🇳🇱
wlt-blocker
2026-09-05 11:32:51
(3 hours ago)
Unauthorized access to webpage admin
Web App Attack
🇫🇷
SpaceHost-Server
2026-09-04 22:20:41
(16 hours ago)
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 15:15:53
(23 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.74.99.25 (25.99.74.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.74.99.25 (25.99.74.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 11:15:48.972509 2026] [security2:error] [pid 19043:tid 19043] [client 34.74.99.25:51478] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.nolaanimereviews.com"] [uri "/.env.local"] [unique_id "aprgpFBAzpXuVUQMN7nqSgAAAB8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
debestelapp
2026-09-04 14:50:10
(1 day ago)
Web App Attack
🇩🇪
Dominik Lysiak
2026-09-04 14:47:04
(1 day ago)
34.74.99.25 - - [04/Sep/2026:16:47:03 +0200] "GET /.env.dev HTTP/1.1" 444 0 "-" "crusader-worker/1.0 ...
show more
34.74.99.25 - - [04/Sep/2026:16:47:03 +0200] "GET /.env.dev HTTP/1.1" 444 0 "-" "crusader-worker/1.0"
34.74.99.25 - - [04/Sep/2026:16:47:03 +0200] "GET /.env.save HTTP/1.1" 444 0 "-" "crusader-worker/1.0"
34.74.99.25 - - [04/Sep/2026:16:47:03 +0200] "GET /.env HTTP/1.1" 444 0 "-" "crusader-worker/1.0"
...
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 14:07:55
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.74.99.25 (25.99.74.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.74.99.25 (25.99.74.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 10:07:50.319368 2026] [security2:error] [pid 20727:tid 20727] [client 34.74.99.25:42076] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.infraredovens.net"] [uri "/wp-config.php.swp"] [unique_id "aprQtjSbT00JGovbztUM4wAAAEE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-04 13:50:05
(1 day ago)
| Suspicious URL access.
Web App Attack
Hacking
SQL Injection
🇺🇸
TPI-Abuse
2026-09-04 13:28:11
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.74.99.25 (25.99.74.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.74.99.25 (25.99.74.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 09:28:04.710326 2026] [security2:error] [pid 16429:tid 16429] [client 34.74.99.25:42696] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "skulldump.com"] [uri "/.env.production"] [unique_id "aprHZCrBH9tt8BNTehRU0AAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
OceanTreasure
2026-09-04 12:20:04
(1 day ago)
tcp/80; WEB_SERVER Tilde in URI - potential .php~ source disclosure vulnerability: "GET /wp-config.p ...
show more
tcp/80; WEB_SERVER Tilde in URI - potential .php~ source disclosure vulnerability: "GET /wp-config.php~" @ 2026-09-04T12:16:45Z
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 11:44:22
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.74.99.25 (25.99.74.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.74.99.25 (25.99.74.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 07:44:14.467588 2026] [security2:error] [pid 606352:tid 606352] [client 34.74.99.25:38576] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.hotelausland.com"] [uri "/.env.example"] [unique_id "apqvDszcLhpX6VeHQLUz5wAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇮
YF
2026-09-04 10:34:37
(1 day ago)
WordPress config file probe
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 10:00:06
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.74.99.25 (25.99.74.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.74.99.25 (25.99.74.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 05:59:58.163470 2026] [security2:error] [pid 31156:tid 31184] [client 34.74.99.25:34422] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.jsbarber.com"] [uri "/.env.local"] [unique_id "apqWnrXaduj_y9pQpylXPgAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 09:20:45
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.74.99.25 (25.99.74.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.74.99.25 (25.99.74.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 05:20:37.613890 2026] [security2:error] [pid 7901:tid 7901] [client 34.74.99.25:53640] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "lyounglaw.com"] [uri "/.env.old"] [unique_id "apqNZSqjR7lEkAg2SCL36AAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
dynamix
2026-09-04 08:43:12
(1 day ago)
Multiple WAF Violations
Web App Attack
Anonymous
2026-09-04 08:24:24
(1 day ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking