Anonymous
2026-09-03 02:00:33
(2 hours ago)
Auto-reported by Fail2Ban (NPM-Auth)
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-09-02 21:59:55
(6 hours ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-09-01.
show less
Web App Attack
SSH
Hacking
๐บ๐ธ
Matthew Ping
2026-09-02 14:45:02
(13 hours ago)
Excessive connections (DDoS/flood) blocked by CSF CT_LIMIT on wp2.
DDoS Attack
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-09-01 14:01:38
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.39.13.51 (51.13.39.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.39.13.51 (51.13.39.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 10:01:32.261583 2026] [security2:error] [pid 8046:tid 8046] [client 34.39.13.51:38706] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.richmondrents.com"] [uri "/.env"] [unique_id "apbavMc0kzJKwaodjaNf0QAAADo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
tentwentyfour
2026-09-01 13:00:34
(1 day ago)
Blocked for probing for sensitive web application components
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 12:38:29
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.39.13.51 (51.13.39.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.39.13.51 (51.13.39.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 08:38:25.024252 2026] [security2:error] [pid 16277:tid 16277] [client 34.39.13.51:35962] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "churchbehindthewalls.bridgital.com"] [uri "/.env.bak"] [unique_id "apbHQQFA9eN7B_JPFe9VmgAAADk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
big-cloud.nl
2026-09-01 11:58:37
(1 day ago)
Try to access /.env
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 11:09:40
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.39.13.51 (51.13.39.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.39.13.51 (51.13.39.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 07:09:36.168410 2026] [security2:error] [pid 4988:tid 4988] [client 34.39.13.51:33738] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.ronelgas.com"] [uri "/.env.bak"] [unique_id "apaycHCuqTYFkRSYLBtq7QAAACs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 10:51:09
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.39.13.51 (51.13.39.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.39.13.51 (51.13.39.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 06:51:02.756764 2026] [security2:error] [pid 20082:tid 20157] [client 34.39.13.51:44302] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "peoplewith.ai"] [uri "/wp-config.php~"] [unique_id "apauFkzo3XFLOK5zIgB9lAAAAEw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 10:08:35
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.39.13.51 (51.13.39.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.39.13.51 (51.13.39.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 06:08:28.153893 2026] [security2:error] [pid 9516:tid 9516] [client 34.39.13.51:40492] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "icl1.org"] [uri "/.env.old"] [unique_id "apakHLWeFvOSVmMHfDNinQAAADI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
CBJ
2026-09-01 09:52:49
(1 day ago)
fail2ban: apache-filepath-recon
...
Web App Attack
๐ฉ๐ช
maxpower
2026-09-01 09:37:52
(1 day ago)
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 34.39.13.51 (GB/United Kingdom/51.13.39. ...
show more
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 34.39.13.51 (GB/United Kingdom/51.13.39.34.bc.googleusercontent.com): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 34.39.13.51 - - [01/Sep/2026:11:37:48 +0200] "GET /wp-config.php.bak HTTP/1.1" 200 11983 "-" "crusader-worker/1.0" "-" host=smtp.emmeccipubblicita.it
show less
Port Scan
๐ซ๐ท
masterguru
2026-09-01 09:36:25
(1 day ago)
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 34.39.13.51 (GB/United Kingdom/51.13. ...
show more
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 34.39.13.51 (GB/United Kingdom/51.13.39.34.bc.googleusercontent.com): 1 in the last 3600 secs (0-195)
show less
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-01 08:47:15
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.39.13.51 (51.13.39.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.39.13.51 (51.13.39.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 04:47:08.725622 2026] [security2:error] [pid 18791:tid 18791] [client 34.39.13.51:45268] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "serranoscoffee.com"] [uri "/wp-config.php.bak"] [unique_id "apaRDExS1iAfHJ0xVx38OwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-09-01 08:24:02
(1 day ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking