๐ซ๐ท
dynamix
2026-08-28 17:02:22
(1 month ago)
Multiple WAF Violations
Web App Attack
๐ฉ๐ช
webanyone
2026-08-28 16:31:45
(1 month ago)
WAF repeated trigger detected by Fail2Ban in plesk-modsecurity jail
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 15:54:09
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 34.24.97.207 (207.97.24.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.24.97.207 (207.97.24.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 11:54:02.833677 2026] [security2:error] [pid 9033:tid 9084] [client 34.24.97.207:58348] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ayubhamdardfoundation.org"] [uri "/wp-config.php.bak"] [unique_id "apGvGmYAD95Oz2JiGSET9gAAAFI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-08-28 15:00:06
(1 month ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 14:27:24
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 34.24.97.207 (207.97.24.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.24.97.207 (207.97.24.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 10:27:19.645506 2026] [security2:error] [pid 28011:tid 28011] [client 34.24.97.207:59288] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.senshouji.ichi51e.net"] [uri "/wp-config.php~"] [unique_id "apGax0ySdDdQEyRY7SAvfwAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
paulo.apoloni
2026-08-28 13:48:40
(1 month ago)
34.24.97.207 - - [28/Aug/2026:10:48:39 -0300] "GET /wp-config.php.swp HTTP/1.1" 444 0 "-" "crusader- ...
show more
34.24.97.207 - - [28/Aug/2026:10:48:39 -0300] "GET /wp-config.php.swp HTTP/1.1" 444 0 "-" "crusader-worker/1.0"
34.24.97.207 - - [28/Aug/2026:10:48:39 -0300] "GET /.env.save HTTP/1.1" 444 0 "-" "crusader-worker/1.0"
34.24.97.207 - - [28/Aug/2026:10:48:39 -0300] "GET /.env HTTP/1.1" 444 0 "-" "crusader-worker/1.0"
34.24.97.207 - - [28/Aug/2026:10:48:39 -0300] "GET /.env.backup HTTP/1.1" 444 0 "-" "crusader-worker/1.0"
34.24.97.207 - - [28/Aug/2026:10:48:39 -0300] "GET /.env.old HTTP/1.1" 444 0 "-" "crusader-worker/1.0"
...
show less
Bad Web Bot
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-08-28 13:06:42
(1 month ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-08-28 12:49:17
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 34.24.97.207 (207.97.24.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.24.97.207 (207.97.24.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 08:49:09.567827 2026] [security2:error] [pid 12508:tid 12508] [client 34.24.97.207:58182] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.bobrossi.gregorii.com"] [uri "/.env.production"] [unique_id "apGDxWohTEN_P2lmUGzScwAAACU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ญ๐ณ
soporte
2026-08-28 12:47:35
(1 month ago)
Probe for vulnerabilities. Path attempted: /.env.prod
Web App Attack
๐ท๐บ
DZBOT
2026-08-28 12:34:46
(1 month ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
๐ซ๐ท
masterguru
2026-08-28 12:02:59
(1 month ago)
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 34.24.97.207 (US/United States/207.97 ...
show more
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 34.24.97.207 (US/United States/207.97.24.34.bc.googleusercontent.com): 2 in the last 3600 secs (0-196)
show less
Hacking
Anonymous
2026-08-28 11:43:02
(1 month ago)
Bot / scanning and/or hacking attempts: GET /.env.example HTTP/1.1, GET /wp-config.php~ HTTP/1.1, GE ...
show more
Bot / scanning and/or hacking attempts: GET /.env.example HTTP/1.1, GET /wp-config.php~ HTTP/1.1, GET /.env.dev HTTP/1.1, GET /.env.local HTTP/1.1, GET /.env.production HTTP/1.1, GET /actuator/env HTTP/1.1, GET /_ignition/health-check HTTP/1.1
show less
Hacking
Web App Attack
๐ฌ๐ง
consul.to
2026-08-28 11:41:24
(1 month ago)
Web attack/malicious scanning detected
Web App Attack
๐ณ๐ด
jad-abuse
2026-08-28 11:19:18
(1 month ago)
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: env_probe ...
show more
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: env_probe, scanner_ua, ignition_debug, config_backup, source_backup, actuator. Observed by 1 sensor(s); 28 hits.
show less
Hacking
Web App Attack
๐ฆ๐บ
A.i.D.A.N.N
2026-08-28 11:06:09
(1 month ago)
A.i.D.A.N.N: Anomaly Detected - Signature match Web Service - Web application attack detected
Web App Attack