๐ฉ๐ช
ghostwarriors
2026-08-27 14:50:12
(1 hour ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 14:45:33
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.23.196.130 (130.196.23.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.23.196.130 (130.196.23.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 10:45:27.122537 2026] [security2:error] [pid 2245:tid 2245] [client 34.23.196.130:49260] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "rangerroma.com"] [uri "/.env.bak"] [unique_id "apBNh4JufPPNQ9ucJUsIMwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
yitzhaq
2026-08-27 14:42:55
(1 hour ago)
34.23.196.130 - - [27/Aug/2026:16:42:51 +0200] "GET /wp-config.php.bak HTTP/1.1" 404 4495 "-" "crusa ...
show more
34.23.196.130 - - [27/Aug/2026:16:42:51 +0200] "GET /wp-config.php.bak HTTP/1.1" 404 4495 "-" "crusader-worker/1.0"
34.23.196.130 - - [27/Aug/2026:16:42:51 +0200] "GET /wp-config.php~ HTTP/1.1" 404 4496 "-" "crusader-worker/1.0"
34.23.196.130 - - [27/Aug/2026:16:42:51 +0200] "GET /.env.old HTTP/1.1" 404 4497 "-" "crusader-worker/1.0"
34.23.196.130 - - [27/Aug/2026:16:42:51 +0200] "GET /.env.dev HTTP/1.1" 404 4497 "-" "crusader-worker/1.0"
34.23.196.130 - - [27/Aug/2026:16:42:51 +0200] "GET /env HTTP/1.1" 404 4495 "-" "crusader-worker/1.0"
34.23.196.130 - - [27/Aug/2026:16:42:51 +0200] "GET /_ignition/health-check HTTP/1.1" 404 4495 "-" "crusader-worker/1.0"
34.23.196.130 - - [27/Aug/2026:16:42:51 +0200] "GET /.env.example HTTP/1.1" 404 4495 "-" "crusader-worker/1.0"
34.23.196.130 - - [27/Aug/2026:16:42:51 +0200] "GET /actuator/env HTTP/1.1" 404 4497 "-" "crusader-worker/1.0"
34.23.196.130 - - [27/Aug/2026:16:42:51 +0200] "GET /.env.bak HTTP/1.1" 404 4495 "-" "crusader-worker/1.0"
34.23
show less
Web App Attack
Brute-Force
๐ฉ๐ช
Lino Project
2026-08-27 14:17:46
(2 hours ago)
CrowdSec abuse IP report (host SRV-2) Scenario: crowdsecurity/http-sensitive-files
Hacking
๐บ๐ธ
TPI-Abuse
2026-08-27 13:47:21
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.23.196.130 (130.196.23.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.23.196.130 (130.196.23.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 09:47:15.237061 2026] [security2:error] [pid 15546:tid 15546] [client 34.23.196.130:49400] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.thegreatleapforward.com.herecometheplanes.com"] [uri "/wp-config.php.swp"] [unique_id "apA_46zKwxMDZfDpOZVBbQAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-27 13:07:07
(3 hours ago)
Automated web scanner. Requested suspicious paths: /.env.production | /actuator/configprops | /crusa ...
show more
Automated web scanner. Requested suspicious paths: /.env.production | /actuator/configprops | /crusader-404-probe | /.env.bak | /.env.old | /storage/logs/laravel.log | /.env.local | /.env.prod | /.env.example | /.env | /.env.dev, /.env.save | /actuator/configprops | /crusader-404-probe | /.env.bak | /.env.old | /storage/logs/laravel.log | /.env.local | /.env.prod | /.env.example | /.env | /.env.dev. UTC: 2026-08-27 12:49:23.
show less
Web App Attack
๐บ๐ธ
infra-monitor
2026-08-27 13:00:04
(3 hours ago)
Automated ban via infra-monitor: mgmt-path-probe, suspicious-probe, wordpress-probe, +2 more
Port Scan
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 12:52:43
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.23.196.130 (130.196.23.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.23.196.130 (130.196.23.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 08:52:35.990617 2026] [security2:error] [pid 20238:tid 20238] [client 34.23.196.130:48446] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.albionglobalmarketing.com"] [uri "/.env.production"] [unique_id "apAzE_P9VTi7qJBUJPvkgAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-08-27 12:40:14
(3 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
Anonymous
2026-08-27 12:38:15
(3 hours ago)
(mod_security) mod_security triggered on hostname [redacted] 34.23.196.130 (US/United States/130.196 ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.23.196.130 (US/United States/130.196.23.34.bc.googleusercontent.com)
show less
SQL Injection
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-08-27 12:10:17
(4 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
๐บ๐ธ
mnsf
2026-08-27 12:05:36
(4 hours ago)
Scanning/Probing (20)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 11:33:58
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.23.196.130 (130.196.23.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.23.196.130 (130.196.23.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 07:33:50.462059 2026] [security2:error] [pid 26065:tid 26065] [client 34.23.196.130:37622] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mkbcbible.com"] [uri "/.env.local"] [unique_id "apAgnkRy73J5ZSPjd80HqgAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
VHosting
2026-08-27 10:45:06
(5 hours ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-08-27 10:27:41
(5 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack