๐บ๐ธ
Matthew Ping
2026-05-08 20:15:01
(1 month ago)
ModSecurity rule 949110 triggered on wp3. Web application attack blocked by CSF/LFD.
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-05-08 18:46:13
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 34.35.123.152 (152.123.35.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.35.123.152 (152.123.35.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 08 14:46:06.184421 2026] [security2:error] [pid 21514:tid 21514] [client 34.35.123.152:57844] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "krystalsgiftshopandboutique.net"] [uri "/.env"] [unique_id "af4vbtlxVSVxNi8clwMRqQAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
2000cn.com.au
2026-05-08 18:17:14
(1 month ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-05-08 16:48:51
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 34.35.123.152 (152.123.35.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.35.123.152 (152.123.35.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 08 12:48:45.186753 2026] [security2:error] [pid 13335:tid 13335] [client 34.35.123.152:40946] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "carjinn.net"] [uri "/.env"] [unique_id "af4T7QEHWFUNcaRK3PVn_QAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-05-08 16:45:02
(1 month ago)
suspicious request in access.log
Web App Attack
๐น๐ท
sgonul71
2026-05-08 16:35:07
(1 month ago)
Web app attacks (IIS logs)
Web App Attack
๐ฆ๐บ
screwlooseit.com.au
2026-05-08 16:26:50
(1 month ago)
Blocked by CSF 13 firewall - Rule: config-dotfile
US/United States/152.123.35.34.bc.googleuserconten ...
show more
Blocked by CSF 13 firewall - Rule: config-dotfile
US/United States/152.123.35.34.bc.googleusercontent.com
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-08 15:38:47
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 34.35.123.152 (152.123.35.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.35.123.152 (152.123.35.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 08 11:38:42.961884 2026] [security2:error] [pid 19303:tid 19303] [client 34.35.123.152:44660] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.huddleston.construction.savingshvac.com"] [uri "/app/.env"] [unique_id "af4DgnZnWx0ykhobJef2uwAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-05-08 15:06:16
(1 month ago)
Scanning/Probing (20)
Brute-Force
Web App Attack
๐ซ๐ท
masterguru
2026-05-08 13:32:51
(1 month ago)
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 34.35.123.152 (ZA/South Africa/152.12 ...
show more
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 34.35.123.152 (ZA/South Africa/152.123.35.34.bc.googleusercontent.com): 1 in the last 3600 secs (0-195)
show less
Hacking