🇳🇱
WeCloudit-Anti-Abuse
2026-09-06 07:34:13
(1 hour ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
🇮🇳
Starburst SysOp Team
2026-09-06 06:28:40
(2 hours ago)
Restricted File Access Attempt. Matched phrase ".env" at REQUEST_FILENAME. (930130-bom2-2)
Hacking
Web App Attack
🇦🇺
QT
2026-09-06 05:44:26
(3 hours ago)
Website hack attempted at 2026-09-06 15:44:20 +1000
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 03:02:29
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.58.105.196 (196.105.58.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.58.105.196 (196.105.58.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 23:02:22.842811 2026] [security2:error] [pid 26661:tid 26661] [client 34.58.105.196:40854] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.artspacecleveland.com"] [uri "/wp-config.php.bak"] [unique_id "apzXvjVXdfb2TvCCAnu3MwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
big-cloud.nl
2026-09-06 02:20:12
(7 hours ago)
Try to access /.env
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 02:02:24
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.58.105.196 (196.105.58.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.58.105.196 (196.105.58.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 22:02:21.138935 2026] [security2:error] [pid 17973:tid 17973] [client 34.58.105.196:55384] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "medioskreativos.com.spyasociados.com"] [uri "/wp-config.php.bak"] [unique_id "apzJrVQ4xQIuYAEjUjQT2AAAAHQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
WeCloudit-Anti-Abuse
2026-09-06 01:45:52
(7 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-06 01:31:34
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.58.105.196 (196.105.58.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.58.105.196 (196.105.58.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 21:31:30.037267 2026] [security2:error] [pid 3228:tid 3228] [client 34.58.105.196:48078] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mwrn.microscopedia.com"] [uri "/.env.local"] [unique_id "apzCcoQnoW7cHtEmhMG90gAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-06 01:26:16
(8 hours ago)
Scenarios: http-sensitive-files
Total requests: 19
Web App Attack
🇩🇪
MusicLibrary
2026-09-06 01:19:17
(8 hours ago)
Probing foreign-stack admin panels / known exploit paths (Joomla, phpMyAdmin, phpunit, OWA, etc.)
Bad Web Bot
Web App Attack
🇫🇷
masterguru
2026-09-06 01:14:14
(8 hours ago)
Restricted File Access Attempt. Matched phrase ".env" at REQUEST_FILENAME. (930130-195)
Hacking
Web App Attack
🇺🇸
mnsf
2026-09-06 01:05:49
(8 hours ago)
Scanning/Probing (20)
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 00:48:41
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.58.105.196 (196.105.58.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.58.105.196 (196.105.58.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 20:48:34.812993 2026] [security2:error] [pid 26512:tid 26512] [client 34.58.105.196:42900] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.dwipapuri-abadi.com"] [uri "/wp-config.php~"] [unique_id "apy4Yg_Dea03K4Lm-ZBTvAAAAH0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
Aetherweb Ark
2026-09-06 00:07:12
(9 hours ago)
(mod_security) mod_security (id:949110) triggered by 34.58.105.196 (US/United States/196.105.58.34.b ...
show more
(mod_security) mod_security (id:949110) triggered by 34.58.105.196 (US/United States/196.105.58.34.bc.googleusercontent.com): N in the last X secs
show less
Web App Attack
🇳🇱
e.fierstra
2026-09-06 00:00:27
(9 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack