way handshake completed (full HTTP request received).
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 13:56:19
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.21.248.9 (9.248.21.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.21.248.9 (9.248.21.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 09:56:11.987096 2026] [security2:error] [pid 10820:tid 10820] [client 34.21.248.9:44224] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.mkdesignndetailing.com"] [uri "/wp-config.php~"] [unique_id "apbZe8psLp1Y0Aag0R15xgAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-01 13:20:32
(6 hours ago)
CrowdSec:crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
Anonymous
2026-09-01 12:58:47
(6 hours ago)
Web scanner: GET /.env.example
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-01 11:09:48
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.21.248.9 (9.248.21.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.21.248.9 (9.248.21.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 07:09:44.406630 2026] [security2:error] [pid 12296:tid 12296] [client 34.21.248.9:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.earscript.net"] [uri "/.env.old"] [unique_id "apayeBDcz7sGQtTGg2ssAAAAACE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฒ๐พ
Rizzy
2026-09-01 07:48:08
(11 hours ago)
Multiple WAF Violations
Brute-Force
Web App Attack
๐ฉ๐ช
ddobko
2026-09-01 07:09:53
(12 hours ago)
Bad Web Bot
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-09-01 06:34:05
(13 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 12
Exploited Host
Web App Attack
Anonymous
2026-09-01 06:24:17
(13 hours ago)
Scanner hitting /.env.dev on livekit.ara-oman.com (GOOGL-2) โ aaguard
Brute-Force
Port Scan
๐บ๐ธ
TPI-Abuse
2026-09-01 06:08:05
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.21.248.9 (9.248.21.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.21.248.9 (9.248.21.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 02:07:56.834350 2026] [security2:error] [pid 25530:tid 25530] [client 34.21.248.9:51102] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.luxurymicrobikinis.com"] [uri "/wp-config.php.swp"] [unique_id "apZrvD3OSH9yfJea1ojS6wAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
raph
2026-09-01 05:17:46
(14 hours ago)
[Wordpress] crawler /wp-admin/*, /wp-content/*, etc.
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 04:31:15
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.21.248.9 (9.248.21.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.21.248.9 (9.248.21.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 00:31:09.846488 2026] [security2:error] [pid 31301:tid 31301] [client 34.21.248.9:34092] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bosozuki.com"] [uri "/.env.production"] [unique_id "apZVDX1CkdlxZU4OSYAwkgAAACw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
MyGlobalFlowers
2026-09-01 04:19:04
(15 hours ago)
Multiple WAF Violations
Web App Attack
๐ฉ๐ช
wpadm4
2026-09-01 04:16:03
(15 hours ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 03:53:26
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.21.248.9 (9.248.21.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.21.248.9 (9.248.21.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 23:53:21.010267 2026] [security2:error] [pid 5856:tid 5856] [client 34.21.248.9:41062] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "laurengardner.org"] [uri "/wp-config.php~"] [unique_id "apZMMa0ahJBJlzvOkPXTtQAAADM"]
show less
Brute-Force
Bad Web Bot
Web App Attack