🇺🇸
OceanTreasure
2026-09-06 06:25:03
(1 day ago)
tcp/443; Spring Boot Actuator exposure attempt: "GET /actuator/env" @ 2026-09-06T06:18:32Z [proxy]
Web App Attack
Anonymous
2026-09-06 04:05:08
(1 day ago)
WAF repeated trigger detected by Fail2Ban
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 03:50:16
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.22.94.137 (137.94.22.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.22.94.137 (137.94.22.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 23:50:08.645951 2026] [security2:error] [pid 24284:tid 24284] [client 34.22.94.137:59178] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.southshorestreetrods.com"] [uri "/.env.save"] [unique_id "apzi8MW_MkecqjSbnqq_mAAAAGQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
FD-IX
2026-09-06 03:28:10
(1 day ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
🇩🇪
todix
2026-09-06 03:01:08
(1 day ago)
Web App Attack Exploid from 34.22.94.137
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 03:00:07
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.22.94.137 (137.94.22.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.22.94.137 (137.94.22.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 22:59:57.240440 2026] [security2:error] [pid 3425:tid 3425] [client 34.22.94.137:53956] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.casalaaldehuela.com"] [uri "/.env.prod"] [unique_id "apzXLaL_Hijpirr9Ue-WEAAAACo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
crypto i trust, hold i must
2026-09-06 02:36:48
(1 day ago)
Web scanner path: /actuator/configprops
Web App Attack
🇳🇱
WeCloudit-Anti-Abuse
2026-09-06 02:28:53
(1 day ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
Anonymous
2026-09-06 02:23:34
(1 day ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 01:55:41
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.22.94.137 (137.94.22.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.22.94.137 (137.94.22.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 21:55:36.869069 2026] [security2:error] [pid 695:tid 695] [client 34.22.94.137:58884] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "artichokedesign.net"] [uri "/wp-config.php.swp"] [unique_id "apzIGGt7A4o5rXsnPJpGSgAAAFc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
dynamix
2026-09-06 01:51:22
(1 day ago)
Multiple WAF Violations
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 01:10:39
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.22.94.137 (137.94.22.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.22.94.137 (137.94.22.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 21:10:35.920661 2026] [security2:error] [pid 6643:tid 6643] [client 34.22.94.137:49852] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.rphenry.com"] [uri "/.env.local"] [unique_id "apy9i3Sqf2jZM4DgxwX5DAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 23:56:05
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.22.94.137 (137.94.22.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.22.94.137 (137.94.22.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 19:56:00.487462 2026] [security2:error] [pid 10178:tid 10178] [client 34.22.94.137:34046] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.bacona.org"] [uri "/.env.local"] [unique_id "apysEIW7Andhl_lnJ64c-QAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
maxpower
2026-09-05 23:00:14
(1 day ago)
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 34.22.94.137 (KR/South Korea/137.94.22.3 ...
show more
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 34.22.94.137 (KR/South Korea/137.94.22.34.bc.googleusercontent.com): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 34.22.94.137 - - [06/Sep/2026:01:00:12 +0200] "GET /wp-config.php.bak HTTP/1.1" 403 146 "-" "crusader-worker/1.0" "-" host=mail.poderedellatorre.it
show less
Port Scan
🇳🇱
e.fierstra
2026-09-05 22:58:03
(1 day ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack