Anonymous
2026-08-27 15:20:02
(1 day ago)
suspicious request in access.log
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 14:57:37
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.74.111.167 (167.111.74.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.74.111.167 (167.111.74.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 10:57:32.688862 2026] [security2:error] [pid 2724393:tid 2724399] [client 34.74.111.167:46198] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bestthingieveratelocations.com"] [uri "/wp-config.php~"] [unique_id "apBQXOmHkda15Q5D3BzEVwAAAIQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Skyrider
2026-08-27 14:50:35
(1 day ago)
crowdsecurity/http-sensitive-files
Web App Attack
๐ซ๐ท
dynamix
2026-08-27 14:36:49
(1 day ago)
Multiple WAF Violations
Web App Attack
๐ซ๐ฎ
paissangroup
2026-08-27 14:36:31
(1 day ago)
Multiple WAF Violations
Web App Attack
๐ท๐บ
ago.su
2026-08-27 14:11:14
(1 day ago)
F2B blocked nginx bad bot [otd]
Hacking
Web App Attack
๐จ๐ฆ
Not Fake
2026-08-27 14:10:58
(1 day ago)
$f2bV_matches
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 14:01:29
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.74.111.167 (167.111.74.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.74.111.167 (167.111.74.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 10:01:24.734633 2026] [security2:error] [pid 8197:tid 8197] [client 34.74.111.167:36180] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.desertshadowsrv.org"] [uri "/wp-config.php.bak"] [unique_id "apBDNFz6zQbPiBSvdGpmFQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
maxpower
2026-08-27 13:20:24
(1 day ago)
(nginx_hardened) REGOLA 3 - Nginx Hardening Triggered 34.74.111.167 (US/United States/167.111.74.34. ...
show more
(nginx_hardened) REGOLA 3 - Nginx Hardening Triggered 34.74.111.167 (US/United States/167.111.74.34.bc.googleusercontent.com): 3 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 2026/08/27 15:20:21 [error] 3842680#3842680: *469568 access forbidden by rule, client: 34.74.111.167, server: grafica-x.com, request: "GET /wp-config.php~ HTTP/1.1", host: "grafica-x.com"
2026/08/27 15:20:21 [error] 3842684#3842684: *469566 access forbidden by rule, client: 34.74.111.167, server: grafica-x.com, request: "GET /wp-config.php.bak HTTP/1.1", host: "grafica-x.com"
2026/08/27 15:20:21 [error] 3842689#3842689: *469575 access forbidden by rule, client: 34.74.111.167, server: grafica-x.com, request: "GET /wp-config.php.swp HTTP/1.1", host: "grafica-x.com"
show less
Port Scan
๐ณ๐ด
jad-abuse
2026-08-27 12:35:27
(1 day ago)
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: env_probe ...
show more
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: env_probe, source_backup, scanner_ua, actuator, config_backup, ignition_debug. Observed by 1 sensor(s); 43 hits.
show less
Hacking
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-08-27 11:20:22
(1 day ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-08-27 11:07:17
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.74.111.167 (167.111.74.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.74.111.167 (167.111.74.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 07:07:10.937077 2026] [security2:error] [pid 3486:tid 3486] [client 34.74.111.167:35736] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.ava-world.com"] [uri "/.env.old"] [unique_id "apAaXtx5N2y71CsnnfdJyQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-27 10:49:05
(1 day ago)
[ns65.kdns.gr] httpd-config-scan: sites=www.hatzifotis.gr; logs=/var/log/httpd/domains/hatzifotis.gr ...
show more
[ns65.kdns.gr] httpd-config-scan: sites=www.hatzifotis.gr; logs=/var/log/httpd/domains/hatzifotis.gr.log; samples=/.env.prod | /actuator/env | /.env.production
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 10:46:47
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.74.111.167 (167.111.74.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.74.111.167 (167.111.74.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 06:46:38.861177 2026] [security2:error] [pid 19231:tid 19231] [client 34.74.111.167:38578] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.mylesmitchell.lilachost.net"] [uri "/.env"] [unique_id "apAVjjH0lrUYdvft9ULXXgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
kosada.com
2026-08-27 10:37:45
(1 day ago)
Web vulnerability probing: /.env.example
Web App Attack