๐ฟ๐ฆ
conure.sh
2026-09-22 11:58:49
(2 days ago)
csagent: score 24.8: 404 noise floor x3, secrets grab x1, wp-config backup grab x1; 1 domain(s) in 0 ...
show more
csagent: score 24.8: 404 noise floor x3, secrets grab x1, wp-config backup grab x1; 1 domain(s) in 0s
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 11:53:04
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.50.51.38 (38.51.50.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.50.51.38 (38.51.50.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 07:52:56.358809 2026] [security2:error] [pid 32448:tid 32448] [client 34.50.51.38:55846] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.sympalais.com"] [uri "/.env.bak"] [unique_id "arJsGGL34YdRlgG9_nB9bwAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
debestelapp
2026-09-22 11:40:12
(2 days ago)
Web App Attack
Anonymous
2026-09-22 11:33:48
(2 days ago)
[email.tmg.gr] httpd-config-scan: sites=www.cdn.tmg.gr; logs=/var/log/httpd/domains/cdn.tmg.gr.log; ...
show more
[email.tmg.gr] httpd-config-scan: sites=www.cdn.tmg.gr; logs=/var/log/httpd/domains/cdn.tmg.gr.log; samples=/.env.old | /wp-config.php.bak | /.env.prod
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 11:22:29
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.50.51.38 (38.51.50.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.50.51.38 (38.51.50.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 07:22:25.068679 2026] [security2:error] [pid 8649:tid 8649] [client 34.50.51.38:47526] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "brookspowell.com"] [uri "/.env.old"] [unique_id "arJk8dMR-9TL0mRXZhL3pAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
Rocky Mountain Bioengineering Symposium
2026-09-22 11:19:46
(2 days ago)
[Tue Sep 22 05:19:45.565061 2026] [authz_core:error] [pid 2469822:tid 140603580991040] [client 34.50 ...
show more
[Tue Sep 22 05:19:45.565061 2026] [authz_core:error] [pid 2469822:tid 140603580991040] [client 34.50.51.38:49142] AH01630: client denied by server configuration: /var/www/public_html/board/wp-config.php.swp
[Tue Sep 22 05:19:45.568545 2026] [authz_core:error] [pid 2470217:tid 140601634801216] [client 34.50.51.38:49148] AH01630: client denied by server configuration: /var/www/public_html/board/wp-config.php.bak
[Tue Sep 22 05:19:45.569034 2026] [authz_core:error] [pid 2469826:tid 140602616288832] [client 34.50.51.38:49082] AH01630: client denied by server configuration: /var/www/public_html/board/.env.bak
...
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-22 10:52:17
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.50.51.38 (38.51.50.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.50.51.38 (38.51.50.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 06:52:13.085775 2026] [security2:error] [pid 7978:tid 7978] [client 34.50.51.38:59870] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "artfranz.com"] [uri "/.env"] [unique_id "arJd3WcIyIjUA8iVyfd5CQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-22 10:36:28
(2 days ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack
๐ฎ๐น
VHosting
2026-09-22 10:25:04
(2 days ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 10:13:25
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.50.51.38 (38.51.50.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.50.51.38 (38.51.50.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 06:13:20.314607 2026] [security2:error] [pid 22280:tid 22280] [client 34.50.51.38:35572] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "4tee2stock.fynyx.com"] [uri "/.env.example"] [unique_id "arJUwA45dbtFJZjKhHAo5QAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack