๐ฉ๐ช
4server
2026-08-28 23:27:19
(28 minutes ago)
[SatAug2901:27:13.8933402026][security2:error][pid3315933:tid3316004][client34.24.127.101:0]ModSecur ...
show more
[SatAug2901:27:13.8933402026][security2:error][pid3315933:tid3316004][client34.24.127.101:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Patternmatch\"\(\?i\)\(\?:/\(\?:\^\|/\)\\\\\\\\.\(env\|git\|svn\|hg\|DS_Store\)\|/\(\?:wp-config\|\\\\\\\\.htaccess\|\\\\\\\\.htpasswd\)\|\\\\\\\\.\(\?:sql\|bak\|old\|log\)\$\)\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"156\"][id\"960720\"][msg\"Forbiddenfileaccessattempt\"][severity\"CRITICAL\"][hostname\"autodiscover.admin-services.ch\"][uri\"/storage/logs/laravel.log\"][unique_id\"apIZUQg8dVv-fqILZJ1EQAAAAIo\"]
show less
Port Scan
Brute-Force
Web App Attack
๐ธ๐ฎ
administrator
2026-08-28 22:05:35
(1 hour ago)
2026-08-28 22:39:02,348 fail2ban.actions [1074]: NOTICE [error-bots] Ban 34.24.127.101
2026- ...
show more
2026-08-28 22:39:02,348 fail2ban.actions [1074]: NOTICE [error-bots] Ban 34.24.127.101
2026-08-28 22:39:02,362 fail2ban.actions [1074]: NOTICE [apache-badbots] Ban 34.24.127.101
2026-08-28 22:39:02,348 fail2ban.actions [1074]: NOTICE [error-bots] Ban 34.24.127.101
...
show less
Bad Web Bot
Web Spam
Email Spam
Blog Spam
Port Scan
Brute-Force
Web App Attack
๐ฉ๐ช
dispaisyenterprises
2026-08-28 21:56:53
(1 hour ago)
Triggered Cloudflare WAF (firewallManaged) from US.
Action: BLOCK | Protocol: HTTP/1.1 (GET) | Endpo ...
show more
Triggered Cloudflare WAF (firewallManaged) from US.
Action: BLOCK | Protocol: HTTP/1.1 (GET) | Endpoint: /wp-config.php.swp | UA: crusader-worker/1.0 โข Reported by DisPaisy Enterprises (dispaisy.systems)
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-08-28 21:43:43
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.24.127.101 (101.127.24.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.24.127.101 (101.127.24.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 17:43:39.766911 2026] [security2:error] [pid 29633:tid 29633] [client 34.24.127.101:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cloudex.click"] [uri "/.env.prod"] [unique_id "apIBC8P3NCs6MWRk86n8XQAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
Aetherweb Ark
2026-08-28 20:27:35
(3 hours ago)
(mod_security) mod_security (id:949110) triggered by 34.24.127.101 (US/United States/101.127.24.34.b ...
show more
(mod_security) mod_security (id:949110) triggered by 34.24.127.101 (US/United States/101.127.24.34.bc.googleusercontent.com): N in the last X secs
show less
Web App Attack
๐ฉ๐ช
Holger
2026-08-28 19:28:05
(4 hours ago)
WordPress WebAttack
Brute-Force
Web App Attack
Anonymous
2026-08-28 18:35:15
(5 hours ago)
Failed login attempt detected by Fail2Ban in plesk-modsecurity jail
Exploited Host
๐ฉ๐ช
XICTRON
2026-08-28 18:20:06
(5 hours ago)
ModSecurity rule violation detected by Fail2Ban
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 17:42:09
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.24.127.101 (101.127.24.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.24.127.101 (101.127.24.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 13:42:01.142677 2026] [security2:error] [pid 26147:tid 26147] [client 34.24.127.101:56602] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kittensquid.com"] [uri "/.env.bak"] [unique_id "apHIaY3TwDIPF5LR0OkdxQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-08-28 17:41:33
(6 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 1247
Exploited Host
Web App Attack
Anonymous
2026-08-28 17:29:19
(6 hours ago)
RdpGuard detected brute-force attempt on HTTP
Brute-Force
๐จ๐ฆ
polycoda
2026-08-28 16:54:16
(7 hours ago)
AutoBlock: ๐ฏ Vulnerability Scanner (Non Decay-Based) - โ๏ธ Configuration File Access (Non Decay-Based ...
show more
AutoBlock: ๐ฏ Vulnerability Scanner (Non Decay-Based) - โ๏ธ Configuration File Access (Non Decay-Based)
show less
Hacking
Bad Web Bot
Web App Attack
๐ธ๐ช
nekopavel
2026-08-28 16:01:37
(7 hours ago)
34.24.127.101 - - [28/Aug/2026:18:01:36 +0200]"GET /.env.production HTTP/1.1" 404 146"-" mta-sts.nek ...
show more
34.24.127.101 - - [28/Aug/2026:18:01:36 +0200]"GET /.env.production HTTP/1.1" 404 146"-" mta-sts.neko.chat "crusader-worker/1.0""0.001" "0.001""North Charleston" "US"
34.24.127.101 - - [28/Aug/2026:18:01:36 +0200]"GET /.env.old HTTP/1.1" 404 146"-" mta-sts.neko.chat "crusader-worker/1.0""0.001" "0.000""North Charleston" "US"
34.24.127.101 - - [28/Aug/2026:18:01:36 +0200]"GET /wp-config.php~ HTTP/1.1" 404 146"-" mta-sts.neko.chat "crusader-worker/1.0""0.000" "0.000""North Charleston" "US"
...
show less
Hacking
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 15:07:09
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.24.127.101 (101.127.24.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.24.127.101 (101.127.24.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 11:07:05.497016 2026] [security2:error] [pid 14745:tid 14745] [client 34.24.127.101:59054] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "al-harbi.com"] [uri "/.env.local"] [unique_id "apGkGbeis9Y-NepncU_gxAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 14:30:59
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.24.127.101 (101.127.24.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.24.127.101 (101.127.24.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 10:30:55.759633 2026] [security2:error] [pid 1886:tid 1886] [client 34.24.127.101:39634] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "shine-x.com"] [uri "/.env.save"] [unique_id "apGbn66Hx4ATILOsgTxw6gAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack