๐ณ๐ฑ
homeshowdomain.nl
2026-09-23 22:03:37
(3 days ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-09-22.
show less
Web App Attack
SSH
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-22 17:08:01
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 34.78.51.238 (238.51.78.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.78.51.238 (238.51.78.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 13:07:53.610352 2026] [security2:error] [pid 1052069:tid 1052069] [client 34.78.51.238:40498] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sifnosgreekcatering.com"] [uri "/wp-config.php~"] [unique_id "arK16WxC4w-nPxPoUD9LsQAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ฐ
ScamAware
2026-09-22 16:39:02
(4 days ago)
Detected by Cloudflare Security Events via WordPress automation. Detection: sensitive_files (Sensiti ...
show more
Detected by Cloudflare Security Events via WordPress automation. Detection: sensitive_files (Sensitive files, source control, config, and backups). Hits from same IP in last 60 minutes: 20. Unique request paths counted internally: 20. Cloudflare action: block. Cloudflare source: firewallCustom.
show less
Web App Attack
๐ณ๐ฑ
debestelapp
2026-09-22 16:15:12
(4 days ago)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 15:58:57
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 34.78.51.238 (238.51.78.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.78.51.238 (238.51.78.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 11:58:52.941379 2026] [security2:error] [pid 26047:tid 26047] [client 34.78.51.238:51472] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "pattymoorearmstrong.com"] [uri "/wp-config.php.bak"] [unique_id "arKlvHJsQoGs-G6MZkfNJAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ฆ
Anytech
2026-09-22 15:23:54
(4 days ago)
Blocked by Conn-Monitor: env-probing
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-22 14:46:22
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 34.78.51.238 (238.51.78.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.78.51.238 (238.51.78.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 10:46:15.121249 2026] [security2:error] [pid 25506:tid 25506] [client 34.78.51.238:33892] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.csf-pos.com"] [uri "/.env.old"] [unique_id "arKUt27HHTatOsXNr56TJQAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 14:12:39
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 34.78.51.238 (238.51.78.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.78.51.238 (238.51.78.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 10:12:33.892636 2026] [security2:error] [pid 6233:tid 6233] [client 34.78.51.238:54450] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "justicehoward.com"] [uri "/.env"] [unique_id "arKM0YVxX1PkWnjOhFWjsQAAACs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-22 13:24:48
(4 days ago)
[ti-01ov] Web exploit scanning: 7 suspicious requests detected by fail2ban jail <name>. Example: 34. ...
show more
[ti-01ov] Web exploit scanning: 7 suspicious requests detected by fail2ban jail <name>. Example: 34.78.51.238 - - \[22/Sep/2026:15:24:36 +0200\] "GET /.env.prod HTTP/1.1" 403 7481 "-" "crusader-worker/1.0"
34.78.51.238 - - \[22/Sep/2026:15:24:36 +0200\] "GET /.env HTTP/1.1" 403 2104 "-" "crusader-worker/1.0"
34.78.51.238 - - \[22/Sep/2026:15:24:36 +0200\] "GET /.env.example HTTP/1.1" 403 7481 "-" "crusader-worker/1.0"
34.78.51.238 - - \[22/Sep/2026:15:24:36 +0200\] "GET /.env.production HTTP/1.1" 403 7481 "-" "crusader-worker/1.0"
34.78.51.238 - - \[22/Sep/2026:15:24:36 +0200\] "GET /.env.backup HTTP/1.1" 403 7481 "-" "crusader-worker/1.0"
34.78.51.238 - - \[22/Sep/2026:15:24:36
...
show less
Bad Web Bot
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-09-22 13:23:56
(4 days ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 13:12:19
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 34.78.51.238 (238.51.78.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.78.51.238 (238.51.78.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 09:12:15.438958 2026] [security2:error] [pid 22506:tid 22506] [client 34.78.51.238:34324] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "forestvalleyfarm.com"] [uri "/.env"] [unique_id "arJ-r4gTndy8IpoQQ7VWngAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-22 12:40:01
(4 days ago)
suspicious request in access.log
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 12:13:00
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 34.78.51.238 (238.51.78.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.78.51.238 (238.51.78.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 08:12:55.814644 2026] [security2:error] [pid 22537:tid 22537] [client 34.78.51.238:55802] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "deharrisassoc.com"] [uri "/.env.save"] [unique_id "arJwxxWIKCQIOHoFZ6ehxwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-22 12:03:35
(4 days ago)
[ns41.kdns.gr] httpd-config-scan: sites=www.crm.koukas-machines.com; logs=/var/log/httpd/domains/kou ...
show more
[ns41.kdns.gr] httpd-config-scan: sites=www.crm.koukas-machines.com; logs=/var/log/httpd/domains/koukas-machines.com.crm.log; samples=/wp-config.php~ | /.env.save | /.env.prod
show less
Hacking
Web App Attack
๐จ๐ฆ
polycoda
2026-09-22 11:55:21
(4 days ago)
AutoBlock: ๐ฏ Vulnerability Scanner (Non Decay-Based) - โช๏ธ Excessive 30X Errors (Decay-Based)
Hacking
Bad Web Bot
Web App Attack