Anonymous
2026-09-06 04:16:53
(1 minute ago)
Bot detected scanning for vulnerable pages
Port Scan
🇺🇸
TPI-Abuse
2026-09-06 03:01:58
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.53.47.124 (124.47.53.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.53.47.124 (124.47.53.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 23:01:53.816482 2026] [security2:error] [pid 11887:tid 11887] [client 34.53.47.124:46038] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "wamgirlz.com"] [uri "/wp-config.php.bak"] [unique_id "apzXoRFjVGoFMCQ-jEjqEAAAAIo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
COMAITE
2026-09-06 02:35:36
(1 hour ago)
Suspicious URL access.
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 02:09:29
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.53.47.124 (124.47.53.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.53.47.124 (124.47.53.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 22:09:21.261635 2026] [security2:error] [pid 1328:tid 1328] [client 34.53.47.124:39764] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "shtondo.com"] [uri "/.env.save"] [unique_id "apzLUVFD6WRwV-PfJmt-5wAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
hxsain
2026-09-06 02:04:26
(2 hours ago)
Automated report from CrowdSec: probing for exposed configuration and credential files. 5 events obs ...
show more
Automated report from CrowdSec: probing for exposed configuration and credential files. 5 events observed.
show less
Hacking
Web App Attack
🇬🇧
consul.to
2026-09-06 00:35:20
(3 hours ago)
Web attack/malicious scanning detected
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 22:38:31
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.53.47.124 (124.47.53.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.53.47.124 (124.47.53.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 18:38:28.316933 2026] [security2:error] [pid 3372533:tid 3372533] [client 34.53.47.124:44860] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ftp.mindchill.net"] [uri "/wp-config.php.swp"] [unique_id "apyZ5EjHYMno17e3sSCwBQAAACM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
MusicLibrary
2026-09-05 22:36:37
(5 hours ago)
Attempted access to sensitive configuration files (.env, .git, etc.)
Bad Web Bot
Web App Attack
🇬🇧
Aetherweb Ark
2026-09-05 22:34:34
(5 hours ago)
(mod_security) mod_security (id:949110) triggered by 34.53.47.124 (US/United States/124.47.53.34.bc. ...
show more
(mod_security) mod_security (id:949110) triggered by 34.53.47.124 (US/United States/124.47.53.34.bc.googleusercontent.com): N in the last X secs
show less
Web App Attack
🇺🇸
mnsf
2026-09-05 22:05:15
(6 hours ago)
Scanning/Probing (20)
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 22:00:31
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.53.47.124 (124.47.53.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.53.47.124 (124.47.53.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 18:00:27.526135 2026] [security2:error] [pid 11730:tid 11784] [client 34.53.47.124:51192] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "trumpinvadesus.n2play.net"] [uri "/.env.save"] [unique_id "apyQ-6AugWq2W0pLCwxKNAAAAZQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-05 21:26:32
(6 hours ago)
34.53.47.124 - - [06/Sep/2026:05:26:32 +0800] "GET /actuator/env HTTP/1.1" 404 196 "-" "crusader-wor ...
show more
34.53.47.124 - - [06/Sep/2026:05:26:32 +0800] "GET /actuator/env HTTP/1.1" 404 196 "-" "crusader-worker/1.0"
34.53.47.124 - - [06/Sep/2026:05:26:32 +0800] "GET /crusader-404-probe HTTP/1.1" 404 196 "-" "crusader-worker/1.0"
34.53.47.124 - - [06/Sep/2026:05:26:32 +0800] "GET /.env.production HTTP/1.1" 404 196 "-" "crusader-worker/1.0"
34.53.47.124 - - [06/Sep/2026:05:26:32 +0800] "GET /.env.prod HTTP/1.1" 404 196 "-" "crusader-worker/1.0"
34.53.47.124 - - [06/Sep/2026:05:26:32 +0800] "GET /actuator/configprops HTTP/1.1" 404 196 "-" "crusader-worker/1.0"
34.53.47.124 - - [06/Sep/2026:05:26:32 +0800] "GET /wp-config.php.swp HTTP/1.1" 404 196 "-" "crusader-worker/1.0"
34.53.47.124 - - [06/Sep/2026:05:26:32 +0800] "GET /.env.bak HTTP/1.1" 404 196 "-" "crusader-worker/1.0"
34.53.47.124 - - [06/Sep/2026:05:26:32 +0800] "GET /.env.old HTTP/1.1" 404 196 "-" "crusader-worker/1.0"
34.53.47.124 - - [06/Sep/2026:05:26:32 +0800] "GET /env HTTP/1.1" 404 196 "-" "crusader-worker/1.0"
34.53.47.124 - -
...
show less
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 21:18:15
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.53.47.124 (124.47.53.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.53.47.124 (124.47.53.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 17:18:10.206078 2026] [security2:error] [pid 28714:tid 28714] [client 34.53.47.124:58508] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "wmbbqing.com"] [uri "/.env.save"] [unique_id "apyHEldjTipWbeMKhHiWZAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇨🇦
polycoda
2026-09-05 20:46:18
(7 hours ago)
AutoBlock: 🎯 Vulnerability Scanner (Non Decay-Based) - ❌ Excessive 40X Errors (Decay-Based)
Hacking
Bad Web Bot
Web App Attack
Anonymous
2026-09-05 20:39:28
(7 hours ago)
(mod_security) mod_security triggered on hostname [redacted] 34.53.47.124 (US/United States/124.47.5 ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.53.47.124 (US/United States/124.47.53.34.bc.googleusercontent.com)
show less
SQL Injection