๐บ๐ธ
TPI-Abuse
2026-09-01 07:10:37
(4 minutes ago)
(mod_security) mod_security (id:210492) triggered by 34.38.200.95 (95.200.38.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.38.200.95 (95.200.38.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 03:10:33.688130 2026] [security2:error] [pid 30598:tid 30598] [client 34.38.200.95:57810] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mrbaystreet.crossfiregold.com"] [uri "/wp-config.php.swp"] [unique_id "apZ6aUTIQpqXiNHC_DMGwAAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 06:34:41
(40 minutes ago)
(mod_security) mod_security (id:210492) triggered by 34.38.200.95 (95.200.38.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.38.200.95 (95.200.38.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 02:34:33.635861 2026] [security2:error] [pid 29608:tid 29608] [client 34.38.200.95:34444] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "superlamb.com"] [uri "/.env.local"] [unique_id "apZx-aT2BJp5qW7ZISPpGQAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
openstrike.co.uk
2026-09-01 05:13:36
(2 hours ago)
13 attacks on PHP URLs, env grabbing URLs:
GET /wp-config.php.swp HTTP/1.1
GET /.env.example HTTP/1. ...
show more
13 attacks on PHP URLs, env grabbing URLs:
GET /wp-config.php.swp HTTP/1.1
GET /.env.example HTTP/1.1
show less
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-01 05:08:30
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.38.200.95 (95.200.38.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.38.200.95 (95.200.38.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 01:08:24.890091 2026] [security2:error] [pid 14087:tid 14095] [client 34.38.200.95:36750] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.rudiseq.com"] [uri "/wp-config.php~"] [unique_id "apZdyPaFODPEoRpIu-RqPQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
DEV-DNS
2026-09-01 04:37:04
(2 hours ago)
(mod_security) mod_security triggered on hostname [redacted])
SQL Injection
Anonymous
2026-09-01 04:27:12
(2 hours ago)
Bot / seems abusive / Apache connections: 35
DDoS Attack
Web Spam
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 04:21:29
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.38.200.95 (95.200.38.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.38.200.95 (95.200.38.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 00:21:23.110697 2026] [security2:error] [pid 25745:tid 25757] [client 34.38.200.95:60180] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "newsrank.hdtv55.com"] [uri "/.env.example"] [unique_id "apZSw4BdI55s7-WYQ1oyZwAAAQo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-01 04:20:02
(2 hours ago)
suspicious request in access.log
Web App Attack
๐ฉ๐ช
Viveronese
2026-09-01 04:09:59
(3 hours ago)
HTTP vulnerability scanning
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 04:03:15
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.38.200.95 (95.200.38.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.38.200.95 (95.200.38.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 00:03:09.589434 2026] [security2:error] [pid 24404:tid 24404] [client 34.38.200.95:44324] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "knorgmusic.com"] [uri "/.env.dev"] [unique_id "apZOff2Ri1glZSjERdZ3dAAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
MarkGGN
2026-09-01 03:19:04
(3 hours ago)
Web attack. 34.38.200.95 - - [01/Sep/2026:05:19:03 +0200] "GET /wp-config.php.swp HTTP/1.1" 200 9438 ...
show more
Web attack. 34.38.200.95 - - [01/Sep/2026:05:19:03 +0200] "GET /wp-config.php.swp HTTP/1.1" 200 9438 "-" "crusader-worker/1.0"
34.38.200.95 - - [01/Sep/2026:05:19:03 +0200] "GET /wp-config.php.bak HTTP/1.1" 200 9438 "-" "crusader-worker/1.0"
show less
Web App Attack
๐ฌ๐ง
consul.to
2026-09-01 02:46:56
(4 hours ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 02:35:21
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.38.200.95 (95.200.38.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.38.200.95 (95.200.38.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 22:35:15.322820 2026] [security2:error] [pid 14458:tid 14458] [client 34.38.200.95:56274] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.gfsprod.com"] [uri "/.env.prod"] [unique_id "apY54_OmzFiWfHVn9TSFKQAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
debestelapp
2026-09-01 02:35:10
(4 hours ago)
Web App Attack
๐ท๐บ
DZBOT
2026-09-01 02:29:46
(4 hours ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack