๐บ๐ธ
TPI-Abuse
2026-09-01 13:54:39
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.78.185.160 (160.185.78.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.78.185.160 (160.185.78.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 09:54:33.584532 2026] [security2:error] [pid 1934:tid 1934] [client 34.78.185.160:56502] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.airplanechristmascards.com"] [uri "/.env.old"] [unique_id "apbZGVr-vxUgJJ7HYe82IQAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
4server
2026-09-01 13:49:35
(16 hours ago)
[TueSep0115:49:31.7987892026][security2:error][pid3511678:tid3511960][client34.78.185.160:0]ModSecur ...
show more
[TueSep0115:49:31.7987892026][security2:error][pid3511678:tid3511960][client34.78.185.160:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\"wp-config\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"610\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"cpanel.swiss-web-hosting.com\"][uri\"/wp-config.php~\"][unique_id\"apbX6yWl1AY3N-P-vNBH3AAAAQw\"]
show less
Hacking
Web App Attack
Anonymous
2026-09-01 13:06:05
(17 hours ago)
Bot / scanning and/or hacking attempts: GET /storage/logs/laravel.log HTTP/1.1, GET /wp-config.php.s ...
show more
Bot / scanning and/or hacking attempts: GET /storage/logs/laravel.log HTTP/1.1, GET /wp-config.php.swp HTTP/1.1, GET /.env.save HTTP/1.1, GET /.env.example HTTP/1.1, GET /actuator/configprops HTTP/1.1, GET /.env.prod HTTP/1.1, GET /.env.backup HTTP/1.1, GET /.env.old HTTP/1.1
show less
Hacking
Web App Attack
๐ธ๐ช
vaia.cloud
2026-09-01 13:05:02
(17 hours ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 12:33:54
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.78.185.160 (160.185.78.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.78.185.160 (160.185.78.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 08:33:48.744342 2026] [security2:error] [pid 13001:tid 13001] [client 34.78.185.160:47364] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "chipnado.fractalsky.com"] [uri "/.env.save"] [unique_id "apbGLOcbBlxGMlK2I0M14QAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฑ๐ป
garmtech.com
2026-09-01 10:56:56
(19 hours ago)
Attempted access to sensitive endpoint (/.env) detected. Automated scan or unauthorized probing.
Web App Attack
๐ฉ๐ช
Vegascosmetics
2026-09-01 10:51:31
(19 hours ago)
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after sensitive config/credentials exposure ...
show more
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after sensitive config/credentials exposure probe. Evidence: AttackPattern: /\.env (Match: /.env)
show less
Hacking
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 10:05:23
(20 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.78.185.160 (160.185.78.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.78.185.160 (160.185.78.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 06:05:16.535757 2026] [security2:error] [pid 2397:tid 2397] [client 34.78.185.160:50482] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "unwaved.kooroshvaziri.com"] [uri "/wp-config.php.bak"] [unique_id "apajXKq9kjQCqhP03Wr2TAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
maxpower
2026-09-01 09:40:26
(21 hours ago)
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 34.78.185.160 (BE/Belgium/160.185.78.34. ...
show more
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 34.78.185.160 (BE/Belgium/160.185.78.34.bc.googleusercontent.com): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 34.78.185.160 - - [01/Sep/2026:11:40:20 +0200] "GET /wp-config.php.bak HTTP/1.1" 403 146 "-" "crusader-worker/1.0" "-" host=spaziolaserpescara.it
show less
Port Scan
๐ฉ๐ช
on-com
2026-09-01 07:10:47
(23 hours ago)
URL scan
Brute-Force
Web App Attack
๐ธ๐ฌ
simpeg-adm.bandung.go.id
2026-09-01 06:32:06
(1 day ago)
...
Web Spam
Brute-Force
Web App Attack
๐ฌ๐ง
Aetherweb Ark
2026-09-01 06:10:41
(1 day ago)
(mod_security) mod_security (id:949110) triggered by 34.78.185.160 (BE/Belgium/160.185.78.34.bc.goog ...
show more
(mod_security) mod_security (id:949110) triggered by 34.78.185.160 (BE/Belgium/160.185.78.34.bc.googleusercontent.com): N in the last X secs
show less
Web App Attack
๐ฉ๐ช
pltcldvlpr
2026-09-01 05:09:09
(1 day ago)
CMS/framework probe: 34.78.185.160 - - [01/Sep/2026:07:09:09 +0200] "GET /actuator/configprops HTTP/ ...
show more
CMS/framework probe: 34.78.185.160 - - [01/Sep/2026:07:09:09 +0200] "GET /actuator/configprops HTTP/1.1" 444 0 "-" "crusader-worker/1.0" asn=396982 org="Google LLC" country=BE
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 04:36:28
(1 day ago)
(mod_security) mod_security (id:949110) triggered by 34.78.185.160 (160.185.78.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:949110) triggered by 34.78.185.160 (160.185.78.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 00:36:22.227442 2026] [security2:error] [pid 27109:tid 27109] [client 34.78.185.160:49044] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "hotelrevabookings.com.hamiltonbookings.com"] [uri "/.env.dev"] [unique_id "apZWRuBRnB5eUgrHlX-v1wAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 04:01:45
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.78.185.160 (160.185.78.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.78.185.160 (160.185.78.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 00:01:37.264409 2026] [security2:error] [pid 16011:tid 16011] [client 34.78.185.160:45908] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "laurengardner.digifonics.com"] [uri "/wp-config.php.swp"] [unique_id "apZOIY29yCIVhYPOiztsmwAAACA"]
show less
Brute-Force
Bad Web Bot
Web App Attack