Anonymous
2026-08-29 04:32:13
(3 days ago)
Failed login attempt detected by Fail2Ban in plesk-modsecurity jail
Exploited Host
๐ธ๐ช
vaia.cloud
2026-08-29 03:00:05
(3 days ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
๐ฉ๐ช
findlab
2026-08-29 02:30:02
(3 days ago)
Backdrop CMS module - malicious activity detected
Bad Web Bot
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-08-29 01:28:10
(3 days ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-29 01:15:04
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.73.38.91 (91.38.73.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.73.38.91 (91.38.73.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 21:14:55.699693 2026] [security2:error] [pid 12775:tid 12775] [client 34.73.38.91:57318] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "gulftelecom.com"] [uri "/wp-config.php.bak"] [unique_id "apIyj3KFudOJa7h4XxlKiwAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-29 00:38:42
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.73.38.91 (91.38.73.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.73.38.91 (91.38.73.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 20:38:36.443851 2026] [security2:error] [pid 22808:tid 22808] [client 34.73.38.91:52988] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.chilako.com"] [uri "/.env.save"] [unique_id "apIqDF_qniOkRQpTTaRJjgAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฏ๐ต
ZEROVOX
2026-08-28 23:38:45
(3 days ago)
CrowdSec: crowdsecurity/http-sensitive-files detected
Web App Attack
Anonymous
2026-08-28 23:20:03
(3 days ago)
suspicious request in access.log
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 22:37:25
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.73.38.91 (91.38.73.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.73.38.91 (91.38.73.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 18:37:17.597152 2026] [security2:error] [pid 32165:tid 32165] [client 34.73.38.91:59490] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "hyps.com"] [uri "/wp-config.php.swp"] [unique_id "apINnbpKCOv9KXaGgx3O6wAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-28 21:50:05
(4 days ago)
| Suspicious URL access.
Web App Attack
Hacking
SQL Injection
Anonymous
2026-08-28 21:23:46
(4 days ago)
(config_exploit_scan) Configuratie Scanner / Nep GPTBot 34.73.38.91 (US/United States/91.38.73.34.bc ...
show more
(config_exploit_scan) Configuratie Scanner / Nep GPTBot 34.73.38.91 (US/United States/91.38.73.34.bc.googleusercontent.com): 3 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 34.73.38.91 - - [28/Aug/2026:23:23:44 +0200] "GET /.env.production HTTP/1.1" 406 4830 "-" "crusader-worker/1.0"
34.73.38.91 - - [28/Aug/2026:23:23:44 +0200] "GET /.env.old HTTP/1.1" 406 4829 "-" "crusader-worker/1.0"
34.73.38.91 - - [28/Aug/2026:23:23:44 +0200] "GET /.env.save HTTP/1.1" 406 4831 "-" "crusader-worker/1.0"
show less
Port Scan
Anonymous
2026-08-28 20:55:39
(4 days ago)
Wordpress vulnerability scanning
...
Web App Attack
Anonymous
2026-08-28 20:17:12
(4 days ago)
Bot / seems abusive / Apache connections: 20
DDoS Attack
Web Spam
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 19:47:56
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 34.73.38.91 (91.38.73.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.73.38.91 (91.38.73.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 15:47:49.627310 2026] [security2:error] [pid 17301:tid 17301] [client 34.73.38.91:54612] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "stlrosesociety.org"] [uri "/wp-config.php.bak"] [unique_id "apHl5ZeZB3deJqryV8S9ggAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 18:26:11
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 34.73.38.91 (91.38.73.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.73.38.91 (91.38.73.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 14:26:05.237283 2026] [security2:error] [pid 5046:tid 5046] [client 34.73.38.91:49022] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "web197.dnchosting.com"] [uri "/.env.old"] [unique_id "apHSvT5s6I_k7T-VlHnY4wAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack