Anonymous
2026-08-29 03:42:47
(1 hour ago)
Banned by Fail2Ban on server
Web App Attack
πΊπΈ
MatCat
2026-08-29 03:05:09
(1 hour ago)
Banned by fail2ban: apache-webprobe
Port Scan
Bad Web Bot
πΊπΈ
TPI-Abuse
2026-08-29 03:01:34
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.61.47.134 (134.47.61.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.61.47.134 (134.47.61.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 23:01:26.325654 2026] [security2:error] [pid 31677:tid 31696] [client 34.61.47.134:39568] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.certifiedwealthmanager.com.aafm.us"] [uri "/wp-config.php.swp"] [unique_id "apJLhtb8JZEbKsYLT05NygAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-29 02:19:04
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.61.47.134 (134.47.61.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.61.47.134 (134.47.61.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 22:18:58.864046 2026] [security2:error] [pid 7845:tid 7845] [client 34.61.47.134:43104] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.join.oxfordgliding.com"] [uri "/wp-config.php~"] [unique_id "apJBkgBs4HDsr6QxemfExgAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
mnsf
2026-08-29 02:05:20
(2 hours ago)
Abuse Detected (9)
Brute-Force
Web App Attack
Anonymous
2026-08-29 01:33:28
(3 hours ago)
34.61.47.134 - - [29/Aug/2026:09:33:27 +0800] "GET /.env HTTP/1.1" 404 196 "-" "crusader-worker/1.0" ...
show more
34.61.47.134 - - [29/Aug/2026:09:33:27 +0800] "GET /.env HTTP/1.1" 404 196 "-" "crusader-worker/1.0"
34.61.47.134 - - [29/Aug/2026:09:33:27 +0800] "GET /actuator/configprops HTTP/1.1" 404 196 "-" "crusader-worker/1.0"
34.61.47.134 - - [29/Aug/2026:09:33:27 +0800] "GET /storage/logs/laravel.log HTTP/1.1" 404 196 "-" "crusader-worker/1.0"
34.61.47.134 - - [29/Aug/2026:09:33:27 +0800] "GET /_ignition/health-check HTTP/1.1" 404 196 "-" "crusader-worker/1.0"
34.61.47.134 - - [29/Aug/2026:09:33:27 +0800] "GET /.env.backup HTTP/1.1" 404 196 "-" "crusader-worker/1.0"
34.61.47.134 - - [29/Aug/2026:09:33:27 +0800] "GET /.env.prod HTTP/1.1" 404 196 "-" "crusader-worker/1.0"
34.61.47.134 - - [29/Aug/2026:09:33:27 +0800] "GET /.env.example HTTP/1.1" 404 196 "-" "crusader-worker/1.0"
34.61.47.134 - - [29/Aug/2026:09:33:27 +0800] "GET /.env.dev HTTP/1.1" 404 196 "-" "crusader-worker/1.0"
34.61.47.134 - - [29/Aug/2026:09:33:27 +0800] "GET /.env.save HTTP/1.1" 404 196 "-" "crusader-worker/1.0"
34.61.47
...
show less
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-29 00:30:33
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.61.47.134 (134.47.61.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.61.47.134 (134.47.61.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 20:30:26.757441 2026] [security2:error] [pid 8604:tid 8604] [client 34.61.47.134:53960] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.plantmedicinerocks.shannonmatter.com"] [uri "/.env.prod"] [unique_id "apIoIjFu6epu3QgDCvSihwAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
maxpower
2026-08-29 00:29:39
(4 hours ago)
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 34.61.47.134 (US/United States/134.47.61 ...
show more
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 34.61.47.134 (US/United States/134.47.61.34.bc.googleusercontent.com): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 34.61.47.134 - - [29/Aug/2026:02:29:34 +0200] "GET /wp-config.php.bak HTTP/1.1" 403 146 "-" "crusader-worker/1.0" "-" host=samitecnopetrol.it
show less
Port Scan
πΊπΈ
TPI-Abuse
2026-08-28 23:46:13
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.61.47.134 (134.47.61.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.61.47.134 (134.47.61.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 19:46:07.696514 2026] [security2:error] [pid 5016:tid 5016] [client 34.61.47.134:58674] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "caonabo.com"] [uri "/.env.old"] [unique_id "apIdv3M3ftiz3zoLPxFMgwAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
bazter.pro
2026-08-28 23:18:46
(5 hours ago)
Fail2Ban: plesk-bot-aggressive - 15 failures
Port Scan
Bad Web Bot
Web App Attack
π¨π
4server
2026-08-28 22:55:53
(6 hours ago)
[SatAug2900:55:45.5137962026][security2:error][pid3379484:tid3379659][client34.61.47.134:0]ModSecuri ...
show more
[SatAug2900:55:45.5137962026][security2:error][pid3379484:tid3379659][client34.61.47.134:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\".env\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"610\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"webmail.creazione-siti-ticino.ch\"][uri\"/.env.example\"][unique_id\"apIR8akO7LEJelR8DB-AmwAAAYA\"]
show less
Hacking
Web App Attack
π΅π±
Roper123
2026-08-28 22:36:19
(6 hours ago)
WP-LOGIN brute-force
Brute-Force
Web App Attack
π©πͺ
maxpower
2026-08-28 22:11:29
(6 hours ago)
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 34.61.47.134 (US/United States/134.47.61 ...
show more
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 34.61.47.134 (US/United States/134.47.61.34.bc.googleusercontent.com): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 34.61.47.134 - - [29/Aug/2026:00:11:28 +0200] "GET /wp-config.php.bak HTTP/1.1" 200 11914 "-" "crusader-worker/1.0" "-" host=birreriadelcorso.it
show less
Port Scan
πΊπΈ
TPI-Abuse
2026-08-28 22:10:03
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.61.47.134 (134.47.61.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.61.47.134 (134.47.61.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 18:09:54.332643 2026] [security2:error] [pid 3783:tid 3783] [client 34.61.47.134:55754] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "garysgates.com"] [uri "/.env.backup"] [unique_id "apIHMgY1o5v0GDCcGnGvzAAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-28 21:27:57
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.61.47.134 (134.47.61.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.61.47.134 (134.47.61.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 17:27:52.890522 2026] [security2:error] [pid 2067:tid 2067] [client 34.61.47.134:45290] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.warbonnetmusic.tremulant.com"] [uri "/.env.bak"] [unique_id "apH9WP4wfQ7bCvIlMsKdhAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack