๐บ๐ธ
TPI-Abuse
2026-09-01 13:54:51
(40 minutes ago)
(mod_security) mod_security (id:210492) triggered by 34.65.1.9 (9.1.65.34.bc.googleusercontent.com): ...
show more
(mod_security) mod_security (id:210492) triggered by 34.65.1.9 (9.1.65.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 09:54:47.840411 2026] [security2:error] [pid 26501:tid 26501] [client 34.65.1.9:57616] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.wilklass.com"] [uri "/wp-config.php.bak"] [unique_id "apbZJzWPYpwEs0mScc9_rQAAADY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
Saec
2026-09-01 13:12:01
(1 hour ago)
Jarvis auto-ban: CF top attacker on saec.me (25 hits, CH)
Port Scan
Web App Attack
๐จ๐ญ
zynex
2026-09-01 10:08:21
(4 hours ago)
URL Probing: /.env
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 09:38:09
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.65.1.9 (9.1.65.34.bc.googleusercontent.com): ...
show more
(mod_security) mod_security (id:210492) triggered by 34.65.1.9 (9.1.65.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 05:38:04.501477 2026] [security2:error] [pid 14801:tid 14801] [client 34.65.1.9:43632] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "snowrideadventures.com"] [uri "/.env.old"] [unique_id "apac_Lh0pBTz9peYcTVdfQAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 08:16:37
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.65.1.9 (9.1.65.34.bc.googleusercontent.com): ...
show more
(mod_security) mod_security (id:210492) triggered by 34.65.1.9 (9.1.65.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 04:16:32.493325 2026] [security2:error] [pid 11933:tid 11933] [client 34.65.1.9:54870] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "arcdesign.me"] [uri "/.env.bak"] [unique_id "apaJ4KBHIZhXtLACPmIZPgAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
MatCat
2026-09-01 08:05:07
(6 hours ago)
Banned by fail2ban: apache-webprobe
Port Scan
Bad Web Bot
Anonymous
2026-09-01 07:15:01
(7 hours ago)
suspicious request in access.log
Web App Attack
๐ฉ๐ช
ddobko
2026-09-01 07:08:36
(7 hours ago)
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 06:04:00
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.65.1.9 (9.1.65.34.bc.googleusercontent.com): ...
show more
(mod_security) mod_security (id:210492) triggered by 34.65.1.9 (9.1.65.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 02:03:52.072526 2026] [security2:error] [pid 5719:tid 5719] [client 34.65.1.9:56186] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.gmroyalties.com"] [uri "/wp-config.php~"] [unique_id "apZqyLBu-luLCNeKI_Zd2gAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ท
chronos
2026-09-01 05:44:09
(8 hours ago)
Web traffic. Possible probing or exploitation attempts. | Port: 443 | Proto: TCP | Location: Switzer ...
show more
Web traffic. Possible probing or exploitation attempts. | Port: 443 | Proto: TCP | Location: Switzerland, Zurich
show less
Bad Web Bot
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-01 04:02:57
(10 hours ago)
(mod_security) mod_security (id:949110) triggered by 34.65.1.9 (9.1.65.34.bc.googleusercontent.com): ...
show more
(mod_security) mod_security (id:949110) triggered by 34.65.1.9 (9.1.65.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 00:02:53.539709 2026] [security2:error] [pid 26635:tid 26635] [client 34.65.1.9:33342] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "letahitibookings.hamiltonbookings.com"] [uri "/.env.bak"] [unique_id "apZObfnqonu9lmGj-yYcHgAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ธ๐ช
vaia.cloud
2026-09-01 04:00:11
(10 hours ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
๐ซ๐ท
masterguru
2026-09-01 03:53:25
(10 hours ago)
Restricted File Access Attempt. Matched phrase ".env" at REQUEST_FILENAME. (930130-201)
Hacking
Web App Attack
๐ฉ๐ช
Sรฉfora Srl
2026-09-01 03:39:31
(10 hours ago)
crowdsecurity/http-probing detected by CrowdSec
Web App Attack
Anonymous
2026-09-01 03:17:12
(11 hours ago)
(config_exploit_scan) Configuratie Scanner / Nep GPTBot 34.65.1.9 (CH/Switzerland/9.1.65.34.bc.googl ...
show more
(config_exploit_scan) Configuratie Scanner / Nep GPTBot 34.65.1.9 (CH/Switzerland/9.1.65.34.bc.googleusercontent.com): 3 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 34.65.1.9 - - [01/Sep/2026:05:17:07 +0200] "GET /.env.backup HTTP/1.1" 406 4832 "-" "crusader-worker/1.0"
34.65.1.9 - - [01/Sep/2026:05:17:07 +0200] "GET /.env.dev HTTP/1.1" 406 4830 "-" "crusader-worker/1.0"
34.65.1.9 - - [01/Sep/2026:05:17:07 +0200] "GET /.env HTTP/1.1" 406 4830 "-" "crusader-worker/1.0"
show less
Port Scan