๐บ๐ธ
TPI-Abuse
2026-09-01 00:14:35
(15 minutes ago)
(mod_security) mod_security (id:210492) triggered by 34.78.178.165 (165.178.78.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.78.178.165 (165.178.78.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 20:14:28.711076 2026] [security2:error] [pid 15700:tid 15700] [client 34.78.178.165:44174] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.carinsteen.com"] [uri "/.env.bak"] [unique_id "apYY5OhtiS3GNKemYyRU6AAAAC8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-31 23:45:48
(44 minutes ago)
(mod_security) mod_security (id:210492) triggered by 34.78.178.165 (165.178.78.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.78.178.165 (165.178.78.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 19:45:43.083621 2026] [security2:error] [pid 27246:tid 27246] [client 34.78.178.165:45044] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cloud.tidarat.com"] [uri "/.env.local"] [unique_id "apYSJ32XXRA3AZ91Bkv15wAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-31 23:45:03
(45 minutes ago)
suspicious request in access.log
Web App Attack
๐ซ๐ท
dynamix
2026-08-31 23:34:02
(56 minutes ago)
Multiple WAF Violations
Web App Attack
๐จ๐ญ
leo1305
2026-08-31 22:52:16
(1 hour ago)
CrowdSec detection | scenario: http-probing
Port Scan
Web App Attack
๐ณ๐ฑ
MyGlobalFlowers
2026-08-31 22:33:20
(1 hour ago)
Multiple WAF Violations
Web App Attack
Anonymous
2026-08-31 22:17:42
(2 hours ago)
Scenarios: http-probing, http-sensitive-files
Total requests: 19
Web App Attack
๐ฉ๐ช
FD-IX
2026-08-31 22:13:52
(2 hours ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
๐บ๐ธ
MatCat
2026-08-31 22:05:11
(2 hours ago)
Banned by fail2ban: apache-webprobe
Port Scan
Bad Web Bot
๐บ๐ฆ
URAN Publishing Service
2026-08-31 22:05:06
(2 hours ago)
[01/Sep/2026:01:05:06 +0300] -- 34.78.178.165 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET / ...
show more
[01/Sep/2026:01:05:06 +0300] -- 34.78.178.165 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET /.env HTTP/1.1
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-31 21:43:16
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.78.178.165 (165.178.78.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.78.178.165 (165.178.78.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 17:43:12.752697 2026] [security2:error] [pid 21448:tid 21448] [client 34.78.178.165:43510] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "amarrasdeescobar.com.cerrovictoria.com"] [uri "/.env.save"] [unique_id "apX1cMj3klLTQCN7njEFIwAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ต๐ฑ
lns.bz
2026-08-31 20:58:13
(3 hours ago)
Web app attack [PL.Lu]
Exploited Host
Web App Attack
๐ฉ๐ช
ghostwarriors
2026-08-31 18:20:03
(6 hours ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack
๐ฉ๐ช
yitzhaq
2026-08-31 17:51:54
(6 hours ago)
34.78.178.165 - - [31/Aug/2026:19:51:51 +0200] "GET /wp-config.php.bak HTTP/1.1" 301 534 "-" "crusad ...
show more
34.78.178.165 - - [31/Aug/2026:19:51:51 +0200] "GET /wp-config.php.bak HTTP/1.1" 301 534 "-" "crusader-worker/1.0"
34.78.178.165 - - [31/Aug/2026:19:51:51 +0200] "GET /wp-config.php~ HTTP/1.1" 301 528 "-" "crusader-worker/1.0"
34.78.178.165 - - [31/Aug/2026:19:51:51 +0200] "GET /wp-config.php.bak HTTP/1.1" 301 531 "-" "crusader-worker/1.0"
34.78.178.165 - - [31/Aug/2026:19:51:51 +0200] "GET /wp-config.php~ HTTP/1.1" 301 525 "-" "crusader-worker/1.0"
34.78.178.165 - - [31/Aug/2026:19:51:50 +0200] "GET /wp-config.php.bak HTTP/1.1" 404 66443 "-" "crusader-worker/1.0"
34.78.178.165 - - [31/Aug/2026:19:51:50 +0200] "GET /wp-config.php~ HTTP/1.1" 404 62660 "-" "crusader-worker/1.0"
34.78.178.165 - - [31/Aug/2026:19:51:50 +0200] "GET /wp-config.php~ HTTP/1.1" 404 67663 "-" "crusader-worker/1.0"
34.78.178.165 - - [31/Aug/2026:19:51:50 +0200] "GET /wp-config.php.bak HTTP/1.1" 404 67664 "-" "crusader-worker/1.0"
34.78.178.165 - - [31/Aug/2026:19:51:50 +0200] "GET /.env.example HTTP/1.1" 404 6644
show less
Web App Attack
Brute-Force
Anonymous
2021-03-08 10:56:47
(5 years ago)
[Drupal AbuseIPDB module] Request path is blacklisted. /util/login.aspx
Web App Attack