🇳🇱
homeshowdomain.nl
2026-09-06 22:01:35
(10 hours ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-09-05.
show less
Web App Attack
SSH
Hacking
🇺🇸
TPI-Abuse
2026-09-06 03:53:42
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.26.61.130 (130.61.26.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.26.61.130 (130.61.26.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 23:53:38.285525 2026] [security2:error] [pid 3717027:tid 3717027] [client 34.26.61.130:56334] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.truefauxstudio.com"] [uri "/.env.old"] [unique_id "apzjwvFSGWN-yq3zanVoIQAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
e.fierstra
2026-09-06 03:39:14
(1 day ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 03:34:02
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.26.61.130 (130.61.26.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.26.61.130 (130.61.26.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 23:33:57.425402 2026] [security2:error] [pid 29476:tid 29476] [client 34.26.61.130:49894] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "plazahacienda.imerka.com.mx"] [uri "/.env.production"] [unique_id "apzfJc90G31UBIpVy16SlAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
dbmwebdesign
2026-09-06 03:00:08
(1 day ago)
WAF repeated trigger detected by Fail2Ban in plesk-modsecurity jail
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 02:57:35
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.26.61.130 (130.61.26.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.26.61.130 (130.61.26.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 22:57:30.630682 2026] [security2:error] [pid 24682:tid 24689] [client 34.26.61.130:33042] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.shieldsenterprisesusa.com"] [uri "/.env.dev"] [unique_id "apzWmnh4BOPFfcuw8ENwbwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇷🇸
Smel
2026-09-06 02:33:11
(1 day ago)
Unauthorized Probe/Connection, Hack -
Port Scan
Hacking
🇺🇸
TPI-Abuse
2026-09-06 02:26:11
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.26.61.130 (130.61.26.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.26.61.130 (130.61.26.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 22:26:07.456646 2026] [security2:error] [pid 8010:tid 8010] [client 34.26.61.130:40264] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "smtp.budinger.org"] [uri "/.env.backup"] [unique_id "apzPP94ZUO_ua47dipvWDgAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
gadix
2026-09-06 01:01:17
(1 day ago)
[06/Sep/2026:03:01:16.997617 +0200] apy7XECFwmxP6jzL-cyyLgAAAAM 34.26.61.130 51728 127.0.0.1 7081
[0 ...
show more
[06/Sep/2026:03:01:16.997617 +0200] apy7XECFwmxP6jzL-cyyLgAAAAM 34.26.61.130 51728 127.0.0.1 7081
[06/Sep/2026:03:01:16.999323 +0200] apy7XCmbBAe7kMfIqr0sKgAAAAA 34.26.61.130 51748 127.0.0.1 7081
[06/Sep/2026:03:01:17.001419 +0200] apy7XbPAp6LIr8tQV4WpfQAAAAk 34.26.61.130 51732 127.0.0.1 7081
...
show less
Web App Attack
Anonymous
2026-09-06 00:36:03
(1 day ago)
Bot / scanning and/or hacking attempts: GET /wp-config.php.swp HTTP/1.1, GET /.env.save HTTP/1.1, GE ...
show more
Bot / scanning and/or hacking attempts: GET /wp-config.php.swp HTTP/1.1, GET /.env.save HTTP/1.1, GET /actuator/env HTTP/1.1, GET /wp-config.php.bak HTTP/1.1, GET /.env.example HTTP/1.1, GET /.env.dev HTTP/1.1, GET /.env.prod HTTP/1.1, GET /_ignition/health-check HTTP/1.1, GET /.env.backup HTTP/1.1, GET /.env.production HTTP/1.1
show less
Hacking
Web App Attack
Anonymous
2026-09-06 00:06:05
(1 day ago)
Trying to access config files
Web App Attack
🇺🇸
Rocky Mountain Bioengineering Symposium
2026-09-05 23:56:15
(1 day ago)
[Sat Sep 05 17:56:15.227785 2026] [authz_core:error] [pid 26889:tid 139766263694912] [client 34.26.6 ...
show more
[Sat Sep 05 17:56:15.227785 2026] [authz_core:error] [pid 26889:tid 139766263694912] [client 34.26.61.130:60434] AH01630: client denied by server configuration: /var/www/horde/wp-config.php.swp
[Sat Sep 05 17:56:15.232934 2026] [authz_core:error] [pid 27271:tid 139765575820864] [client 34.26.61.130:60292] AH01630: client denied by server configuration: /var/www/horde/.env.bak
[Sat Sep 05 17:56:15.258771 2026] [authz_core:error] [pid 26889:tid 139764502079040] [client 34.26.61.130:60412] AH01630: client denied by server configuration: /var/www/horde/wp-config.php.bak
...
show less
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-05 23:55:03
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.26.61.130 (130.61.26.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.26.61.130 (130.61.26.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 19:54:56.446713 2026] [security2:error] [pid 27541:tid 27541] [client 34.26.61.130:56682] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.crearetest.com"] [uri "/.env"] [unique_id "apyr0E-8_mlkuqZEC9KvLQAAAEA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
jhuisi
2026-09-05 23:51:34
(1 day ago)
Mod Security Hit
Web App Attack
Anonymous
2026-09-05 22:58:18
(1 day ago)
Web App Attack
Brute-Force
Exploited Host
Web App Attack