๐บ๐ธ
TPI-Abuse
2026-09-01 11:09:55
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.40.133.169 (169.133.40.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.40.133.169 (169.133.40.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 07:09:49.856265 2026] [security2:error] [pid 2830:tid 2830] [client 34.40.133.169:54484] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.robertlundquist.com"] [uri "/.env.example"] [unique_id "apayfb35VuhpOchBNnwIbAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 10:50:19
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.40.133.169 (169.133.40.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.40.133.169 (169.133.40.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 06:50:11.713830 2026] [security2:error] [pid 12227:tid 12227] [client 34.40.133.169:54412] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "partybuseslansing.com"] [uri "/.env.bak"] [unique_id "apat4w9yLTZ8AMzE756KNAAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
Saec
2026-09-01 09:46:01
(1 day ago)
Jarvis auto-ban: CF top attacker on saec.me (24 hits, AU)
Port Scan
Web App Attack
๐ฌ๐ง
consul.to
2026-09-01 09:29:16
(1 day ago)
Web attack/malicious scanning detected
Web App Attack
๐ฉ๐ช
patrisei
2026-09-01 08:51:27
(1 day ago)
You are now banned for 10 years by Schiffdorf-West Patrol. Trigger: crowdsecurity/http-sensitive-fil ...
show more
You are now banned for 10 years by Schiffdorf-West Patrol. Trigger: crowdsecurity/http-sensitive-files
show less
Port Scan
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 07:44:23
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.40.133.169 (169.133.40.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.40.133.169 (169.133.40.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 03:44:16.188363 2026] [security2:error] [pid 27995:tid 27995] [client 34.40.133.169:53998] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ftp.globalmonitoringinc.com"] [uri "/.env.old"] [unique_id "apaCUDvUuv5Tao0AtWNwiAAAAC8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
kommunos
2026-09-01 07:41:30
(1 day ago)
/wp-config.php.bak
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 06:37:20
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.40.133.169 (169.133.40.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.40.133.169 (169.133.40.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 02:37:14.993238 2026] [security2:error] [pid 25303:tid 25303] [client 34.40.133.169:58074] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "tekbit.com"] [uri "/.env.old"] [unique_id "apZymg0cRc_TnHXxpEOsYAAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Petros Stefanakis
2026-09-01 06:29:40
(2 days ago)
(mod_security) mod_security triggered on hostname [redacted] 34.40.133.169 (AU/Australia/169.133.40. ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.40.133.169 (AU/Australia/169.133.40.34.bc.googleusercontent.com)
show less
SQL Injection
๐บ๐ธ
TPI-Abuse
2026-09-01 06:03:20
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.40.133.169 (169.133.40.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.40.133.169 (169.133.40.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 02:03:11.398870 2026] [security2:error] [pid 17141:tid 17141] [client 34.40.133.169:42918] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.merlinaerospace.com"] [uri "/.env.save"] [unique_id "apZqn0tZW-YwYaJZS0-VogAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 05:08:45
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.40.133.169 (169.133.40.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.40.133.169 (169.133.40.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 01:08:39.337543 2026] [security2:error] [pid 6159:tid 6159] [client 34.40.133.169:44240] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.ayudaclic.com"] [uri "/.env.local"] [unique_id "apZd1_bfQBqV5_7NlGjsQgAAAEk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-01 04:46:12
(2 days ago)
Bot / seems abusive / Apache connections: 28
DDoS Attack
Web Spam
Bad Web Bot
Web App Attack
๐ฉ๐ช
FD-IX
2026-09-01 04:33:12
(2 days ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 04:16:45
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.40.133.169 (169.133.40.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.40.133.169 (169.133.40.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 00:16:38.528983 2026] [security2:error] [pid 14196:tid 14196] [client 34.40.133.169:37536] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "nesetsv.com"] [uri "/wp-config.php.bak"] [unique_id "apZRpjWvOpoj5JKkLvO2ugAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob
2026-09-01 04:00:40
(2 days ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /wp-config.php.bak (+12 more) | 2026-09-01 04:00 UTC
show less
Hacking
Web App Attack