Anonymous
2026-09-22 17:15:02
(5 days ago)
suspicious request in access.log
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 16:45:46
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 34.40.206.142 (142.206.40.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.40.206.142 (142.206.40.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 12:45:38.559669 2026] [security2:error] [pid 31248:tid 31248] [client 34.40.206.142:41296] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "riser-astrology.com"] [uri "/wp-config.php~"] [unique_id "arKwsrzZin9zJepivRWyKwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
Starburst SysOp Team
2026-09-22 16:43:56
(5 days ago)
Restricted File Access Attempt. Matched phrase ".env" at REQUEST_FILENAME. (930130-stl2-17)
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 15:45:41
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 34.40.206.142 (142.206.40.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.40.206.142 (142.206.40.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 11:45:35.086576 2026] [security2:error] [pid 24080:tid 24080] [client 34.40.206.142:48152] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "octaviomontes.com"] [uri "/.env.old"] [unique_id "arKin1awyEozLto7ZT8uYAAAADU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 15:29:53
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 34.40.206.142 (142.206.40.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.40.206.142 (142.206.40.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 11:29:47.097502 2026] [security2:error] [pid 12279:tid 12279] [client 34.40.206.142:38542] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "nashuaboyscouts.org"] [uri "/wp-config.php.swp"] [unique_id "arKe6ycm9I8kC2Gmq_g4CwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
Lee Daniel
2026-09-22 14:12:32
(5 days ago)
34.40.206.142 - - [22/Sep/2026:10:12:31 -0400] "GET /.env HTTP/1.1" 403 6309 "-" "crusader-worker/1. ...
show more
34.40.206.142 - - [22/Sep/2026:10:12:31 -0400] "GET /.env HTTP/1.1" 403 6309 "-" "crusader-worker/1.0"
...
show less
DDoS Attack
Web Spam
Email Spam
Port Scan
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Petros Stefanakis
2026-09-22 13:45:30
(5 days ago)
(mod_security) mod_security triggered on hostname [redacted] 34.40.206.142 (AU/Australia/142.206.40. ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.40.206.142 (AU/Australia/142.206.40.34.bc.googleusercontent.com)
show less
SQL Injection
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-09-22 13:17:32
(5 days ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐จ๐ฟ
akac
2026-09-22 13:01:49
(5 days ago)
Web vulnerability scanning: HTTP/1.1 GET /wp-config.php~
Hacking
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
ghostwarriors
2026-09-22 12:50:13
(5 days ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack
๐ซ๐ท
dynamix
2026-09-22 12:45:41
(5 days ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 12:45:12
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 34.40.206.142 (142.206.40.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.40.206.142 (142.206.40.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 08:45:07.543593 2026] [security2:error] [pid 27223:tid 27265] [client 34.40.206.142:51334] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "eliteproductions.tv"] [uri "/.env"] [unique_id "arJ4U_1kW2THq_56-DKpCQAAAJY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ฟ
Countryman
2026-09-22 12:40:49
(5 days ago)
IPS detection: Spring.Boot.Actuator.Unauthorized.Access
Hacking
๐จ๐ฟ
Countryman
2026-09-22 12:40:49
(5 days ago)
IPS detection: Spring.Boot.Actuator.Unauthorized.Access
Hacking
๐ฉ๐ช
yitzhaq
2026-09-22 12:31:26
(5 days ago)
34.40.206.142 - - [22/Sep/2026:14:31:23 +0200] "GET /wp-config.php.bak HTTP/1.1" 403 4469 "-" "crusa ...
show more
34.40.206.142 - - [22/Sep/2026:14:31:23 +0200] "GET /wp-config.php.bak HTTP/1.1" 403 4469 "-" "crusader-worker/1.0"
34.40.206.142 - - [22/Sep/2026:14:31:23 +0200] "GET /wp-config.php~ HTTP/1.1" 403 4470 "-" "crusader-worker/1.0"
34.40.206.142 - - [22/Sep/2026:14:31:23 +0200] "GET /.env.local HTTP/1.1" 403 4469 "-" "crusader-worker/1.0"
34.40.206.142 - - [22/Sep/2026:14:31:23 +0200] "GET /.env.dev HTTP/1.1" 403 4469 "-" "crusader-worker/1.0"
34.40.206.142 - - [22/Sep/2026:14:31:23 +0200] "GET /.env.old HTTP/1.1" 403 4470 "-" "crusader-worker/1.0"
34.40.206.142 - - [22/Sep/2026:14:31:23 +0200] "GET /.env.bak HTTP/1.1" 403 4469 "-" "crusader-worker/1.0"
34.40.206.142 - - [22/Sep/2026:14:31:23 +0200] "GET /.env.backup HTTP/1.1" 403 4469 "-" "crusader-worker/1.0"
34.40.206.142 - - [22/Sep/2026:14:31:23 +0200] "GET /.env.save HTTP/1.1" 403 4470 "-" "crusader-worker/1.0"
34.40.206.142 - - [22/Sep/2026:14:31:23 +0200] "GET /.env.production HTTP/1.1" 403 4468 "-" "crusader-worker/1.0"
34.40.206
show less
Web App Attack
Brute-Force