๐ซ๐ท
dynamix
2026-09-01 03:20:09
(56 minutes ago)
Multiple WAF Violations
Web App Attack
๐ซ๐ท
masterguru
2026-09-01 03:19:04
(57 minutes ago)
Attempt to access a backup or working file. Pattern match "\\\\. (920500-193)
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-01 03:10:21
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.22.63.243 (243.63.22.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.22.63.243 (243.63.22.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 23:10:16.143388 2026] [security2:error] [pid 29920:tid 29920] [client 34.22.63.243:46624] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "pharmasalesconnect.com"] [uri "/wp-config.php.bak"] [unique_id "apZCGCTPz6V1krhNGiNzkgAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 02:44:30
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.22.63.243 (243.63.22.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.22.63.243 (243.63.22.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 22:44:24.827276 2026] [security2:error] [pid 11588:tid 11588] [client 34.22.63.243:56098] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.hardemancountyjournal.com"] [uri "/.env.old"] [unique_id "apY8CEz7P3GVy0zcDP1TGQAAACg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
marcel-knorr.de
2026-09-01 01:38:50
(2 hours ago)
[MK-Root1] Blocked by UFW
Brute-Force
Port Scan
๐บ๐ธ
TPI-Abuse
2026-09-01 00:15:39
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.22.63.243 (243.63.22.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.22.63.243 (243.63.22.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 20:15:32.034067 2026] [security2:error] [pid 8873:tid 8873] [client 34.22.63.243:35972] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.gowithevergreen.com"] [uri "/.env.old"] [unique_id "apYZJKkLNSmLgD-Us_ZLEgAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
thilo
2026-08-31 23:45:40
(4 hours ago)
Probe for vulnerabilities. Path attempted: /.env.dev
Web App Attack
๐บ๐ธ
mnsf
2026-08-31 23:06:14
(5 hours ago)
Scanning/Probing (20)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-31 22:40:59
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.22.63.243 (243.63.22.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.22.63.243 (243.63.22.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 18:40:53.546155 2026] [security2:error] [pid 3601135:tid 3601281] [client 34.22.63.243:60210] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "besfixedwireless.com"] [uri "/.env.dev"] [unique_id "apYC9TXTCLp4H1pGL-ttuAAAAEE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
VHosting
2026-08-31 22:20:04
(5 hours ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-31 22:18:28
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.22.63.243 (243.63.22.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.22.63.243 (243.63.22.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 18:18:20.175521 2026] [security2:error] [pid 9552:tid 9552] [client 34.22.63.243:48614] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.celltechs.net"] [uri "/.env.old"] [unique_id "apX9rC59mzQazHumG7-Z3AAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
4server
2026-08-31 22:17:38
(5 hours ago)
[TueSep0100:17:30.2502792026][security2:error][pid439259:tid439581][client34.22.63.243:0]ModSecurity ...
show more
[TueSep0100:17:30.2502792026][security2:error][pid439259:tid439581][client34.22.63.243:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\".env\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"610\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"autoconfig.kairoslab.ch\"][uri\"/.env.local\"][unique_id\"apX9emU7ru70w4w_S7uKhQAAAFI\"]
show less
Hacking
Web App Attack