🇬🇧
Apache
2026-09-06 06:18:27
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.26.191.110 (US/United States/110.191.26.34.b ...
show more
(mod_security) mod_security (id:210492) triggered by 34.26.191.110 (US/United States/110.191.26.34.bc.googleusercontent.com): 5 in the last 300 secs (CF_ENABLE)
show less
Brute-Force
Web App Attack
🇳🇱
debestelapp
2026-09-06 06:17:54
(1 day ago)
Web App Attack
Anonymous
2026-09-06 03:06:08
(1 day ago)
Trying to access config files
Web App Attack
🇲🇾
Rizzy
2026-09-06 02:10:58
(1 day ago)
Multiple WAF Violations
Brute-Force
Web App Attack
🇷🇴
iulianh
2026-09-06 01:47:17
(1 day ago)
80,443
Brute-Force
SSH
🇺🇸
TPI-Abuse
2026-09-06 01:10:31
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.26.191.110 (110.191.26.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.26.191.110 (110.191.26.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 21:10:25.544521 2026] [security2:error] [pid 8991:tid 8991] [client 34.26.191.110:38304] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.basselier.com"] [uri "/.env"] [unique_id "apy9gQEzfY4iua368HydDQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-06 00:51:44
(1 day ago)
[da.kdns.gr] httpd-config-scan: sites=www.e-stiatorio.gr; logs=/var/log/httpd/domains/e-stiatorio.gr ...
show more
[da.kdns.gr] httpd-config-scan: sites=www.e-stiatorio.gr; logs=/var/log/httpd/domains/e-stiatorio.gr.log; samples=/.env.bak | /.env.prod | /.env.dev
show less
Hacking
Web App Attack
🇩🇪
FeG Deutschland
2026-09-06 00:17:09
(1 day ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 1247
Exploited Host
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 23:57:41
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.26.191.110 (110.191.26.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.26.191.110 (110.191.26.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 19:57:37.859743 2026] [security2:error] [pid 10865:tid 10865] [client 34.26.191.110:53102] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.suffe.cool"] [uri "/.env.example"] [unique_id "apyscRpzG_XmRT9eu2BvfAAAAFY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 23:42:05
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 34.26.191.110 (110.191.26.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.26.191.110 (110.191.26.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 19:41:56.809426 2026] [security2:error] [pid 10807:tid 10807] [client 34.26.191.110:58204] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||theseoscribe.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "theseoscribe.com"] [uri "/db.sql"] [unique_id "apyoxC9AkQw8FbRQsOMCKQAAACE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
MyGlobalFlowers
2026-09-05 23:08:08
(1 day ago)
Multiple WAF Violations
Web App Attack
🇬🇧
consul.to
2026-09-05 22:39:57
(1 day ago)
Web attack/malicious scanning detected
Web App Attack
Anonymous
2026-09-05 22:12:15
(1 day ago)
34.26.191.110 - - [05/Sep/2026:17:12:14 -0500] "GET /.env.example HTTP/1.1" 403 199 "-" "crusader-wo ...
show more
34.26.191.110 - - [05/Sep/2026:17:12:14 -0500] "GET /.env.example HTTP/1.1" 403 199 "-" "crusader-worker/1.0" 34.26.191.110
34.26.191.110 - - [05/Sep/2026:17:12:14 -0500] "GET /.env.bak HTTP/1.1" 403 199 "-" "crusader-worker/1.0" 34.26.191.110
34.26.191.110 - - [05/Sep/2026:17:12:14 -0500] "GET /.env.old HTTP/1.1" 403 199 "-" "crusader-worker/1.0" 34.26.191.110
34.26.191.110 - - [05/Sep/2026:17:12:14 -0500] "GET /.env.prod HTTP/1.1" 403 199 "-" "crusader-worker/1.0" 34.26.191.110
34.26.191.110 - - [05/Sep/2026:17:12:14 -0500] "GET /.env.backup HTTP/1.1" 403 199 "-" "crusader-worker/1.0" 34.26.191.110
34.26.191.110 - - [05/Sep/2026:17:12:14 -0500] "GET /.env HTTP/1.1" 403 199 "-" "crusader-worker/1.0" 34.26.191.110
34.26.191.110 - - [05/Sep/2026:17:12:14 -0500] "GET /.env.save HTTP/1.1" 403 199 "-" "crusader-worker/1.0" 34.26.191.110
34.26.191.110 - - [05/Sep/2026:17:12:14 -0500] "GET /.env.local HTTP/1.1" 403 199 "-" "crusader-worker/1.0" 34.26.191.110
34.26.191.110 - - [05/Sep/2026:17
...
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 21:40:42
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.26.191.110 (110.191.26.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.26.191.110 (110.191.26.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 17:40:37.317376 2026] [security2:error] [pid 1959:tid 1959] [client 34.26.191.110:37780] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.dragoldio.com"] [uri "/.env.prod"] [unique_id "apyMVVE8W37LjFKcTZVfdQAAAGk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-05 21:37:33
(1 day ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack