๐บ๐ธ
TPI-Abuse
2026-08-29 00:42:04
(20 minutes ago)
(mod_security) mod_security (id:210492) triggered by 34.73.216.44 (44.216.73.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.73.216.44 (44.216.73.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 20:41:56.907539 2026] [security2:error] [pid 4682:tid 4682] [client 34.73.216.44:57976] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.t5-online.powerastronomy.com"] [uri "/.env.save"] [unique_id "apIq1KMe2BeXX8xB8k-4qgAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
4server
2026-08-29 00:28:01
(34 minutes ago)
[SatAug2902:27:57.5142392026][security2:error][pid3652641:tid3652705][client34.73.216.44:0]ModSecuri ...
show more
[SatAug2902:27:57.5142392026][security2:error][pid3652641:tid3652705][client34.73.216.44:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\".env\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"610\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"www.efg-investment.ch.81-17-25-250.cpanel.site\"][uri\"/.env.example\"][unique_id\"apInjdnfMTvKTlHRTHx-fAAAAIM\"]
show less
Hacking
Web App Attack
๐บ๐ธ
antlac1
2026-08-29 00:26:01
(36 minutes ago)
crowdsecurity/http-probing
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-29 00:19:25
(42 minutes ago)
(mod_security) mod_security (id:210492) triggered by 34.73.216.44 (44.216.73.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.73.216.44 (44.216.73.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 20:19:20.512751 2026] [security2:error] [pid 8723:tid 8723] [client 34.73.216.44:35216] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "glicksmandro.com.truefauxstudio.com"] [uri "/.env.example"] [unique_id "apIliJ0SvFuxa4SZN16btgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
debestelapp
2026-08-29 00:00:22
(1 hour ago)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 23:10:36
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.73.216.44 (44.216.73.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.73.216.44 (44.216.73.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 19:10:29.917382 2026] [security2:error] [pid 14454:tid 14454] [client 34.73.216.44:43368] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.test.zunosaki.com"] [uri "/wp-config.php.swp"] [unique_id "apIVZY-rXE6V0nf866tTWQAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
RamSet
2026-08-28 22:51:23
(2 hours ago)
[swy] HTTP-Probe on port 443 (via domain). 19 distinct paths probed in 1s. Sustained 29 req/min, 19 ...
show more
[swy] HTTP-Probe on port 443 (via domain). 19 distinct paths probed in 1s. Sustained 29 req/min, 19 nonexistent paths (404). Paths: /.env, /.env.example, /.env.local, /actuator/env, /.env.backup, /.env.production, /.env.save, /.env.dev, /wp-config.php.swp, /.env.bak, /.env.old, /.env.prod, /actuator/configprops, /wp-config.php~, /wp-config.php.bak, /_ignition/health-check, /crusader-404-probe, /env, /storage/logs/laravel.log
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob
2026-08-28 21:54:23
(3 hours ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /wp-config.php~ (+12 more) | 2026-08-28 21:54 UTC
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 21:40:00
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.73.216.44 (44.216.73.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.73.216.44 (44.216.73.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 17:39:54.975920 2026] [security2:error] [pid 604:tid 604] [client 34.73.216.44:47662] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "demo.12345.is"] [uri "/.env.local"] [unique_id "apIAKiydVoz5TC1vps5eMwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 20:36:32
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.73.216.44 (44.216.73.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.73.216.44 (44.216.73.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 16:36:27.559941 2026] [security2:error] [pid 24346:tid 24346] [client 34.73.216.44:44936] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "3905ccn.us.3905ccn.org"] [uri "/wp-config.php.bak"] [unique_id "apHxS4hc60J45OiB1K0aiwAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 20:01:43
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.73.216.44 (44.216.73.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.73.216.44 (44.216.73.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 16:01:39.915473 2026] [security2:error] [pid 18133:tid 18133] [client 34.73.216.44:47270] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "shadowveil.io"] [uri "/wp-config.php.bak"] [unique_id "apHpI8n_oZK9eNPqseEA4gAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
LoneRider
2026-08-28 19:56:54
(5 hours ago)
[28/Aug/2026:21:56:54.061489 +0200] apHoBiDOU7HOfj1mj9WM2gAAAAY 34.73.216.44 50600 127.0.0.1 7081
[2 ...
show more
[28/Aug/2026:21:56:54.061489 +0200] apHoBiDOU7HOfj1mj9WM2gAAAAY 34.73.216.44 50600 127.0.0.1 7081
[28/Aug/2026:21:56:54.061594 +0200] apHoBvUg79u-4OPTH1dywAAAAA0 34.73.216.44 50598 127.0.0.1 7081
[28/Aug/2026:21:56:54.074490 +0200] apHoBsze00L0wcDrMJKdhwAAAAE 34.73.216.44 50614 127.0.0.1 7081
...
show less
Hacking
๐ฉ๐ช
itsolon
2026-08-28 19:20:35
(5 hours ago)
[28/Aug/2026:21:20:32 +0200] 178794483221.939084 34.73.216.44 42108 217.154.7.177 443
[28/Aug/2026:2 ...
show more
[28/Aug/2026:21:20:32 +0200] 178794483221.939084 34.73.216.44 42108 217.154.7.177 443
[28/Aug/2026:21:20:32 +0200] 178794483270.560885 34.73.216.44 42098 217.154.7.177 443
[28/Aug/2026:21:20:32 +0200] 178794483210.641301 34.73.216.44 42072 217.154.7.177 443
[28/Aug/2026:21:20:32 +0200] 178794483255.027706 34.73.216.44 42020 217.154.7.177 443
[28/Aug/2026:21:20:32 +0200] 178794483242.504340 34.73.216.44 42062 217.154.7.177 443
...
show less
Port Scan
Hacking
Brute-Force
Web App Attack
๐ฉ๐ช
BlueWire Hosting
2026-08-28 19:15:51
(5 hours ago)
Aggressive scanning resulting into 404
Bad Web Bot
๐ฉ๐ช
Bedios GmbH
2026-08-28 19:00:02
(6 hours ago)
Login credentials theft attempt
Hacking