Anonymous
2026-09-01 14:02:09
(16 hours ago)
Web App Attack
Brute-Force
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 13:47:58
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.50.85.109 (109.85.50.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.50.85.109 (109.85.50.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 09:47:54.193564 2026] [security2:error] [pid 24541:tid 24541] [client 34.50.85.109:42792] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.programsforwedding.com"] [uri "/wp-config.php.swp"] [unique_id "apbXirSDQNh1qZnFcMERiAAAAEs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 13:14:18
(17 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.50.85.109 (109.85.50.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.50.85.109 (109.85.50.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 09:14:13.106980 2026] [security2:error] [pid 20082:tid 20166] [client 34.50.85.109:59996] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||lasertagmetairie.com|F|2"] [data ".log"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "lasertagmetairie.com"] [uri "/storage/logs/laravel.log"] [unique_id "apbPpUzo3XFLOK5zIgCQVwAAAFA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
big-cloud.nl
2026-09-01 12:45:55
(17 hours ago)
Try to access /.env
Web App Attack
๐จ๐ฟ
Countryman
2026-09-01 12:40:48
(18 hours ago)
IPS detection: Spring.Boot.Actuator.Unauthorized.Access
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-01 12:17:09
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.50.85.109 (109.85.50.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.50.85.109 (109.85.50.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 08:17:04.327274 2026] [security2:error] [pid 29854:tid 29854] [client 34.50.85.109:37374] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "saratogaequity.com"] [uri "/.env.production"] [unique_id "apbCQCkxy06-5H7kCMYsKgAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 11:04:58
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.50.85.109 (109.85.50.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.50.85.109 (109.85.50.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 07:04:50.113217 2026] [security2:error] [pid 12312:tid 12312] [client 34.50.85.109:57286] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.edgewatertaxidermy.com"] [uri "/.env.bak"] [unique_id "apaxUukdZHD-bWN3wkkN9AAAAB8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-09-01 11:02:43
(19 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐ธ๐ช
vaia.cloud
2026-09-01 09:50:01
(20 hours ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
๐ณ๐ด
jad-abuse
2026-09-01 09:43:53
(20 hours ago)
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: env_probe ...
show more
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: env_probe, source_backup, scanner_ua, ignition_debug, actuator, config_backup. Observed by 1 sensor(s); 42 hits.
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 09:43:22
(20 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.50.85.109 (109.85.50.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.50.85.109 (109.85.50.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 05:43:17.138591 2026] [security2:error] [pid 4618:tid 4618] [client 34.50.85.109:33296] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "smart1services.com"] [uri "/.env.local"] [unique_id "apaeNUWewtCz4c99icwOdAAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
SwinT
2026-09-01 09:00:08
(21 hours ago)
WAF repeated trigger detected by Fail2Ban in plesk-modsecurity jail
Web App Attack
๐ฟ๐ฆ
conure.sh
2026-09-01 08:31:22
(22 hours ago)
csagent: score 20.8: 404 noise floor x3, secrets grab x2; 1 domain(s) in 0s
Web App Attack
๐ฉ๐ฐ
castipo
2026-09-01 06:36:14
(1 day ago)
nginx-env :: 34.50.85.109 - - [01/Sep/2026:10:35:11 +0700] "GET /actuator/configprops HTTP/2.0" 403 ...
show more
nginx-env :: 34.50.85.109 - - [01/Sep/2026:10:35:11 +0700] "GET /actuator/configprops HTTP/2.0" 403 107 "-" "crusader-worker/1.0" host="api.[user].[host]" cfip="34.50.85.109" cfray="a3413935ad9770ef-SIN"
34.50.85.109 - - [01/Sep/2026:10:35:11 +0700] "GET /actuator/env HTTP/2.0" 403 107 "-" "crusader-worker/1.0" host="api.[user].[host]" cfip="34.50.85.109" cfray="a3413935aa79ba32-SIN"
show less
IoT Targeted
Web App Attack
Port Scan
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-01 06:07:30
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.50.85.109 (109.85.50.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.50.85.109 (109.85.50.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 02:07:24.701871 2026] [security2:error] [pid 19388:tid 19388] [client 34.50.85.109:51800] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.jimsvet.com"] [uri "/.env.bak"] [unique_id "apZrnERcXqTUfpkRMu7V1gAAADo"]
show less
Brute-Force
Bad Web Bot
Web App Attack