🇿🇦
conure.sh
2026-08-29 12:01:39
(5 hours ago)
csagent: score 20.8: 404 noise floor x3, secrets grab x2; 1 domain(s) in 0s
Web App Attack
🇲🇽
octageeks.com
2026-08-29 04:25:55
(12 hours ago)
Wordpress malicious attack:[octablocked]
Web App Attack
🇨🇦
zXero
2026-08-29 03:16:06
(13 hours ago)
Fail2Ban automatic report - jail: no-wordpress
Brute-Force
SSH
DDoS Attack
🇺🇸
TPI-Abuse
2026-08-29 02:37:05
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.48.78.121 (121.78.48.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.48.78.121 (121.78.48.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 22:37:00.396521 2026] [security2:error] [pid 30868:tid 30868] [client 34.48.78.121:59986] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.draindoctorplumbinganddraincom.draindoctor.us"] [uri "/.env.production"] [unique_id "apJFzFtgi0Jgfhcm1ND5_gAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇨🇦
zXero
2026-08-29 02:30:38
(14 hours ago)
Fail2Ban automatic report - jail: web-exploit
Brute-Force
SSH
DDoS Attack
🇳🇱
debestelapp
2026-08-29 01:50:08
(15 hours ago)
Web App Attack
🇺🇸
TPI-Abuse
2026-08-29 01:28:51
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.48.78.121 (121.78.48.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.48.78.121 (121.78.48.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 21:28:43.968909 2026] [security2:error] [pid 4775:tid 4775] [client 34.48.78.121:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.dentguyvt.com"] [uri "/.env.bak"] [unique_id "apI1yy77zxVyDdwqSkUgUgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
COMAITE
2026-08-29 01:00:37
(16 hours ago)
Suspicious URL access.
Web App Attack
🇺🇸
TPI-Abuse
2026-08-29 00:59:49
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.48.78.121 (121.78.48.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.48.78.121 (121.78.48.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 20:59:42.447127 2026] [security2:error] [pid 26754:tid 26754] [client 34.48.78.121:34836] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "louisianasecurityforce.sguard.co"] [uri "/.env.production"] [unique_id "apIu_j-j8elBIPImUubRdAAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
4server
2026-08-29 00:00:28
(17 hours ago)
[SatAug2902:00:25.8408982026][security2:error][pid3343181:tid3343239][client34.48.78.121:0]ModSecuri ...
show more
[SatAug2902:00:25.8408982026][security2:error][pid3343181:tid3343239][client34.48.78.121:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:5\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.10\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"traslocareinsvizzera.ch\"][uri\"/.env.production\"][unique_id\"apIhGbUbvsMdYY323LyC1gAAAFY\"]
show less
Port Scan
Brute-Force
Web App Attack
🇦🇺
electronico
2026-08-28 23:58:59
(17 hours ago)
34.48.78.121 - - [29/Aug/2026:10:58:58 +1100] "GET /.env.example HTTP/1.1" 404 7408 "-" "crusader-wo ...
show more
34.48.78.121 - - [29/Aug/2026:10:58:58 +1100] "GET /.env.example HTTP/1.1" 404 7408 "-" "crusader-worker/1.0"
34.48.78.121 - - [29/Aug/2026:10:58:58 +1100] "GET /wp-config.php.bak HTTP/1.1" 404 7408 "-" "crusader-worker/1.0"
34.48.78.121 - - [29/Aug/2026:10:58:58 +1100] "GET /storage/logs/laravel.log HTTP/1.1" 404 7408 "-" "crusader-worker/1.0"
34.48.78.121 - - [29/Aug/2026:10:58:58 +1100] "GET /.env.old HTTP/1.1" 404 7408 "-" "crusader-worker/1.0"
34.48.78.121 - - [29/Aug/2026:10:58:58 +1100] "GET /env HTTP/1.1" 404 7408 "-" "crusader-worker/1.0"
34.48.78.121 - - [29/Aug/2026:10:58:58 +1100] "GET /.env.backup HTTP/1.1" 404 7408 "-" "crusader-worker/1.0"
34.48.78.121 - - [29/Aug/2026:10:58:58 +1100] "GET /_ignition/health-check HTTP/1.1" 404 7408 "-" "crusader-worker/1.0"
34.48.78.121 - - [29/Aug/2026:10:58:58 +1100] "GET /crusader-404-probe HTTP/1.1" 404 7408 "-" "crusader-worker/1.0"
34.48.78.121 - - [29/Aug/2026:10:58:58 +1100] "GET /.env.dev HTTP/1.1" 404 7408 "-" "crusader-worker/
...
show less
Brute-Force
Web App Attack
🇧🇷
Halux
2026-08-28 23:53:01
(17 hours ago)
34.48.78.121 Probing protected path or service
Web App Attack
🇺🇸
TPI-Abuse
2026-08-28 23:35:24
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.48.78.121 (121.78.48.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.48.78.121 (121.78.48.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 19:35:16.975649 2026] [security2:error] [pid 21955:tid 21955] [client 34.48.78.121:51116] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "volkerjahn.link.theholographicseed.com"] [uri "/.env.dev"] [unique_id "apIbNDEkkFR6M4Dqexq_eQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-28 23:05:17
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.48.78.121 (121.78.48.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.48.78.121 (121.78.48.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 19:05:11.139993 2026] [security2:error] [pid 10904:tid 10904] [client 34.48.78.121:40262] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.clientes.mpservice.com.sv"] [uri "/.env.backup"] [unique_id "apIUJ_rqHRFoATmkvFgvmwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇸🇪
vaia.cloud
2026-08-28 22:45:01
(18 hours ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack